security.txt Checker

Verify a site publishes a valid security.txt at /.well-known/security.txt and lists a working contact.

Free, unlimited, no signup.

About security.txt Checker

A valid security.txt tells researchers exactly where to send vulnerability reports before they end up on Twitter. It's a five-minute file that every bug-bounty program, pen-test firm and enterprise procurement team now looks for. This checker fetches yours, validates it against RFC 9116 and flags anything that would confuse a would-be reporter.

What this tool checks

security.txt Checker focuses on the following signals from your site's live response:

  • security-txtmodule in the full audit

Why it matters

Signals covered by security.txt Checker are the ones attackers, browsers, and search engines look at first. A weak result here means real users are exposed — via downgrade attacks, broken trust warnings, indexing problems, or leaked data — long before anything obvious breaks. Fixing them is usually a config change, not a rewrite, and the impact is immediate.

How to interpret your result

  • Pass — the signal meets modern best practice. Keep it monitored; regressions happen after deploys.
  • Warn — functional but weaker than recommended. Usually a quick header, DNS, or config tweak away from a full pass.
  • Fail — a real risk to users or search visibility. Follow the recommendation shown next to the finding — it's copy-pasteable.

Best practices

  • • Re-run after every deploy — configuration drift is the #1 cause of regressions.
  • • Compare against a competitor's report to spot easy wins.
  • • Wire the public API into CI to gate merges on the score.
  • • Fix warns before failures — they're the cheapest to close and pay off compounding gains.

Frequently asked questions

Not legally, but it is standard practice (RFC 9116) and part of most bug-bounty program hygiene.

Related guides

Related articles

More tools