security.txt: What It Is and How to Publish It
A simple text file that helps researchers find your security contact and policy.
What is security.txt?
security.txt is a proposed standard (RFC 9116) that provides a standardized way for websites to define security policies and contact information for security researchers. It solves the common problem of researchers not knowing how to report vulnerabilities they discover.
Why security.txt matters
Discoverability: Researchers can automatically find your security contact information without guessing email addresses or hunting through websites.
Standardization: Consistent format across organizations makes it easier for security tools and researchers to parse contact information.
Legal Clarity: Direct link to your vulnerability disclosure policy and safe harbor terms reduces legal uncertainty.
Automation: Security scanners and research tools can automatically discover and respect your disclosure preferences.
Standard Locations
https://example.com/.well-known/security.txthttps://example.com/security.txtFields & Format Specification
Required Fields
Contact: https://example.com/security-contact
Contact: tel:+1-555-123-4567
Optional Fields
Format Requirements
- Plain text file encoded in UTF-8
- One field per line in "Field: Value" format
- Lines starting with # are comments
- Empty lines are ignored
- Field names are case-insensitive
- URLs must be absolute (include https://)
- Maximum file size: 64KB
Deployment and Web Server Configuration
File Placement
The security.txt file must be accessible via HTTPS at specific locations. The primary location follows RFC 8615 for well-known URIs:
Web Server Configuration
# Serve security.txt with correct MIME type
<Files "security.txt">
Header set Content-Type "text/plain; charset=utf-8"
Header set Cache-Control "public, max-age=86400"
</Files>
# Enable /.well-known/ directory
RewriteEngine On
RewriteRule ^\.well-known/security\.txt$ /security.txt [L]
location = /.well-known/security.txt {
alias /var/www/html/security.txt;
add_header Content-Type "text/plain; charset=utf-8";
add_header Cache-Control "public, max-age=86400";
}
location = /security.txt {
add_header Content-Type "text/plain; charset=utf-8";
add_header Cache-Control "public, max-age=86400";
}
addEventListener('fetch', event => {
event.respondWith(handleRequest(event.request))
})
async function handleRequest(request) {
const url = new URL(request.url)
if (url.pathname === '/.well-known/security.txt' || url.pathname === '/security.txt') {
const securityTxt = `Contact: mailto:[email protected]
Policy: https://example.com/security-policy
Expires: 2025-12-31T23:59:59.000Z
Canonical: https://example.com/.well-known/security.txt`
return new Response(securityTxt, {
headers: {
'Content-Type': 'text/plain; charset=utf-8',
'Cache-Control': 'public, max-age=86400'
}
})
}
return fetch(request)
}
Complete Examples
Basic Example
Minimal security.txt with required fields only:
# Basic security.txt for example.com Contact: mailto:[email protected] Expires: 2025-12-31T23:59:59.000Z
Comprehensive Example
Full-featured security.txt with all recommended fields:
# Security contact information for example.com # Updated: 2024-01-15 Contact: mailto:[email protected] Contact: https://example.com/security/contact Contact: tel:+1-555-123-4567 # Link to our vulnerability disclosure policy Policy: https://example.com/security/disclosure-policy # PGP key for encrypted communications Encryption: https://example.com/.well-known/pgp-key.asc # Hall of fame for security researchers Acknowledgments: https://example.com/security/hall-of-fame # We prefer reports in English, but accept German and French Preferred-Languages: en, de, fr # Canonical location of this file Canonical: https://example.com/.well-known/security.txt # Security job openings Hiring: https://example.com/careers/security # File expires at end of 2025 Expires: 2025-12-31T23:59:59.000Z
Enterprise Example
Enterprise security.txt with multiple contact methods and detailed policies:
# Enterprise Corp Security Team # For immediate security issues, use the phone number # For non-urgent issues, use email or web form Contact: tel:+1-800-SECURITY (24/7 hotline) Contact: mailto:[email protected] Contact: https://enterprise.com/security/report # Detailed disclosure policy with legal safe harbor Policy: https://enterprise.com/security/responsible-disclosure # Department PGP key (4096-bit RSA) Encryption: https://enterprise.com/.well-known/security-pgp.asc # Security researcher recognition program Acknowledgments: https://enterprise.com/security/researchers # Multilingual support Preferred-Languages: en, es, fr, de, ja # This file's canonical location Canonical: https://enterprise.com/.well-known/security.txt # Join our world-class security team Hiring: https://enterprise.com/careers/security # File valid through Q4 2025 Expires: 2025-12-31T23:59:59.000Z
Validation and Testing
Automated Validation Tools
- securitytxt.org - Official validator
- Heroku validator - Alternative checker
- Browser extensions for quick validation
curlfor basic connectivity testingsecurity-txtPython package- Custom scripts for CI/CD integration
Manual Testing Checklist
Monitoring and Maintenance
Regular Updates: Review and update your security.txt file at least every 6 months, or when contact information changes.
Expiration Monitoring: Set calendar reminders to update the Expires field before it lapses. Some organizations use monitoring tools to alert when expiration approaches.
Contact Testing: Periodically test all contact methods to ensure they reach the security team and generate appropriate responses.
Policy Synchronization: Keep the Policy URL synchronized with your actual vulnerability disclosure process and legal requirements.
Implementation Best Practices
Security Considerations
- Use dedicated security email addresses that are monitored 24/7
- Ensure phone numbers reach security personnel, not general support
- Implement email encryption for sensitive vulnerability reports
- Avoid personal email addresses or unmonitored contact methods
- Serve security.txt over HTTPS only
- Use appropriate caching headers (24-hour cache is reasonable)
- Monitor access logs for unusual patterns or automated scraping
- Ensure the file is accessible even during maintenance windows
Organizational Integration
- Include security.txt in incident response procedures
- Train support staff to escalate security contacts
- Document security.txt maintenance in security policies
- Include file updates in change management processes
- Coordinate policy URLs with legal team
- Ensure contact methods comply with data protection laws
- Review language preferences for regulatory requirements
- Document security.txt for compliance audits
Generate Your security.txt File
Use our interactive generator to create a compliant security.txt file for your domain. The generator includes validation, best practice recommendations, and deployment instructions.