Security maturity

security.txt check

A small published file that tells security researchers how to report a problem with your site to you.

Check this on your own domain now. It is free with a DomainGuard account, reads only public records, and gives you a report you can send to whoever runs your website.

What we look at

We look for /.well-known/security.txt with a Contact field.

Why it matters to your business

When a researcher finds a flaw in your site, security.txt is how they find someone to tell. Without it, the report may never reach you, or reach you as a public post.

How to fix it

  1. Publish /.well-known/security.txt with at least: Contact: mailto:security@yourdomain and an Expires: date.

If you would rather not touch DNS or server settings yourself, forward this page and your report to whoever manages your website, or ask us to do it.