security-txt.eu

Check your security.txt, signature and keys included

Enter your domain. The check fetches the file, verifies structure, expiry date, links, keys and the OpenPGP signature, and tells you how to fix each finding.

We fetch https://your-domain/.well-known/security.txt. A check takes a few seconds.

Standard

The IETF specification: is the file valid and trustworthy?

What the check covers

The rules come from RFC 9116, the IANA registry of security.txt fields and sections 4.2, 4.3.1, 4.3.2 and 4.5.3 of BSI TR-03183-3, and for keys and signature from BSI TR-03116-4 and the ECCG catalogue. Every finding cites the clause it is based on.

Retrieval

Is the file at /.well-known/security.txt, reachable over HTTPS with a valid certificate? Where do redirects lead? Does the server send text/plain; charset=utf-8 or an error page dressed as HTML? Does a firewall block automated requests, which the TR rules out in section 4.2.11?

Structure and content

Every line is a field or a comment, values in ASCII only. Contact and Expires are present, Expires exactly once, in RFC 3339 format, recommended at most one year ahead. Canonical names the actual location. Linked pages respond, mail domains have an MX, A or AAAA record. Typical mistakes such as Acknowledgements instead of Acknowledgments are caught, and the newer fields CSAF and Bug-Bounty are known.

Signature and keys

If the file is signed, the check verifies the OpenPGP signature cryptographically: with the keys from the Encryption fields, from the reporting page or, if none fits, from keys.openpgp.org. Plus algorithm and key length, hash algorithm, expiry and, under the TR, the algorithms permitted by BSI TR-03116-4 and the ECCG catalogue and the five-year limit.

BSI TR-03183-3

With the stricter standard: contacts in the order PSIRT, CSIRT, reporting page, recognisable role mailboxes, one key per mailbox as .asc, English in Preferred-Languages, Policy, a mandatory signature and the recommended comments.

What no check can see

Whether anyone reads the mailbox, whether the policy holds up and whether reporters get a timely answer. Only a real case or a test run shows that: send a message to the address yourself.

No file yet? The generator writes one in a few minutes. All fields and the most common mistakes are explained in the guide.