reddit hackernews mail facebook facebook linkedin
findsecuritycontacts.com

findsecuritycontacts.com

Scans the top 500 sites daily for their security.txt file or DNS records.
#dns   #emails   #online  

A security contact is a way for websites or services to sign post where and how security researchers can get in contact. It also typically describes whether there is any vulnerability disclosure policy or bug bounty.

There are two methods to set security contacts, with a security.txt file served on a known path and with DNS TXT records.

You can also query any website to see if there is a security.txt file (RFC 9116) or DNS records and whether they appear to be formatted correctly.