security.txt Validator
Lint Contact, Expires, duplicate fields, unknown fields, and URI shape locally.
security.txt validator workspace
Lint security.txt fields and copy a normalized RFC 9116 file.
security.txt input
Cleaned file
Validation
Ready
Contact and Expires are present, the date is in the future, and the cleaned file is ready to copy.
Questions
What does Security.txt Validator check?
It checks pasted security.txt content for required fields, duplicate single-use fields, URI shape, expiration, and unknown names.
Does this fetch my live security.txt URL?
No. Paste the file content. The validator runs locally and does not make external requests.
Which fields are required?
RFC 9116 requires Contact and Expires. The validator also checks duplicate single-use fields and unknown field names.
Can warnings still be published?
Maybe. Warnings highlight issues worth reviewing, while errors cover missing or invalid core fields.
Does Utilumo upload my input?
No. This tool is designed for local browser processing and does not send your input to a server.
Do I need an account?
No. Utilumo tools are built to work without accounts or sign-in.