Conversation

Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.

The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.

https://blog.disclose.io/dns-security-txt-five-years-on/

1
0
0

@disclose What about putting this into whois/rdap? imo, that might be a far better place for this sort of thing than yet more overloading of TXT RRs.

1
0
0

@jtk @disclose

Given the length of time it takes for ICANN to implement anything, this is probably better.

1
0
0

@johntimaeus @disclose Not sure why ICANN needs to even be involved, maybe just something like this: https://www.rfc-editor.org/info/rfc7483/#section-4.2

@andy is an expert in this area and maybe could weigh in?

1
0
0
@johntimaeus @disclose @jtk there have been recent discussions in the REGEXT working group and the RIPE DB list about pointing to info directly under the control of resource holders. Maybe that will work for this. Generally getting data into the “authoritative” server requires policy.

Putting contact data in DNS is not a new idea. The biggest issue is that very few people care to do it, and they don’t tend to be the people we really need to do it.
0
0
1