Five years ago we proposed publishing your security contact in DNS, so a researcher can find the right reporting channel before they even load your site.
The 2026 update: records now live at _security.yourdomain, a security_expires freshness field is required, a Standards Track Internet-Draft is in the works, and a sweep found 181 domains publishing records in the wild.
@disclose What about putting this into whois/rdap? imo, that might be a far better place for this sort of thing than yet more overloading of TXT RRs.
@johntimaeus @disclose Not sure why ICANN needs to even be involved, maybe just something like this: https://www.rfc-editor.org/info/rfc7483/#section-4.2
@andy is an expert in this area and maybe could weigh in?