I do, but with a few tweaks that cut most of the junk the other comments mention:
- Point
Contact:at a dedicated alias, not your main inbox, and filter it hard. If the noise gets bad you can drop the alias without touching anything else. - Add a
Policy:line linking to a short page that says plainly there is no bug bounty and no payment for reports. Most beg-bounty mails are mass-sent with a payment ask, so this gives you something to point them at and lets you bin them without guilt. - Don’t forget
Expires:, it’s actually required by RFC 9116 and a lot of hand-written files leave it out. Set a calendar reminder to bump it. - Serve it at
/.well-known/security.txt; the root path is only a legacy fallback.
Whether it’s worth it for a homelab is debatable, but if you host anything other people rely on (a Matrix/Lemmy instance, a shared Nextcloud), having one real contact path beats someone finding a hole and having nowhere to send it.
- Point
No, because it invites beg bounties and slop reports.
If you run any sort of public facing website, you’ll likely get some of those eventually.
No, it’s free real estate for scams, slop and the like.
Yes, but I should probably also put one up on my other domains
I was gonna say you had it in the wrong place, but it looks like you also serve it in the /.well-known/ location as well.
Nice domain!
Do people actually contact you with that?
Yep. Looots of phishing emails.
I have a security.txt with an email to report vulnerabilities and a public key to encrypt sensitive information. The only reports I ever got were on the contract us form, unencrypted.
Nope, maybe I should ! Thanks for the reminder !
Why so people ignore that too?
Nope.






