# IndieSecurityTXT > Check a site's security.txt against RFC 9116: location, media type, redirects, format, Contact, Expires, Canonical, and signature, with the fix for each gap. IndieSecurityTXT is a free, one-input web utility for indie makers at indiesecuritytxt.com. It takes one domain, for example example.com, and answers in about ten seconds. Every answer names its source next to it. No account, no card, no premium plan, no upgrade nag, no hidden paywall. Private lookup activity is never published, and nothing on the page counts anyone. Every page is static HTML, and each link below is that page as Markdown or plain text. Made by turushan, https://twitter.com/turushan. ## Pages - [IndieSecurityTXT](https://indiesecuritytxt.com/index.md): what the tool checks, what it takes, and what it promises - [More tools](https://indiesecuritytxt.com/tools.md): the other tools by turushan, one line each - [Notes](https://indiesecuritytxt.com/blog.md): the posts, newest first ## Notes - [Why IndieSecurityTXT exists](https://indiesecuritytxt.com/blog/2026-09-03-why-indiesecuritytxt-exists.md): Check a site's security.txt against RFC 9116, and get the fix for each gap. Free, no account. ## Policies - [security.txt](https://indiesecuritytxt.com/.well-known/security.txt): how to report a vulnerability, in the RFC 9116 shape