generated: '2026-09-05' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: usa.1more.com https: true tls_version: TLSv1.3 cert_expires: Oct 26 02:57:32 2026 GMT hsts: true hsts_max_age: 7889238 - host: www.1more.com https: true tls_version: TLSv1.3 cert_expires: Feb 2 02:20:11 2027 GMT hsts: false hsts_max_age: null note: 1MORE's corporate site (nginx origin). Probed manually 2026-09-05; not covered by the automated pass because apis.yml carries it as CorporateWebsite. No Strict-Transport-Security header is returned. domains: - domain: 1more.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none note: usa.1more.com is the Shopify-hosted US storefront and carries HSTS; www.1more.com is 1MORE's own corporate origin and does not. The apex https://1more.com returned HTTP 504 on every request and global.1more.com did not resolve to a reachable origin, so neither could be probed. The registrable domain 1more.com publishes SPF and DMARC but DMARC policy is p=none (monitor only), and there is no DNSSEC and no CAA record.