generated: '2026-09-05' method: probed source: 'live DNS/TLS/HTTP probes of every host in apis.yml plus the MCP, dashboard, status and SDK-distribution hosts; baseline written by 0-working/probe-domain-security.py and extended by hand-probed hosts the script did not derive' checked: '2026-09-05' hosts: - host: www.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Oct 26 07:06:17 2026 GMT' hsts: true hsts_max_age: 63072000 - host: help.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Nov 24 10:29:10 2026 GMT' hsts: true hsts_max_age: 63072000 - host: api.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Feb 25 23:59:59 2027 GMT' hsts: false hsts_max_age: null note: 'The API host itself sends no Strict-Transport-Security header, although the docs state all requests must be made over HTTPS.' - host: mcp.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Feb 21 23:59:59 2027 GMT' hsts: false hsts_max_age: null - host: app.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Jan 31 23:59:59 2027 GMT' hsts: false hsts_max_age: null - host: sdk-download.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Jan 31 23:59:59 2027 GMT' hsts: false hsts_max_age: null - host: status.airbridge.io https: true tls_version: TLSv1.3 cert_expires: 'Oct 7 17:27:34 2026 GMT' hsts: true hsts_max_age: 259200 note: Atlassian Statuspage-hosted. - host: www.ab180.co https: true tls_version: TLSv1.3 cert_expires: 'Nov 30 02:17:58 2026 GMT' hsts: true hsts_max_age: 31536000 domains: - domain: airbridge.io dnssec: false caa: [] spf: false dmarc: true dmarc_policy: none note: 'No SPF record on the apex — the only TXT records are a Salesforce verification token and two Google site-verification tokens. DMARC exists but at p=none, which monitors without enforcing.' - domain: ab180.co dnssec: false caa: [] spf: true spf_record: 'v=spf1 include:_spf.google.com include:amazonses.com include:sendgrid.net ~all' dmarc: true dmarc_policy: none note: 'DMARC reporting addresses point at an individual mailbox rather than a role address.' findings: - 'No CAA record on either registrable domain — any CA may issue for airbridge.io and ab180.co.' - 'No DNSSEC on either domain.' - 'airbridge.io publishes no SPF record at all, while ab180.co does.' - 'Both DMARC policies are p=none, so neither enforces.' - 'TLS 1.3 everywhere probed, and no expired or near-expiry certificate.'