generated: '2026-07-31' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts note: The www.npmjs.com host reached via the accessFlow MCP humanURL was excluded — it is a package registry, not an accessiBe-controlled domain. hosts: - host: accessibe.com https: true tls_version: TLSv1.3 cert_expires: Sep 15 22:41:14 2026 GMT hsts: false - host: dashboard.accessibe.com https: true tls_version: TLSv1.3 cert_expires: Oct 18 22:53:42 2026 GMT hsts: false - host: flow-mcp.accessibe.com https: true tls_version: TLSv1.3 cert_expires: Oct 18 22:53:42 2026 GMT hsts: false note: Cloudflare-fronted; unauthenticated GET / returns 404, POST /mcp returns 401. - host: trust.accessibe.com https: true tls_version: TLSv1.3 cert_expires: Sep 13 11:55:29 2026 GMT hsts: true hsts_max_age: 15552000 note: Third-party hosted trust center (trustcenter.anecdotes.ai). - host: status.accessibe.com https: true tls_version: TLSv1.3 cert_expires: Oct 24 08:59:03 2026 GMT hsts: true hsts_max_age: 63113904 note: Third-party hosted status page (statuspage.betteruptime.com). domains: - domain: accessibe.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject findings: - No HSTS on the primary website or on the API host (dashboard.accessibe.com). - No CAA records published for accessibe.com. - DNSSEC is not enabled for accessibe.com. - DMARC is published with an enforcing p=reject policy, and SPF is present.