generated: '2026-09-09' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.advisorcheck.com https: true tls_version: TLSv1.3 cert_expires: Nov 3 01:56:51 2026 GMT hsts: null - host: api.advisorcheck.com https: true tls_version: TLSv1.3 cert_expires: Dec 29 23:59:59 2026 GMT hsts: null domains: - domain: advisorcheck.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none note: Probed 2026-09-09. Neither host sets Strict-Transport-Security (no HSTS on the Vercel front end or the AWS API Gateway host). advisorcheck.com publishes NO DNSSEC and NO CAA record, and DMARC is present but set to p=none (monitor only, no enforcement). DNS also carries THREE conflicting v=spf1 TXT records (Outlook/SES, Zoho One, Zoho zcsend) — RFC 7208 permits exactly one, so receivers must return permerror and SPF is effectively unenforceable on this domain. www.advisorcheck.com is Vercel (cname.vercel-dns.com); api.advisorcheck.com is an AWS API Gateway custom domain; help.advisorcheck.com is Gleap (customers.gleap.help).