generated: '2026-08-06' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.airtm.com https: true tls_version: TLSv1.3 cert_expires: Oct 4 14:41:10 2026 GMT hsts: null - host: docs.airtm.com https: true tls_version: TLSv1.3 cert_expires: Dec 11 23:59:59 2026 GMT hsts: false - host: api.enterprise.airtm.com https: true tls_version: TLSv1.3 cert_expires: Nov 7 23:59:59 2026 GMT hsts: false - host: payments.air-pay.io https: true tls_version: TLSv1.3 cert_expires: Feb 13 23:59:59 2027 GMT hsts: false note: Production base URL of the legacy Enterprise API V1. - host: payments.static-stg.tests.airtm.org https: true tls_version: TLSv1.3 cert_expires: Mar 12 23:59:59 2027 GMT hsts: false note: Sandbox base URL declared in the V1 OpenAPI servers[]. - host: app.airtm.com https: true hsts: true hsts_max_age: 63072000 hsts_preload: true hsts_include_subdomains: true - host: enterprise.airtm.com https: true hsts: true hsts_max_age: 63072000 hsts_preload: true hsts_include_subdomains: true - host: trust.airtm.com https: true hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: status.airtm.com https: true hsts: false domains: - domain: airtm.com dnssec: true caa: [] spf: true dmarc: true dmarc_policy: quarantine - domain: air-pay.io dnssec: true caa: [] spf: false dmarc: false note: The host serving the legacy V1 payments API sits on a domain with no SPF and no DMARC record. notes: 'HSTS posture is inconsistent across the estate: app.airtm.com and enterprise.airtm.com are preloaded with a 2-year max-age, but the API hosts that carry the money-movement traffic (api.enterprise.airtm.com, payments.air-pay.io) and the docs host send no HSTS header at all. Neither airtm.com nor air-pay.io publishes a CAA record, so any CA may issue for them. airtm.com''s DMARC policy is p=quarantine (not reject); air-pay.io publishes neither SPF nor DMARC.'