generated: '2026-07-25' method: probed source: >- live DNS/TLS/HTTP probes of the apis.yml hosts (0-working/probe-domain-security.py) extended by hand to every operating Blue Cross member-plan host in the federation hosts: - host: www.bluecross.ca plan: Canadian Association of Blue Cross Plans https: true tls_version: TLSv1.3 cert_expires: Oct 17 16:18:54 2026 GMT hsts: true hsts_max_age: 300 note: >- HSTS max-age of 300 seconds is far below the 31536000 the member plans use and below any preload threshold — effectively a token policy on the national brand site. - host: pac.bluecross.ca plan: Pacific Blue Cross https: true tls_version: TLSv1.3 cert_expires: Oct 18 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: ab.bluecross.ca plan: Alberta Blue Cross https: true tls_version: TLSv1.3 cert_expires: Oct 23 08:03:30 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true note: Cloudflare bot management returns 403/interstitial to non-browser clients. - host: on.bluecross.ca plan: Ontario / Quebec Blue Cross (Canassurance) https: true tls_version: TLSv1.3 cert_expires: Sep 11 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: www.medaviebc.ca plan: Medavie Blue Cross https: true tls_version: TLSv1.3 cert_expires: Oct 9 05:45:50 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: www.sk.bluecross.ca plan: Saskatchewan Blue Cross https: true tls_version: TLSv1.3 cert_expires: Oct 19 19:17:31 2026 GMT hsts: true hsts_max_age: 15552000 hsts_include_subdomains: true - host: www.mb.bluecross.ca plan: Manitoba Blue Cross https: true tls_version: TLSv1.3 cert_expires: Jan 25 23:59:59 2027 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: false domains: - domain: bluecross.ca dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none nameservers: [dns1.cidc.telus.com, dns2.cidc.telus.com] note: >- DMARC is published but at p=none (monitor only), so no enforcement against spoofed mail from the brand domain. No CAA records, so certificate issuance is unconstrained. No DNSSEC. - domain: medaviebc.ca dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none nameservers: [simon.ns.cloudflare.com, kia.ns.cloudflare.com] note: >- SPF and DMARC are delegated to Proofpoint (pphosted.com); DMARC is also p=none. No CAA, no DNSSEC. summary: https_everywhere: true tls13_everywhere: true hsts_hosts: 7 dnssec_domains: 0 caa_domains: 0 dmarc_enforcing_domains: 0 note: >- Transport hygiene is uniformly good across the federation; domain-level controls (DNSSEC, CAA, DMARC enforcement) are uniformly absent.