generated: '2026-07-27' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.centrica.com https: true tls_version: TLSv1.3 cert_expires: Sep 10 16:56:03 2026 GMT hsts: true hsts_max_age: 31536000 - host: api-developer.dev.fieldops.centrica.com https: true tls_version: TLSv1.3 cert_expires: Sep 10 11:18:52 2026 GMT hsts: true hsts_max_age: 31536000 - host: api.dev.fieldops.centrica.com https: true tls_version: TLSv1.3 cert_expires: Sep 10 11:18:52 2026 GMT hsts: null - host: www.britishgas.co.uk https: true cert_expires: Oct 26 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 domains: - domain: centrica.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: britishgas.co.uk dnssec: false caa: [] spf: true spf_policy: softfail dmarc: true dmarc_policy: reject - domain: bordgaisenergy.ie dnssec: false caa: [] spf: true spf_policy: fail dmarc: true dmarc_policy: reject - domain: hivehome.com dnssec: false caa: [] spf: true spf_policy: softfail dmarc: true dmarc_policy: reject notes: >- Added on the 2026-07-27 enrichment round: the British Gas retail host and the three sibling brand domains (britishgas.co.uk, bordgaisenergy.ie, hivehome.com) were probed by hand because they carry the group's public surface but are not apis.yml baseURL hosts. All four registrable domains share the same posture — DMARC p=reject with Valimail aggregate reporting, SPF present, no CAA records published and no DNSSEC. TLS 1.3 and a one-year HSTS max-age on every reachable web host; the FieldOps development gateway (api.dev.fieldops.centrica.com) is the only host that sends no HSTS header.