generated: '2026-08-11' method: probed source: live DNS/TLS/HTTP probes of every Core10-lineage host note: >- Core10's own domain, core10.io, still holds a valid certificate and 301-redirects to monarchfts.com. api.getaccrue.com is the only live API host in the lineage; it is the weakest posture here — TLSv1.2 and no HSTS header at all — and it serves a bare nginx 404 on every path, so nothing about the contract behind it is public. hosts: - host: monarchfts.com role: primary website (Core10 successor brand) https: true tls_version: TLSv1.3 cert_expires: Nov 6 14:14:37 2026 GMT hsts: false - host: core10.io role: retired Core10 domain, 301 to monarchfts.com https: true tls_version: TLSv1.3 cert_expires: Nov 5 23:39:55 2026 GMT hsts: false - host: blog.core10.io role: Core10 Insights blog https: true tls_version: TLSv1.3 cert_expires: Sep 20 21:47:03 2026 GMT hsts: true hsts_max_age: 31536000 - host: getaccrue.com role: Accrue product site https: true tls_version: TLSv1.3 cert_expires: Oct 19 07:44:59 2026 GMT hsts: true hsts_max_age: 63072000 - host: api.getaccrue.com role: Accrue API host (live nginx, no public contract) https: true tls_version: TLSv1.2 cert_expires: Oct 13 23:59:59 2026 GMT hsts: false domains: - domain: monarchfts.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none - domain: core10.io dnssec: false caa: - 0 issuewild "comodoca.com" - 0 issuewild "digicert.com; cansignhttpexchanges=yes" - 0 issuewild "letsencrypt.org" - 0 issuewild "pki.goog; cansignhttpexchanges=yes" - 0 issuewild "ssl.com" - 0 issue "comodoca.com" spf: true dmarc: true dmarc_policy: quarantine - domain: getaccrue.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none x-evidence: fetched: '2026-08-11' hosts_probed: 5 domains_probed: 3