generated: '2026-08-11' method: probed source: live DNS/TLS/HTTP probes of the darrow.ai marketing, portal, platform and identity hosts hosts: - host: www.darrow.ai role: marketing site (Webflow) https: true tls_version: TLSv1.3 cert_expires: Oct 2 20:17:01 2026 GMT hsts: true hsts_max_age: 31536000 - host: auth.darrow.ai role: identity provider (Auth0 tenant) https: true tls_version: TLSv1.3 cert_expires: Sep 26 16:32:07 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: portal.darrow.ai role: customer portal entry point https: true tls_version: TLSv1.3 cert_expires: Sep 25 01:49:39 2026 GMT hsts: true hsts_max_age: 63072000 - host: platform.darrow.ai role: application host https: true tls_version: TLSv1.3 cert_expires: Sep 12 15:11:28 2026 GMT hsts: true hsts_max_age: 63072000 domains: - domain: darrow.ai dnssec: false caa: [] spf: true spf_record: v=spf1 include:_spf.google.com include:45692213.spf02.hubspotemail.net include:amazonses.com include:_spf.salesforce.com -all dmarc: true dmarc_policy: reject observations: - Every host is TLS 1.3 with HSTS; the identity tenant additionally sets includeSubDomains. - No CAA record and no DNSSEC on darrow.ai — both are absent, not unprobed. - SPF ends in -all and DMARC policy is p=reject, which is a strong published email posture.