generated: '2026-07-25' method: probed source: live DNS/TLS/HTTP probes of every Direct Line Group brand host, the group API host, and the two brand API hosts discovered by DNS enumeration on 2026-07-25 hosts: - host: www.directline.com https: true tls_version: TLSv1.3 cert_expires: Jan 25 12:49:05 2027 GMT cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com hsts: true hsts_max_age: 63072000 - host: www.churchill.com https: true tls_version: TLSv1.3 cert_expires: Jan 25 12:49:05 2027 GMT hsts: true hsts_max_age: 63072000 - host: www.greenflag.com https: true tls_version: TLSv1.3 cert_expires: Mar 3 09:54:18 2027 GMT hsts: true hsts_max_age: 63072000 - host: www.privilege.com https: true tls_version: TLSv1.3 cert_expires: Jan 25 12:49:05 2027 GMT cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com hsts: true hsts_max_age: 63072000 note: Serves the shared www.directline.com certificate — the Privilege brand site runs on the same UK Insurance Limited web estate. - host: www.darwin-insurance.com https: true tls_version: TLSv1.3 cert_expires: Jan 30 11:13:55 2027 GMT cert_subject: CN=www.darwin-insurance.com hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true note: The real Darwin brand site. Policies underwritten by U K Insurance Limited (the Direct Line Group entity, FCA No. 536726) and arranged/administered by iGO4 Limited. - host: www.darwin.co.uk in_group: false https: true tls_version: TLSv1.3 cert_expires: Aug 2 18:53:30 2026 GMT cert_subject: CN=www.darwin.co.uk hsts: false note: NOT a Direct Line Group property. Probed and excluded 2026-07-25 — the host serves a one-line HTML redirector to /lander, which forwards to forsale.godaddy.com/forsale/www.darwin.co.uk, and its /llms.txt states the domain is listed for sale on GoDaddy's aftermarket. Retained here only to record the exclusion so a later round does not re-adopt it. - host: www.bymiles.co.uk https: true tls_version: TLSv1.3 cert_expires: Dec 10 23:59:59 2026 GMT cert_subject: CN=bymiles.co.uk hsts: true hsts_max_age: 15552000 - host: www.directlineforbusiness.co.uk https: true tls_version: TLSv1.3 cert_expires: Sep 13 14:48:51 2026 GMT cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=*.directlineforbusiness.co.uk hsts: true hsts_max_age: 31536000 - host: api.directlinegroup.co.uk https: true tls_version: TLSv1.3 cert_expires: Jun 15 12:34:59 2026 GMT cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=api.directlinegroup.co.uk cert_expired: true hsts: null http_status: 403 note: MuleSoft Anypoint production load balancer (dlg-production-load-balancer.lb.anypointdns.net). Certificate expired 2026-06-15 and has not been renewed; the server sends a TLS CertificateRequest (mutual TLS) and returns an nginx HTTP 403 at every path probed. Partner/internal gateway, not a developer surface. - host: api.bymiles.co.uk https: true tls_version: TLSv1.3 cert_expires: Sep 26 23:59:59 2026 GMT cert_subject: CN=bymiles.co.uk hsts: null http_status: 403 note: Amazon API Gateway (response headers x-amz-apigw-id, x-amzn-errortype ForbiddenException). Root returns {"message":"Forbidden"}; /v1/* returns {"message":"Missing Authentication Token"}. Gated, undocumented. Discovered 2026-07-25 by DNS enumeration — not recorded in the 2026-07-25 initial review. - host: api.darwin.co.uk https: false error: 'TLS handshake failed: tlsv1 unrecognized name (no certificate presented for this SNI name)' note: Resolves to AWS anycast addresses (13.248.169.48, 76.223.54.146) but presents no certificate for the name; not a usable public host. - host: docs.directline.com https: true tls_version: TLSv1.2 cert_expires: Sep 28 08:47:41 2026 GMT cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=docs.directline.com hsts: null http_status: 200 note: Form-based login wall titled "DirectLine - Login"; no reference documentation. Lowest TLS version observed across the estate (TLSv1.2). domains: - domain: directline.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: churchill.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: greenflag.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: privilege.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none note: The only group domain with a permissive DMARC policy (p=none — monitor only). - domain: darwin-insurance.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject dmarc_rua: mailto:dmarcadmin@darwin-insurance.com - domain: darwin.co.uk in_group: false dnssec: false caa: [] spf: true dmarc: false dmarc_policy: null note: Not a group domain — GoDaddy aftermarket listing. Excluded from the summary counts below. - domain: bymiles.co.uk dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: directlineforbusiness.co.uk dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject - domain: directlinegroup.co.uk dnssec: false caa: [] spf: true dmarc: true dmarc_policy: reject summary: scope_note: Counts cover Direct Line Group properties only; www.darwin.co.uk and darwin.co.uk are recorded above but excluded because they are not group properties. hosts_probed: 11 https_reachable: 10 hsts_present: 7 domains_probed: 8 dnssec: 0 caa: 0 spf: 8 dmarc: 7 dmarc_reject: 6 findings: - Every group domain publishes SPF; none publishes CAA and none is DNSSEC-signed. - privilege.com DMARC is p=none (monitor only) while the rest of the estate is p=reject. - The group API host api.directlinegroup.co.uk has been serving an expired certificate since 2026-06-15 while still demanding a client certificate. - www.privilege.com serves the www.directline.com certificate — the Privilege brand runs on the shared U K Insurance Limited web estate. - docs.directline.com is the only host still on TLSv1.2.