generated: '2026-08-04' method: probed source: live DNS/TLS/HTTP probes of apis.yml hosts (probe-domain-security.py, extended by hand to the remaining live execonline.com hosts discovered during contract discovery) hosts: - host: www.execonline.com role: marketing site (WordPress) https: true tls_version: TLSv1.3 cert_expires: Sep 21 07:00:32 2026 GMT hsts: false hsts_max_age: null - host: platform.execonline.com role: learning platform (credentialed SPA) https: true tls_version: TLSv1.3 cert_expires: Oct 25 23:59:59 2026 GMT hsts: true hsts_max_age: 63072000 hsts_include_subdomains: true hsts_preload: true - host: app.execonline.com role: learning platform (credentialed SPA, alternate host) https: true tls_version: TLSv1.3 cert_expires: Oct 25 23:59:59 2026 GMT hsts: true hsts_max_age: 63072000 hsts_include_subdomains: true hsts_preload: true - host: status.execonline.com role: status page (Atlassian Statuspage, vendor-hosted) https: true tls_version: TLSv1.3 cert_expires: Sep 23 05:23:02 2026 GMT hsts: true hsts_max_age: 259200 - host: support.execonline.com role: help center (Intercom, vendor-hosted) https: true tls_version: TLSv1.3 cert_expires: Oct 25 23:59:59 2026 GMT hsts: false hsts_max_age: null - host: connect.execonline.com role: ExecConnect community site (WordPress) https: true tls_version: TLSv1.3 cert_expires: Oct 20 14:25:18 2026 GMT hsts: false hsts_max_age: null domains: - domain: execonline.com dnssec: false caa: [] spf: true spf_record: v=spf1 include:_spf.execonline.com -all dmarc: true dmarc_policy: none dmarc_rua: mailto:dmarc@execonline.com notes: - 'api.execonline.com resolves to GitHub Pages (185.199.108.153) and returns an unconfigured GitHub Pages HTML page with HTTP 200 for every path probed, including /openapi.json and /.well-known/*. It is a catch-all false positive, not an API host.' - 'No HSTS on the marketing site (www) or the ExecConnect community site; the credentialed learning-platform hosts do carry a two-year preloaded HSTS policy.' - 'DMARC is published at p=none (monitor only) with aggregate and forensic reporting; no CAA records are published; the zone is not DNSSEC-signed.' x-evidence: probed: '2026-08-04' method: openssl s_client, curl -I, dig