generated: '2026-08-04' method: probed source: live DNS/TLS/HTTP probes of apis.yml + additional KreditBee hosts note: >- Every KreditBee host observed sits behind Cloudflare and terminates TLS 1.3 with HSTS at the one-year maximum. Neither registrable domain is DNSSEC-signed. kreditbee.in publishes a broad CAA policy naming six issuers; krazybee.com (the RBI-registered NBFC arm, KrazyBee Services Limited) publishes no CAA record at all. Both domains publish a hard-fail SPF record and a DMARC record at p=quarantine rather than p=reject. hosts: - host: www.kreditbee.in role: consumer website (single-page app) https: true tls_version: TLSv1.3 cert_expires: Apr 10 23:59:59 2027 GMT hsts: true hsts_max_age: 31536000 - host: kreditbee.in role: apex (serves the same SPA) https: true tls_version: TLSv1.3 cert_expires: Apr 10 23:59:59 2027 GMT hsts: true hsts_max_age: 31536000 - host: api.kreditbee.in role: private mobile/web backend (AWS API Gateway behind Cloudflare) https: true tls_version: TLSv1.3 cert_expires: Apr 10 23:59:59 2027 GMT hsts: true hsts_max_age: 31536000 anonymous_response: 403 ForbiddenException (application/json) - host: www.krazybee.com role: KrazyBee Services Limited (RBI-registered NBFC) website https: true tls_version: TLSv1.3 cert_expires: Dec 30 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 domains: - domain: kreditbee.in dnssec: false caa: - 0 issue "letsencrypt.org" - 0 issue "pki.goog; cansignhttpexchanges=yes" - 0 issue "sectigo.com" - 0 issue "ssl.com" - 0 issue "comodoca.com" - 0 issue "digicert.com; cansignhttpexchanges=yes" - 0 issuewild "comodoca.com" - 0 issuewild "digicert.com; cansignhttpexchanges=yes" - 0 issuewild "letsencrypt.org" - 0 issuewild "pki.goog; cansignhttpexchanges=yes" - 0 issuewild "ssl.com" spf: true dmarc: true dmarc_policy: quarantine - domain: krazybee.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: quarantine x-evidence: fetched: '2026-08-04' probes: - {host: www.kreditbee.in, method: TLS handshake + HTTP HEAD} - {host: kreditbee.in, method: TLS handshake + HTTP HEAD} - {host: api.kreditbee.in, method: TLS handshake + HTTP HEAD, http_status: 403} - {host: www.krazybee.com, method: TLS handshake + HTTP HEAD} - {domain: kreditbee.in, method: 'dig DNSKEY/CAA/TXT/_dmarc'} - {domain: krazybee.com, method: 'dig DNSKEY/CAA/TXT/_dmarc'}