generated: '2026-07-12' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: api.lexware.io https: true tls_version: TLSv1.3 cert_expires: Nov 10 23:59:59 2026 GMT hsts: false http_status: 200 - host: developers.lexware.io https: true tls_version: TLSv1.3 cert_expires: Oct 30 23:59:59 2026 GMT hsts: false http_status: 200 - host: www.lexware.de https: true tls_version: TLSv1.3 cert_expires: Dec 12 23:59:59 2026 GMT hsts: false http_status: 200 - host: app.lexware.de https: true cert_expires: Nov 2 23:59:59 2026 GMT hsts: true hsts_max_age: 63072000 http_status: 301 domains: - domain: lexware.de dnssec: true caa: [] spf: true spf_policy: '-all' dmarc: true dmarc_policy: quarantine - domain: lexware.io dnssec: false caa: [] dmarc: true dmarc_policy: reject notes: >- The current API gateway (api.lexware.io) and developer portal (developers.lexware.io) serve valid TLSv1.3 certificates but did not return an HSTS header on the probed root responses; the customer web app (app.lexware.de) does send HSTS (max-age 63072000, includeSubDomains). The primary corporate domain lexware.de is DNSSEC-signed with an SPF hard-fail (-all) and a DMARC quarantine policy; the lexware.io API domain publishes a strict DMARC reject policy. No CAA records were observed on either apex domain at probe time. The legacy lexoffice.io API host was retired at the end of 2025 and was not probed.