generated: '2026-08-26' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.neuehouse.com https: true tls_version: TLSv1.3 cert_expires: Nov 14 20:42:50 2026 GMT hsts: false - host: bradbury.neuehouse.com https: true tls_version: TLSv1.3 cert_valid_for_host: false cert_cn: '*.netlify.app' cert_issuer_org: Netlify, Inc hsts: null finding: 'DEFECT — TLS name mismatch. This host serves a real NeueHouse site (HTML title "NeueHouse: Bradbury", 28KB, HTTP 200 when verification is disabled) from Netlify, but presents a *.netlify.app certificate. subjectAltName does not match bradbury.neuehouse.com, so every standards-compliant client fails the handshake: curl returns exit 60 and browsers show a full-page interstitial. The host is reachable ONLY by disabling certificate verification. NeueHouse links to it from its own live content API (location record id 6421), so the broken link is self-referential. Fix is a custom-domain certificate on the Netlify site.' probed: '2026-08-26' domains: - domain: neuehouse.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none note: 'forgeglobal.com was removed from this probe set: it is a secondary-market share-listing page that seeded this repo, not a host NeueHouse operates. Hosts probed are the ones NeueHouse actually serves.'