generated: '2026-07-12' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: api.tiendanube.com https: true tls_version: TLSv1.3 cert_expires: Oct 10 08:15:08 2026 GMT hsts: false hsts_max_age: null - host: tiendanube.com https: true tls_version: TLSv1.3 cert_expires: Aug 22 07:31:38 2026 GMT hsts: false hsts_max_age: null - host: www.tiendanube.com https: true tls_version: TLSv1.3 cert_expires: Aug 22 06:31:23 2026 GMT hsts: false hsts_max_age: null - host: nuvemshop.com.br https: true tls_version: TLSv1.3 cert_expires: Aug 24 17:55:29 2026 GMT hsts: false hsts_max_age: null domains: - domain: tiendanube.com dnssec: false caa: [] spf: true spf_record: 'v=spf1 include:_spf.tiendanube_com._d.easydmarc.pro ~all' dmarc: true dmarc_policy: quarantine - domain: nuvemshop.com.br dnssec: false caa: [] spf: true spf_record: 'v=spf1 include:_spf.nuvemshop_com_br._d.easydmarc.pro include:registrarmail.net ~all' dmarc: true dmarc_policy: quarantine notes: >- All probed hosts serve HTTPS over TLS 1.3. No HTTP Strict-Transport-Security (HSTS) response header was observed on the apex, www, or API hosts at probe time. Neither apex domain publishes CAA records or has DNSSEC (DS) enabled. Both domains publish SPF (soft-fail ~all) and DMARC at policy=quarantine (pct=100), managed via EasyDMARC.