generated: '2026-08-26' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts note: >- ostro.veeva.com is Ostro's live website host since the March 2026 Veeva Systems acquisition, so its registrable domain (veeva.com) reflects VEEVA's DNS posture, not Ostro's. ostrohealth.com — the domain Ostro registered and still owns, which now 301s to ostro.veeva.com — was probed separately below and carries no SPF, no DMARC, no CAA and no DNSSEC of its own. hosts: - host: www.ostrohealth.com https: true tls_version: TLSv1.3 cert_expires: Oct 1 23:54:14 2026 GMT hsts: true hsts_max_age: 31536000 note: 301 redirects to ostro.veeva.com - host: ostro.veeva.com https: true tls_version: TLSv1.3 cert_expires: Oct 4 19:02:51 2026 GMT hsts: true hsts_max_age: 31536000 domains: - domain: veeva.com dnssec: false caa: - 0 issue "amazonaws.com" - 0 issue "amazontrust.com" - 0 issue "awstrust.com" - 0 issue "digicert.com" - 0 issue "godaddy.com" - 0 issue "letsencrypt.org" spf: true dmarc: true dmarc_policy: quarantine - domain: ostrohealth.com dnssec: false caa: [] spf: false dmarc: false note: >- Probed 2026-08-26 with dig — DNSKEY, CAA, TXT (SPF) and _dmarc TXT all returned empty. Ostro's own registrable domain publishes no email-auth or certificate-issuance policy records; TLS 1.3 and HSTS (max-age 31536000) are present on the web listener.