generated: '2026-07-25' method: probed source: >- live DNS/TLS/HTTP probes 2026-07-25 of the apis.yml host plus every resolvable Prudential plc market operating-company host (extends the mechanical 0-working/probe-domain-security.py run, which covers only the apis.yml hosts) note: >- Prudential plc exposes no API host, so this profile covers the corporate site and the market consumer sites instead. The result is the most positive technical finding in this record: the group runs a visibly CENTRALISED email and transport security posture across eleven jurisdictions - TLS 1.3 everywhere, HSTS everywhere, and one shared PowerDMARC/PowerSPF tenant with a common aggregate-report mailbox on every domain. Absence of CAA and (mostly) of DNSSEC is recorded as observed fact, not judgement. hosts: - host: www.prudentialplc.com role: group corporate site https: true tls_version: TLSv1.3 cert_expires: Oct 9 06:45:13 2026 GMT hsts: true hsts_max_age: 31557600 hsts_include_subdomains: false hsts_preload: false - host: www.prudential.com.hk role: Prudential Hong Kong Limited https: true tls_version: TLSv1.3 cert_expires: Sep 24 04:28:38 2026 GMT hsts: true hsts_max_age: 31557600 hsts_include_subdomains: false hsts_preload: false - host: www.prudential.com.sg role: Prudential Assurance Company Singapore https: true tls_version: TLSv1.3 cert_expires: Dec 9 23:59:59 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: true note: The only host in the estate with includeSubDomains and preload - the strongest HSTS posture in the group. - host: www.prudential.co.id role: PT Prudential Life Assurance https: true tls_version: TLSv1.3 cert_expires: Oct 9 06:45:13 2026 GMT hsts: true hsts_max_age: 31557600 hsts_include_subdomains: false hsts_preload: false - host: www.prudential.com.vn role: Prudential Vietnam Assurance https: true tls_version: TLSv1.3 cert_expires: Oct 8 16:33:45 2026 GMT hsts: true hsts_max_age: 31557600 hsts_include_subdomains: false hsts_preload: false - host: www.prulifeuk.com.ph role: Pru Life UK https: true tls_version: TLSv1.3 cert_expires: Oct 8 16:33:45 2026 GMT hsts: true hsts_max_age: 31557600 hsts_include_subdomains: false hsts_preload: false - host: www.prubsn.com.my role: Prudential BSN Takaful Berhad https: true tls_version: TLSv1.3 cert_expires: Oct 8 16:33:45 2026 GMT hsts: true hsts_max_age: 31557600 hsts_include_subdomains: false hsts_preload: false domains: - domain: prudentialplc.com dnssec: false caa: [] spf: true spf_record: v=spf1 include:7fg5yhj2mj.powerspf.com -all dmarc: true dmarc_policy: reject dmarc_record: 'v=DMARC1; p=reject; aspf=s; rua=mailto:rzrknxeawk@rua.powerdmarc.com; fo=0:1:d:s; t=n;' note: >- The only domain in the estate at p=reject, with strict SPF alignment (aspf=s). The _dmarc record is a CNAME into hosteddmarc.dmarc-dns.com, confirming a managed DMARC service. - domain: prudential.com.hk dnssec: false caa: [] spf: true spf_record: v=spf1 include:1smpil468z.powerspf.com -all dmarc: true dmarc_policy: quarantine - domain: prudential.com.sg dnssec: false caa: [] spf: true spf_record: v=spf1 include:e91ggo5akw.powerspf.com -all dmarc: true dmarc_policy: quarantine - domain: prudential.co.id dnssec: true dnssec_ds: 41055 13 2 B3D906BCC31C0CB11609160641E76C9D85815087DDC109B8AE3F7EEC54E2AF74 caa: [] spf: true spf_record: v=spf1 include:epedd15chq.powerspf.com -all dmarc: true dmarc_policy: quarantine note: The only DNSSEC-signed domain found in the estate (algorithm 13, ECDSA P-256 SHA-256). - domain: prudential.com.vn dnssec: false caa: [] spf: true spf_record: v=spf1 include:gru39w8qi1.powerspf.com -all dmarc: true dmarc_policy: quarantine - domain: prulifeuk.com.ph dnssec: false caa: [] spf: true spf_record: v=spf1 include:8wuhbgo5wi.powerspf.com -all dmarc: true dmarc_policy: quarantine note: Adds aspf=s (strict SPF alignment) to the group's standard quarantine policy. - domain: prubsn.com.my dnssec: false caa: [] spf: true spf_record: v=spf1 include:bzxv93thzz.powerspf.com -all dmarc: true dmarc_policy: quarantine group_posture: centralised_email_security: true evidence: >- All seven domains publish an SPF record of the identical shape "v=spf1 include:.powerspf.com -all" with a hard fail, and all seven publish a DMARC record whose aggregate-report address is the SAME mailbox, rzrknxeawk@rua.powerdmarc.com, with several also adding a local market rua. That is one PowerDMARC tenant administered centrally for the whole group rather than seven independently managed estates. tls: TLS 1.3 on every host probed; no host fell back below TLS 1.2. hsts: HSTS present on every host; six of seven use max-age 31557600 (one year in seconds, Adobe Experience Manager default), Singapore alone uses 31536000 with includeSubDomains and preload. dnssec: 1 of 7 domains signed (prudential.co.id). caa: 0 of 7 domains publish a CAA record - certificate issuance is unconstrained at DNS level across the entire estate. gap: >- The clearest actionable gap. Adding CAA records and lifting the market domains from p=quarantine to p=reject would cost nothing and would match the discipline already demonstrated by the shared SPF/DMARC tenancy.