generated: '2026-08-05' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts note: >- Only recodetx.com is a ReCode Therapeutics host. developer.wordpress.org / wordpress.org appear because the API entry's humanURL points at the upstream WordPress REST Handbook — the contract this content API implements — and the prober walks every host in apis.yml. Read the wordpress.org rows as upstream context, not as ReCode Therapeutics' posture. findings: - recodetx.com serves TLS 1.3 with a valid certificate but sends NO Strict-Transport-Security header. - No DNSSEC on recodetx.com. - No CAA records on recodetx.com — any CA may issue for the domain. - SPF and DMARC are both published, but the DMARC policy is p=none — monitoring only, no enforcement against spoofed mail. hosts: - host: recodetx.com https: true tls_version: TLSv1.3 cert_expires: Sep 13 17:41:43 2026 GMT hsts: false - host: developer.wordpress.org https: true tls_version: TLSv1.3 cert_expires: Oct 23 19:43:55 2026 GMT hsts: false domains: - domain: recodetx.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none - domain: wordpress.org dnssec: false caa: - 0 issue "letsencrypt.org;validationmethods=dns-01;accounturi=https://acme-v02.api.letsencrypt.org/acme/acct/53691143" - 0 iodef "mailto:caa@wordpress.org" spf: true dmarc: true dmarc_policy: reject