generated: '2026-08-05' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: www.rokid.com https: true tls_version: TLSv1.3 cert_expires: Feb 3 08:30:20 2027 GMT hsts: true hsts_max_age: 5184000 - host: x-docs.rokid.com https: true tls_version: TLSv1.3 cert_expires: Feb 3 08:30:20 2027 GMT hsts: true hsts_max_age: 31536000 - host: api.rokid.com https: true tls_version: TLSv1.3 cert_expires: Feb 3 08:30:20 2027 GMT hsts: null - host: global.rokid.com https: true tls_version: TLSv1.3 cert_expires: Sep 9 10:27:32 2026 GMT hsts: true hsts_max_age: 7889238 hsts_include_subdomains: false - host: open.rokid.com https: true tls_version: TLSv1.3 cert_expires: Feb 3 08:30:20 2027 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: maven.rokid.com https: true tls_version: TLSv1.2 cert_expires: Feb 3 08:30:20 2027 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true - host: openapi.rokid.com https: true tls_version: TLSv1.2 cert_expires: Feb 3 08:30:20 2027 GMT hsts: true hsts_max_age: 15724800 hsts_include_subdomains: true note: every path answers HTTP 401 anonymously findings: - api.rokid.com — the production API host — sends no Strict-Transport-Security header, while every other Rokid host does. - maven.rokid.com and openapi.rokid.com negotiate TLS 1.2 rather than 1.3. - rokid.com publishes no CAA records and DNSSEC is not enabled. - The DMARC record is published with p=none, so it monitors without enforcing. domains: - domain: rokid.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none