generated: '2026-08-29' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts note: >- Probed 2026-08-29. TLS 1.3 with a valid certificate, but no HSTS, no CAA record, and no DNSSEC. SPF is published. DMARC is NOT enforced: a `v=DMARC1;p=none;...` string is published as an apex TXT record on supiramedical.com instead of at _dmarc.supiramedical.com, and _dmarc.supiramedical.com returns no TXT record, so no receiver will apply the policy. The web origin sits behind a SiteGround bot-challenge (HTTP 202, `sg-captcha: challenge`) which answered every path probed. hosts: - host: supiramedical.com https: true tls_version: TLSv1.3 cert_expires: Oct 1 04:00:54 2026 GMT hsts: false domains: - domain: supiramedical.com dnssec: false caa: [] spf: true dmarc: false