generated: '2026-08-29' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts; zeam.com / syncbak.com / www.syncbak.com probed by hand (2026-08-29) hosts: - host: zeammedia.com https: true tls_version: TLSv1.3 cert_expires: Oct 22 22:36:08 2026 GMT hsts: true hsts_max_age: 63072000 - host: zeam.com https: true tls_version: TLSv1.3 cert_expires: Jan 14 23:59:59 2027 GMT hsts: false note: Zeam consumer streaming app host (ASP.NET). No Strict-Transport-Security header returned. - host: www.syncbak.com https: true cert_expires: Nov 17 23:59:59 2026 GMT hsts: false note: Legacy Syncbak host on an AWS ELB; HTTP 301 to https://zeammedia.com/ for every path probed. - host: syncbak.com https: false cert_expires: Nov 17 23:59:59 2026 GMT hsts: false note: 'Apex TLS fails hostname verification: the certificate presents only CN=*.syncbak.com / SAN DNS:*.syncbak.com, which does not match the bare apex. Plain HTTP 302s to https://syncbak.com and therefore dead-ends for a strict client.' domains: - domain: zeammedia.com dnssec: false caa: [] spf: false dmarc: false - domain: zeam.com dnssec: false caa: [] spf: true spf_record: v=spf1 include:_spf.google.com include:sendgrid.net ~all dmarc: true dmarc_policy: none - domain: syncbak.com dnssec: false caa: [] spf: true spf_record: v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net ~all dmarc: true dmarc_policy: none note: DMARC rua aggregate-report mailbox is a named individual; not recorded here per the enrichment PII guardrail.