generated: '2026-08-31' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI servers[] hosts probed: '2026-08-31' previous_probe: '2026-08-09' hosts: - host: atk.tvarka.pro role: ATK API + developer portal https: true tls_version: TLSv1.3 cert_issuer: "Let's Encrypt (CN=YE2)" cert_expires: Nov 16 12:50:18 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: false edge: cloudflare - host: tvarka.pro role: company site, terms, privacy, security page, security.txt, llms.txt https: true tls_version: TLSv1.3 cert_issuer: "Let's Encrypt (CN=YE2)" cert_expires: Nov 16 12:50:18 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: false edge: cloudflare - host: sign-api.tvarka.pro role: Tvarka Sign API + MCP server (first probed 2026-08-31) https: true tls_version: TLSv1.3 cert_issuer: "Let's Encrypt (CN=YE2)" cert_expires: Nov 16 12:50:18 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: false edge: cloudflare - host: sign.tvarka.pro role: pairing landing host referenced by AuthPairingHint.pairingUrl https: true tls_version: TLSv1.3 cert_issuer: "Let's Encrypt (CN=YE2)" cert_expires: Nov 16 12:50:18 2026 GMT hsts: true hsts_max_age: 31536000 hsts_include_subdomains: true hsts_preload: false edge: cloudflare domains: - domain: tvarka.pro dnssec: false dnssec_note: No DS record is published at the parent, so the zone is not DNSSEC-signed. caa: - 0 issue "comodoca.com" - 0 issue "digicert.com; cansignhttpexchanges=yes" - 0 issue "letsencrypt.org" - 0 issue "pki.goog; cansignhttpexchanges=yes" - 0 issue "sectigo.com" - 0 issue "ssl.com" - 0 issuewild "comodoca.com" - 0 issuewild "digicert.com; cansignhttpexchanges=yes" - 0 issuewild "letsencrypt.org" - 0 issuewild "pki.goog; cansignhttpexchanges=yes" - 0 issuewild "sectigo.com" - 0 issuewild "ssl.com" spf: true spf_record: v=spf1 include:_spf.purelymail.com ~all dmarc: true dmarc_policy: quarantine dmarc_record: 'v=DMARC1; p=quarantine; rua=mailto:dmarc@tvarka.pro; ruf=mailto:dmarc@tvarka.pro; fo=1; adkim=r; aspf=r' txt_records_of_note: - record: 'v=MCPv1; k=ed25519; p=' zone: tvarka.pro kind: MCP server identity note: >- An MCPv1 DNS TXT record publishing an ed25519 public key at the apex. Found 2026-08-31; it was not present, or not looked for, on 2026-08-09. It sits alongside the live MCP server at https://sign-api.tvarka.pro/mcp, so this is a DNS-level identity claim for that server rather than a stray record. Key value not reproduced here - it is a public key, but there is no reason to mirror it and every reason to read it from DNS at verification time. - record: purelymail_ownership_proof=... zone: tvarka.pro kind: mail-provider domain verification posture: strengths: - HSTS with a one-year max-age and includeSubDomains on every host in the estate. - TLS 1.3 everywhere, single wildcard-style certificate across all four hosts. - CAA published, restricting issuance to six named CAs for both exact and wildcard names. - SPF and DMARC published, DMARC at p=quarantine with both aggregate and forensic reporting. gaps: - No DNSSEC. - HSTS is not preloaded. - DMARC is p=quarantine rather than p=reject. changes_since_previous_probe: - Certificates renewed - expiry moved from Sep 18 2026 to Nov 16 2026. - >- HSTS max-age raised from 15552000 (180 days) to 31536000 (1 year) on every host, still with includeSubDomains. - New host in the estate - sign-api.tvarka.pro, with the same posture as the rest. - An MCPv1 DNS TXT identity record is now published at the tvarka.pro apex.