generated: '2026-08-05' method: probed source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts hosts: - host: utilidata.com https: true tls_version: TLSv1.3 cert_expires: Oct 10 08:03:16 2026 GMT hsts: true hsts_max_age: 63072000 - host: developer.utilidata.com https: false tls_version: TLSv1.3 cert_subject: CN=developer.utilidata.com cert_issuer: 'C=US, O=Let''s Encrypt, CN=R12' cert_not_before: Apr 8 09:08:40 2026 GMT cert_expires: Jul 7 09:08:39 2026 GMT cert_expired: true hsts: null x-finding: >- EXPIRED CERTIFICATE. The Karman developer host has been serving an expired Let's Encrypt certificate since 2026-07-07 — every browser, crawler and agent gets a TLS error rather than the site. Probed manually on 2026-08-05 (curl exit 60); the host is not listed in apis.yml because it is unreachable, so the automated probe does not cover it. domains: - domain: utilidata.com dnssec: false caa: [] spf: true dmarc: true dmarc_policy: none