23andMe · Domain Security

23Andme Domain Security

Domain security

Domain security posture for 23andMe, probed live across 3 host(s) and 2 registrable domain(s). 3 host(s) serve HTTPS (up to TLSv1.3); 3 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

CompanyHealth TechGeneticsGenomicsDNA TestingAncestryConsumer HealthBioinformaticsPrecision MedicinePharmacogenomicsTelehealthHealth Research

Transport & Host Security

www.23andme.org
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 6 21:49:47 2026 GMT
www.23andme.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes
api.23andme.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes

Domain (DNS/Email) Security

23andme.org
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none
23andme.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

23andme-domain-security.yml Raw ↑
generated: '2026-08-15'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
note: >-
  probe-domain-security.py covers the hosts named in apis.yml, which is now the
  canonical www.23andme.org. The 23andme.com apex and the api.23andme.com host were
  probed by hand on the same date and appended here, because 23andMe still runs its
  account, auth, API and support subdomains on 23andme.com even though the consumer
  site migrated to 23andme.org.
hosts:
- host: www.23andme.org
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  6 21:49:47 2026 GMT
  hsts: true
  hsts_max_age: 63072000
- host: www.23andme.com
  https: true
  tls_version: TLSv1.3
  hsts: true
  hsts_max_age: 63072000
  hsts_include_subdomains: true
  hsts_preload: true
  http_status: 301
  redirects_to: https://www.23andme.org/
- host: api.23andme.com
  https: true
  tls_version: TLSv1.3
  cert_verify: 0 (ok)
  hsts: true
  hsts_max_age: 63072000
  hsts_include_subdomains: true
  hsts_preload: true
  http_status: 403
  waf: 'Cloudflare managed challenge (cf-mitigated: challenge)'
domains:
- domain: 23andme.org
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
- domain: 23andme.com
  dnssec: false
  caa: []
  spf: true
  spf_policy: ~all
  dmarc: true
  dmarc_policy: quarantine
  dmarc_subdomain_policy: quarantine
  dmarc_pct: 100
  dmarc_aggregate_reporting: true
  dmarc_forensic_reporting: true
findings:
- id: no-dnssec
  detail: Neither 23andme.org nor 23andme.com is DNSSEC-signed (no DS record).
- id: no-caa
  detail: >-
    Neither domain publishes a CAA record, so any public CA may issue for them. Notable
    for a company holding consumer genetic data.
- id: dmarc-not-reject
  detail: >-
    Both domains sit at p=quarantine rather than p=reject, on both the domain and its
    subdomains. Aggregate and forensic reporting are configured (dmarcian).
- id: hsts-strong
  detail: >-
    All three hosts send HSTS with max-age=63072000 (two years), includeSubDomains and
    preload.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/23andme-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.