Appsamurai · Domain Security

Appsamurai Domain Security

Domain security

Domain security posture for Appsamurai, probed live across 9 host(s) and 2 registrable domain(s). 9 host(s) serve HTTPS (up to TLSv1.3); 6 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=none).

CompanyMobileAdvertisingUser AcquisitionMarketingApp GrowthAttributionAnalyticsMobile MarketingSDKStorylyContent ExperienceIn-App StoriesMCPMobile Commerce

Transport & Host Security

appsamurai.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 15 15:04:59 2026 GMT
help.appsamurai.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Nov 9 08:20:21 2026 GMT
api.appsamurai.com
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Nov 9 23:59:59 2026 GMT
www.storyly.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 2 12:32:41 2026 GMT
storyly.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 2 18:11:57 2026 GMT
api.storyly.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Nov 7 23:59:59 2026 GMT
docs.storyly.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 9 07:02:45 2026 GMT
mcp.storyly.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Mar 3 23:59:59 2027 GMT
dashboard.storyly.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Nov 7 23:59:59 2026 GMT

Domain (DNS/Email) Security

appsamurai.com
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none
storyly.io
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-08-13'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts (2026-08-13)
notes: >-
  Round 2 added the storyly.io hosts, which is where App Samurai's live API,
  documentation and MCP surfaces actually run. Two findings worth naming.
  First, TLS posture is good almost everywhere - TLSv1.3 and HSTS on every
  storyly.io host that serves a site - but the two API hosts themselves,
  api.appsamurai.com and api.storyly.io, send NO HSTS header, and
  api.appsamurai.com is still on TLSv1.2.
  Second, the AppSamurai Campaign Spend API is DOCUMENTED over cleartext:
  the Help Center article publishes the base URL as
  http://api.appsamurai.com/api/customer-pull/spent/{api_key}, and the API key is
  a path segment. The host does 301 from :80 to TLS, so the credential is not
  necessarily transmitted in the clear, but a documented http:// URL carrying a
  secret in its path is a real defect in the published guidance.
  Neither domain has DNSSEC or a CAA record. Both publish SPF and DMARC;
  appsamurai.com's DMARC policy is p=none (monitor only) and storyly.io's is
  p=quarantine at pct=5, so neither is meaningfully enforcing.

hosts:
- host: appsamurai.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 15 15:04:59 2026 GMT
  hsts: true
  hsts_max_age: 63072000
- host: help.appsamurai.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Nov  9 08:20:21 2026 GMT
  hsts: true
  hsts_max_age: 63072000
  note: 308-redirects to appsamurai.com/help/.
- host: api.appsamurai.com
  https: true
  tls_version: TLSv1.2
  cert_expires: Nov  9 23:59:59 2026 GMT
  hsts: null
  http_status: 500
  note: >-
    Answers JSON 500 on every path including root. Documented as http:// in the
    Help Center; :80 does 301 to https.
- host: www.storyly.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  2 12:32:41 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  http_status: 200
- host: storyly.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  2 18:11:57 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  http_status: 301
- host: api.storyly.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Nov  7 23:59:59 2026 GMT
  hsts: false
  http_status: 404
  note: >-
    Storyly External API host. No HSTS. CORS is wide open -
    Access-Control-Allow-Origin '*' with Allow-Credentials 'true'.
- host: docs.storyly.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  9 07:02:45 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  http_status: 200
- host: mcp.storyly.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Mar  3 23:59:59 2027 GMT
  hsts: false
  http_status: 404
  note: MCP server host. Root 404s; /mcp and /sse answer.
- host: dashboard.storyly.io
  https: true
  tls_version: TLSv1.3
  cert_expires: Nov  7 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  http_status: 200

domains:
- domain: appsamurai.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
- domain: storyly.io
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
  dmarc_pct: 5
  dmarc_rua: mailto:admin@storyly.io