Brisk Health · Domain Security

Brisk Health Domain Security

Domain security

Domain security posture for Brisk Health, probed live across 3 host(s) and 3 registrable domain(s). 3 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC present, SPF absent, DMARC absent.

CompanyHealthcareUrgent CarePrimary CareHome HealthClinicsColorado

Transport & Host Security

www.briskhealthurgentcare.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 6 01:16:14 2026 GMT
briskhealth.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 28 11:02:37 2026 GMT
brisk.health
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Mar 27 05:04:50 2026 GMT

Domain (DNS/Email) Security

briskhealthurgentcare.com
DNSSEC: yes · SPF: no · DMARC: no · CAA: none
briskhealth.com
DNSSEC: no · SPF: yes · DMARC: yes (p=invalid-multiple-records) · CAA: none
brisk.health
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none

Source

Domain Security

brisk-health-domain-security.yml Raw ↑
generated: '2026-08-08'
method: probed
source: live DNS/TLS/HTTP probes of every Brisk Health host found during enrichment
note: >-
  Scoped to domains Brisk Health controls. The mechanical probe also walked
  dev.wix.com / wix.com because the Wix Site MCP documentation is the only human
  URL for the site's MCP surface; those are Wix's domains, not Brisk Health's, and
  have been removed so this artifact describes only the provider.
hosts:
- host: www.briskhealthurgentcare.com
  role: live marketing site (only reachable Brisk Health web property)
  http_status: 200
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep  6 01:16:14 2026 GMT
  cert_valid: true
  hsts: true
  hsts_max_age: 31556952
- host: briskhealth.com
  role: primary brand domain — parked / misconfigured
  http_status: 404
  http_body: Wix "ConnectYourDomain Error" page
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 28 11:02:37 2026 GMT
  cert_valid: true
  hsts: false
- host: brisk.health
  role: mobile-app landing domain (linked from the marketing site) — dead
  http_status: 404
  http_body: Wix "ConnectYourDomain Error" page
  https: true
  tls_version: TLSv1.3
  cert_expires: Mar 27 05:04:50 2026 GMT
  cert_valid: false
  cert_note: >-
    Certificate expired 2026-03-27 and has not been renewed; a default TLS client
    refuses the connection outright.
  hsts: false
domains:
- domain: briskhealthurgentcare.com
  dnssec: true
  caa: []
  spf: false
  dmarc: false
- domain: briskhealth.com
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:_spf.mlsend.com include:_spf.enguard.com -all
  dmarc: true
  dmarc_policy: invalid-multiple-records
  dmarc_note: >-
    Two conflicting DMARC TXT records are published at _dmarc.briskhealth.com —
    one "p=none" carrying unedited template placeholders
    (rua/ruf pointing at dmarc-reports@yourdomain.com) and one "p=reject". Per
    RFC 7489 6.6.3 a receiver that finds more than one DMARC record discards the
    policy entirely, so this domain is effectively unprotected despite appearing
    to publish a reject policy.
- domain: brisk.health
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:_spf.google.com ~all
  dmarc: true
  dmarc_policy: none
findings:
- id: expired-tls-cert
  host: brisk.health
  severity: high
  detail: TLS certificate expired 2026-03-27; the app landing domain is unusable over HTTPS.
- id: dmarc-multiple-records
  domain: briskhealth.com
  severity: medium
  detail: Duplicate DMARC records void the policy; one still contains template placeholders.
- id: no-caa
  severity: low
  detail: No CAA records on any Brisk Health domain, so certificate issuance is unrestricted.