Bupa Australia · Domain Security

Bupa Australia Domain Security

Domain security

Domain security posture for Bupa Australia, probed live across 6 host(s) and 1 registrable domain(s). 6 host(s) serve HTTPS (up to TLSv1.3); 6 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

InsuranceAustraliaHealth InsurancePrivate Health InsuranceCarrierHealthcareClaimsPolicy AdministrationEmployee BenefitsPartner Gated

Transport & Host Security

www.bupa.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 11 23:59:59 2026 GMT
portal.api.bupa.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 3 23:59:59 2026 GMT
api.bupa.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 3 23:59:59 2026 GMT
partner.bupa.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Aug 25 23:59:59 2026 GMT
partnerlogin.bupa.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 15 23:59:59 2026 GMT
my.bupa.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Aug 29 23:59:59 2026 GMT

Domain (DNS/Email) Security

bupa.com.au
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

bupa-australia-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + developer-portal + identity hosts
hosts:
- host: www.bupa.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 11 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  hsts_preload: true
- host: portal.api.bupa.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec  3 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  hsts_preload: false
  role: Azure API Management managed developer portal
- host: api.bupa.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec  3 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: false
  hsts_preload: false
  http_status: 502
  role: Azure APIM custom gateway host, behind Imperva; 502 to all anonymous callers
- host: partner.bupa.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug 25 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  hsts_preload: true
  role: Dynamics 365 Power Pages partner portal
- host: partnerlogin.bupa.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 15 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: false
  hsts_preload: false
  role: Azure AD B2C identity host
- host: my.bupa.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug 29 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  hsts_preload: false
  role: myBupa member portal
domains:
- domain: bupa.com.au
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
notes: |
  Every Bupa Australia host probed negotiates TLS 1.3 and sets HSTS with a
  one-year max-age; the two consumer-facing hosts (www and partner) additionally
  set includeSubDomains with preload. The registrable domain publishes SPF and a
  DMARC record at p=reject, the strongest of the three DMARC policies. The gaps
  are DNSSEC (unsigned) and CAA (no records, so any CA may issue for
  bupa.com.au). Absence of a record is recorded data, not an inference.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/bupa-australia-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.