CAA Insurance · Domain Security

Caa Insurance Domain Security

Domain security

Domain security posture for CAA Insurance, probed live across 6 host(s) and 4 registrable domain(s). 6 host(s) serve HTTPS (up to TLSv1.3); 5 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=none).

InsuranceCanadaProperty and CasualtyAuto InsuranceHome InsuranceCarrierBrokerPersonal LinesTelematicsPartner GatedNo Public API

Transport & Host Security

caainsurancecompany.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 25 23:59:59 2026 GMT
broker.caainsurance.com
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Dec 5 23:59:59 2026 GMT
www.caabrokerportal.ca
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: Dec 23 23:59:59 2026 GMT
customer.caainsurancecompany.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 30 23:59:59 2026 GMT
car-insurance.caainsurancecompany.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 14 05:01:12 2026 GMT
property-insurance.caainsurancecompany.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 17 16:48:59 2026 GMT

Domain (DNS/Email) Security

caainsurancecompany.ca
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none
caainsurance.com
DNSSEC: no · SPF: no · DMARC: no · CAA: none
caainsurancecompany.com
DNSSEC: no · SPF: yes · DMARC: yes (p=hosted) · CAA: none
caabrokerportal.ca
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

caa-insurance-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: caainsurancecompany.ca
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 25 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 63072000
- host: broker.caainsurance.com
  https: true
  tls_version: TLSv1.2
  cert_expires: Dec  5 23:59:59 2026 GMT
  hsts: null
- host: www.caabrokerportal.ca
  https: true
  tls_version: TLSv1.2
  cert_expires: Dec 23 23:59:59 2026 GMT
  cert_issuer: Sectigo Public Server Authentication CA OV R36
  cert_subject: CN=*.caabrokerportal.ca, O=CAA South Central Ontario Systems and Services Inc., ST=Ontario, C=CA
  hsts: true
  hsts_max_age: 31536000
  server: Microsoft-IIS/10.0 (MicrosoftSharePointTeamServices 16.0.0.5552)
- host: customer.caainsurancecompany.ca
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 30 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 63072000
  hsts_preload: true
  csp: true
  server: ZENEDGE
- host: car-insurance.caainsurancecompany.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 14 05:01:12 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_preload: true
  server: cloudflare
- host: property-insurance.caainsurancecompany.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 17 16:48:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_preload: true
  server: cloudflare
domains:
- domain: caainsurancecompany.ca
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
- domain: caainsurance.com
  dnssec: false
  caa: []
  spf: false
  dmarc: false
- domain: caainsurancecompany.com
  dnssec: false
  caa: []
  spf: true
  spf_record: 'v=spf1 ip4:167.89.89.217 ip4:67.205.56.172 include:spf.caasco.ca include:spf.protection.outlook.com include:_spf.act-on.net -all'
  dmarc: true
  dmarc_policy: hosted
  dmarc_note: _dmarc CNAMEs to caainsurancecompany.com.hosted.dmarc-report.com (managed DMARC); no policy TXT resolved anonymously
- domain: caabrokerportal.ca
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 -all
  dmarc: false
  note: SPF hard-fails all mail (send-nothing domain); no DMARC record.
detail:
  dmarc_caainsurancecompany_ca: 'v=DMARC1; p=none; fo=1; rua=mailto:0cd63e3c@mxtoolbox.dmarc-report.com; ruf=mailto:0cd63e3c@forensics.dmarc-report.com;'
  spf_caainsurancecompany_ca: 'v=spf1 include:spf.caasco.ca include:spf.protection.outlook.com -all'
  probed_extra: '2026-07-25 — customer portal, broker portal, and both quote applications probed manually and added to hosts[]'