Blue Cross Canada · Domain Security

Canadian Blue Cross Domain Security

Domain security

Domain security posture for Blue Cross Canada, probed live across 7 host(s) and 2 registrable domain(s). 7 host(s) serve HTTPS (up to TLSv1.3); 7 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=none).

InsuranceCanadaHealth InsuranceDental BenefitsTravel InsuranceLife InsuranceEmployee BenefitsGroup BenefitsClaimsCarrierAssociationNo Public API

Transport & Host Security

www.bluecross.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 17 16:18:54 2026 GMT
pac.bluecross.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 18 23:59:59 2026 GMT
ab.bluecross.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 23 08:03:30 2026 GMT
on.bluecross.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 11 23:59:59 2026 GMT
www.medaviebc.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 9 05:45:50 2026 GMT
www.sk.bluecross.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 19 19:17:31 2026 GMT
www.mb.bluecross.ca
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 23:59:59 2027 GMT

Domain (DNS/Email) Security

bluecross.ca
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none
medaviebc.ca
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none

Source

Domain Security

canadian-blue-cross-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: >-
  live DNS/TLS/HTTP probes of the apis.yml hosts (0-working/probe-domain-security.py) extended
  by hand to every operating Blue Cross member-plan host in the federation
hosts:
- host: www.bluecross.ca
  plan: Canadian Association of Blue Cross Plans
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 17 16:18:54 2026 GMT
  hsts: true
  hsts_max_age: 300
  note: >-
    HSTS max-age of 300 seconds is far below the 31536000 the member plans use and below any
    preload threshold — effectively a token policy on the national brand site.
- host: pac.bluecross.ca
  plan: Pacific Blue Cross
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 18 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
- host: ab.bluecross.ca
  plan: Alberta Blue Cross
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 23 08:03:30 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  note: Cloudflare bot management returns 403/interstitial to non-browser clients.
- host: on.bluecross.ca
  plan: Ontario / Quebec Blue Cross (Canassurance)
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 11 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
- host: www.medaviebc.ca
  plan: Medavie Blue Cross
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  9 05:45:50 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
- host: www.sk.bluecross.ca
  plan: Saskatchewan Blue Cross
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 19 19:17:31 2026 GMT
  hsts: true
  hsts_max_age: 15552000
  hsts_include_subdomains: true
- host: www.mb.bluecross.ca
  plan: Manitoba Blue Cross
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: false
domains:
- domain: bluecross.ca
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
  nameservers: [dns1.cidc.telus.com, dns2.cidc.telus.com]
  note: >-
    DMARC is published but at p=none (monitor only), so no enforcement against spoofed mail from
    the brand domain. No CAA records, so certificate issuance is unconstrained. No DNSSEC.
- domain: medaviebc.ca
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
  nameservers: [simon.ns.cloudflare.com, kia.ns.cloudflare.com]
  note: >-
    SPF and DMARC are delegated to Proofpoint (pphosted.com); DMARC is also p=none. No CAA, no
    DNSSEC.
summary:
  https_everywhere: true
  tls13_everywhere: true
  hsts_hosts: 7
  dnssec_domains: 0
  caa_domains: 0
  dmarc_enforcing_domains: 0
  note: >-
    Transport hygiene is uniformly good across the federation; domain-level controls (DNSSEC,
    CAA, DMARC enforcement) are uniformly absent.