Centrexion Therapeutics · Domain Security

Centrexion Therapeutics Domain Security

Domain security

Domain security posture for Centrexion Therapeutics, probed live across 1 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.

Companybiopharmaceuticalpharmaceuticalschronic-painnon-opioid-analgesicsimmunologyinflammationclinical-trialslife-sciencescontent-api

Transport & Host Security

centrexion.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 23 21:24:08 2026 GMT

Domain (DNS/Email) Security

centrexion.com
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-08-09'
method: probed
source: live DNS/TLS/HTTP probes of the centrexion.com host and registrable domain
note: >-
  Probed 2026-08-09 by the API Evangelist enrichment pipeline. Only Centrexion Therapeutics' own
  host and registrable domain are recorded. The apis.yml humanURL for the content API points at
  developer.wordpress.org (the upstream WordPress REST handbook that documents the wp/v2 contract);
  that host is not operated by Centrexion and its posture is deliberately excluded so it is not
  misattributed to this provider. The site is a WordPress deployment served by nginx and hosted on
  WP Engine (x-powered-by: WP Engine). HTTPS is enforced by redirect (http:// and www. both 301 to
  https://centrexion.com/) but no Strict-Transport-Security header is sent, so the redirect is the
  only downgrade protection. No CAA records and no DNSSEC are published; DNS is delegated to
  Register.com.
hosts:
- host: centrexion.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 23 21:24:08 2026 GMT
  hsts: false
  server: nginx
  origin: WP Engine (x-powered-by response header observed)
  http_to_https_redirect: 301
  www_redirect: 301 to apex
domains:
- domain: centrexion.com
  dnssec: false
  caa: []
  spf: true
  spf_record: 'v=spf1 include:1xalkvunf.spf.checkpoint-spf.com -all'
  dmarc: false
  nameservers:
  - dns101.register.com
  - dns102.register.com
observations:
- >-
  No DMARC record is published at _dmarc.centrexion.com (empty TXT response). SPF is present and
  strict (-all, delegated to Check Point's hosted email-security SPF service), but with no DMARC
  policy there is no alignment enforcement and no aggregate or forensic reporting, so the domain has
  neither spoofing enforcement beyond SPF nor any visibility into abuse.
- >-
  DANGLING CNAME — investors.centrexion.com is a CNAME to centrexion.gcs-web.com, and that target
  has no A record while its parent zone gcs-web.com is live on AWS Route 53 nameservers. The name
  therefore resolves as a CNAME but terminates in NXDOMAIN, and nothing answers on 80 or 443. A
  CNAME left pointing at a de-provisioned host on a third-party investor-relations platform is the
  classic subdomain-takeover precondition; whoever can claim that hostname on the upstream platform
  inherits a subdomain of centrexion.com. Recommend deleting the record or reclaiming the target.
- >-
  portal.centrexion.com resolves to 72.20.122.198 but both 443 and 80 are closed/filtered — a stale
  A record for a host that no longer serves. sharepoint.centrexion.com (66.227.71.31) behaves the
  same way. Neither is a live surface; both are residue.
- No Strict-Transport-Security header on the site root.
- No Content-Security-Policy header on the site root.
- No X-Content-Type-Options, X-Frame-Options, Referrer-Policy or Permissions-Policy header on the site root.
- >-
  API responses under /wp-json do send x-content-type-options nosniff and x-robots-tag noindex, and
  expose Access-Control-Expose-Headers for X-WP-Total, X-WP-TotalPages and Link.
- No /.well-known/security.txt (RFC 9116) published — see well-known/centrexion-therapeutics-well-known.yml.
- >-
  No api., developer., docs., status., trust., mcp., support., vpn., intranet., files. or careers.
  subdomain resolves for centrexion.com (NXDOMAIN on all eleven), consistent with a company that
  runs no developer program and no status or trust surface.