CoolerX · Domain Security

Cooler Screens Domain Security

Domain security

Domain security posture for CoolerX, probed live across 4 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.

CompanyRetailRetail MediaAdvertisingDigital SignageIn-Store MediaMerchandisingArtificial IntelligenceInternet of Things

Transport & Host Security

www.coolerx.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 9 23:59:59 2026 GMT
coolerx.com
HTTPS: no · TLS: TLSv1.3 · HSTS: no · cert expires: Jun 10 23:59:59 2025 GMT
api.coolerx.com
HTTPS: no · HSTS: no
portal.coolerx.com
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

coolerx.com
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

cooler-screens-domain-security.yml Raw ↑
generated: '2026-08-12'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
rechecked: '2026-08-12'
recheck_note: >-
  Re-probed 2026-08-12. Every finding below still holds. The apex certificate
  (CN=coolerx.com, GeoTrust Global TLS RSA4096 SHA256 2022 CA1, notAfter Jun 10 23:59:59
  2025 GMT) remains expired — 14 months past expiry — and openssl still returns
  "verify error:num=10:certificate has expired". www.coolerx.com was reissued and is
  valid (notBefore Jun 9 2026, notAfter Dec 9 2026), but it 307-redirects to the apex,
  so the canonical site still terminates on the expired host. This now has an API
  consequence as well as a web one: the OAuth authorization server, the protected-
  resource metadata and both MCP endpoints discovered on 2026-08-12 are all served from
  the apex, so no certificate-validating OAuth or MCP client can reach them. See
  well-known/cooler-screens-well-known.yml and mcp/cooler-screens-mcp.yml.
additional_hosts_checked_2026_08_12:
  no_dns: [app.coolerx.com, developer.coolerx.com, developers.coolerx.com, docs.coolerx.com,
    media.coolerx.com, ads.coolerx.com, status.coolerx.com, trust.coolerx.com, blog.coolerx.com]
  note: >-
    None of these resolve. coolerscreens.com resolves to 13.107.246.40 and
    www.coolerscreens.com 307-redirects to https://coolerx.com/index.php, following the
    rebrand.
hosts:
- host: www.coolerx.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec  9 23:59:59 2026 GMT
  cert_subject: CN=www.coolerx.com
  cert_issuer: DigiCert Inc / GeoTrust TLS RSA CA G1
  hsts: null
  notes: >-
    GET / returns 307 to https://coolerx.com/index.php and that redirect response
    carries no Strict-Transport-Security header. Application responses served from
    the origin (e.g. /index.php, /company/) do include
    "strict-transport-security: max-age=31536000; includeSubDomains; preload".
- host: coolerx.com
  https: false
  tls_version: TLSv1.3
  cert_expires: Jun 10 23:59:59 2025 GMT
  cert_subject: CN=coolerx.com
  cert_issuer: DigiCert, Inc. / GeoTrust Global TLS RSA4096 SHA256 2022 CA1
  cert_expired: true
  verify_result: '10 (certificate has expired)'
  hsts: null
  notes: >-
    The apex host serves a certificate that expired 2025-06-10, so every TLS client
    that validates the chain (curl, browsers, WebFetch) fails to connect. Observed
    consistently across the Azure Front Door addresses the apex resolves to
    (150.171.109.113 and 150.171.109.115). www.coolerx.com/ 307-redirects to
    https://coolerx.com/index.php, so the canonical homepage path terminates on the
    expired-certificate host. Probed 2026-08-09.
- host: api.coolerx.com
  https: false
  reachable: false
  dns_a: 13.67.211.230
  notes: >-
    DNS A record resolves, but TCP connections to 443 and 80 time out. No service
    answered; treated as a private or firewalled partner endpoint, not a public API.
- host: portal.coolerx.com
  https: false
  reachable: false
  dns_a: 13.67.211.230
  notes: >-
    DNS A record resolves to the same address as api.coolerx.com; TCP connections to
    443 and 80 time out.
domains:
- domain: coolerx.com
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:spf.protection.outlook.com -all
  dmarc: false
  nameservers:
  - ns1-34.azure-dns.com
  - ns2-34.azure-dns.net
  - ns3-34.azure-dns.org
  - ns4-34.azure-dns.info