CoolerX · Domain Security
Cooler Screens Domain Security
Domain security
Domain security posture for CoolerX, probed live across 4 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC absent.
CompanyRetailRetail MediaAdvertisingDigital SignageIn-Store MediaMerchandisingArtificial IntelligenceInternet of Things
Transport & Host Security
www.coolerx.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Dec 9 23:59:59 2026 GMT
coolerx.com
HTTPS: no
· TLS: TLSv1.3
· HSTS: no
· cert expires: Jun 10 23:59:59 2025 GMT
api.coolerx.com
HTTPS: no
· HSTS: no
portal.coolerx.com
HTTPS: no
· HSTS: no
Domain (DNS/Email) Security
coolerx.com
DNSSEC: no
· SPF: yes
· DMARC: no
· CAA: none
Source
Domain Security
generated: '2026-08-12'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
rechecked: '2026-08-12'
recheck_note: >-
Re-probed 2026-08-12. Every finding below still holds. The apex certificate
(CN=coolerx.com, GeoTrust Global TLS RSA4096 SHA256 2022 CA1, notAfter Jun 10 23:59:59
2025 GMT) remains expired — 14 months past expiry — and openssl still returns
"verify error:num=10:certificate has expired". www.coolerx.com was reissued and is
valid (notBefore Jun 9 2026, notAfter Dec 9 2026), but it 307-redirects to the apex,
so the canonical site still terminates on the expired host. This now has an API
consequence as well as a web one: the OAuth authorization server, the protected-
resource metadata and both MCP endpoints discovered on 2026-08-12 are all served from
the apex, so no certificate-validating OAuth or MCP client can reach them. See
well-known/cooler-screens-well-known.yml and mcp/cooler-screens-mcp.yml.
additional_hosts_checked_2026_08_12:
no_dns: [app.coolerx.com, developer.coolerx.com, developers.coolerx.com, docs.coolerx.com,
media.coolerx.com, ads.coolerx.com, status.coolerx.com, trust.coolerx.com, blog.coolerx.com]
note: >-
None of these resolve. coolerscreens.com resolves to 13.107.246.40 and
www.coolerscreens.com 307-redirects to https://coolerx.com/index.php, following the
rebrand.
hosts:
- host: www.coolerx.com
https: true
tls_version: TLSv1.3
cert_expires: Dec 9 23:59:59 2026 GMT
cert_subject: CN=www.coolerx.com
cert_issuer: DigiCert Inc / GeoTrust TLS RSA CA G1
hsts: null
notes: >-
GET / returns 307 to https://coolerx.com/index.php and that redirect response
carries no Strict-Transport-Security header. Application responses served from
the origin (e.g. /index.php, /company/) do include
"strict-transport-security: max-age=31536000; includeSubDomains; preload".
- host: coolerx.com
https: false
tls_version: TLSv1.3
cert_expires: Jun 10 23:59:59 2025 GMT
cert_subject: CN=coolerx.com
cert_issuer: DigiCert, Inc. / GeoTrust Global TLS RSA4096 SHA256 2022 CA1
cert_expired: true
verify_result: '10 (certificate has expired)'
hsts: null
notes: >-
The apex host serves a certificate that expired 2025-06-10, so every TLS client
that validates the chain (curl, browsers, WebFetch) fails to connect. Observed
consistently across the Azure Front Door addresses the apex resolves to
(150.171.109.113 and 150.171.109.115). www.coolerx.com/ 307-redirects to
https://coolerx.com/index.php, so the canonical homepage path terminates on the
expired-certificate host. Probed 2026-08-09.
- host: api.coolerx.com
https: false
reachable: false
dns_a: 13.67.211.230
notes: >-
DNS A record resolves, but TCP connections to 443 and 80 time out. No service
answered; treated as a private or firewalled partner endpoint, not a public API.
- host: portal.coolerx.com
https: false
reachable: false
dns_a: 13.67.211.230
notes: >-
DNS A record resolves to the same address as api.coolerx.com; TCP connections to
443 and 80 time out.
domains:
- domain: coolerx.com
dnssec: false
caa: []
spf: true
spf_record: v=spf1 include:spf.protection.outlook.com -all
dmarc: false
nameservers:
- ns1-34.azure-dns.com
- ns2-34.azure-dns.net
- ns3-34.azure-dns.org
- ns4-34.azure-dns.info
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/cooler-screens-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.