Direct Line Group Domain Security
Domain security posture for Direct Line Group, probed live across 12 host(s) and 9 registrable domain(s). 11 host(s) serve HTTPS (up to TLSv1.3); 7 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).
Transport & Host Security
Domain (DNS/Email) Security
Source
Domain Security
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of every Direct Line Group brand host, the group
API host, and the two brand API hosts discovered by DNS enumeration on 2026-07-25
hosts:
- host: www.directline.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 25 12:49:05 2027 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
hsts: true
hsts_max_age: 63072000
- host: www.churchill.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 25 12:49:05 2027 GMT
hsts: true
hsts_max_age: 63072000
- host: www.greenflag.com
https: true
tls_version: TLSv1.3
cert_expires: Mar 3 09:54:18 2027 GMT
hsts: true
hsts_max_age: 63072000
- host: www.privilege.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 25 12:49:05 2027 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
hsts: true
hsts_max_age: 63072000
note: Serves the shared www.directline.com certificate — the Privilege brand site
runs on the same UK Insurance Limited web estate.
- host: www.darwin-insurance.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 30 11:13:55 2027 GMT
cert_subject: CN=www.darwin-insurance.com
hsts: true
hsts_max_age: 31536000
hsts_include_subdomains: true
note: The real Darwin brand site. Policies underwritten by U K Insurance Limited
(the Direct Line Group entity, FCA No. 536726) and arranged/administered by
iGO4 Limited.
- host: www.darwin.co.uk
in_group: false
https: true
tls_version: TLSv1.3
cert_expires: Aug 2 18:53:30 2026 GMT
cert_subject: CN=www.darwin.co.uk
hsts: false
note: NOT a Direct Line Group property. Probed and excluded 2026-07-25 — the host
serves a one-line HTML redirector to /lander, which forwards to
forsale.godaddy.com/forsale/www.darwin.co.uk, and its /llms.txt states the
domain is listed for sale on GoDaddy's aftermarket. Retained here only to
record the exclusion so a later round does not re-adopt it.
- host: www.bymiles.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Dec 10 23:59:59 2026 GMT
cert_subject: CN=bymiles.co.uk
hsts: true
hsts_max_age: 15552000
- host: www.directlineforbusiness.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Sep 13 14:48:51 2026 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=*.directlineforbusiness.co.uk
hsts: true
hsts_max_age: 31536000
- host: api.directlinegroup.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Jun 15 12:34:59 2026 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=api.directlinegroup.co.uk
cert_expired: true
hsts: null
http_status: 403
note: MuleSoft Anypoint production load balancer (dlg-production-load-balancer.lb.anypointdns.net).
Certificate expired 2026-06-15 and has not been renewed; the server sends a TLS
CertificateRequest (mutual TLS) and returns an nginx HTTP 403 at every path
probed. Partner/internal gateway, not a developer surface.
- host: api.bymiles.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Sep 26 23:59:59 2026 GMT
cert_subject: CN=bymiles.co.uk
hsts: null
http_status: 403
note: Amazon API Gateway (response headers x-amz-apigw-id, x-amzn-errortype ForbiddenException).
Root returns {"message":"Forbidden"}; /v1/* returns {"message":"Missing Authentication
Token"}. Gated, undocumented. Discovered 2026-07-25 by DNS enumeration — not
recorded in the 2026-07-25 initial review.
- host: api.darwin.co.uk
https: false
error: 'TLS handshake failed: tlsv1 unrecognized name (no certificate presented for
this SNI name)'
note: Resolves to AWS anycast addresses (13.248.169.48, 76.223.54.146) but presents
no certificate for the name; not a usable public host.
- host: docs.directline.com
https: true
tls_version: TLSv1.2
cert_expires: Sep 28 08:47:41 2026 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=docs.directline.com
hsts: null
http_status: 200
note: Form-based login wall titled "DirectLine - Login"; no reference documentation.
Lowest TLS version observed across the estate (TLSv1.2).
domains:
- domain: directline.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: churchill.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: greenflag.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: privilege.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: none
note: The only group domain with a permissive DMARC policy (p=none — monitor only).
- domain: darwin-insurance.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
dmarc_rua: mailto:dmarcadmin@darwin-insurance.com
- domain: darwin.co.uk
in_group: false
dnssec: false
caa: []
spf: true
dmarc: false
dmarc_policy: null
note: Not a group domain — GoDaddy aftermarket listing. Excluded from the summary
counts below.
- domain: bymiles.co.uk
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: directlineforbusiness.co.uk
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: directlinegroup.co.uk
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
summary:
scope_note: Counts cover Direct Line Group properties only; www.darwin.co.uk and
darwin.co.uk are recorded above but excluded because they are not group properties.
hosts_probed: 11
https_reachable: 10
hsts_present: 7
domains_probed: 8
dnssec: 0
caa: 0
spf: 8
dmarc: 7
dmarc_reject: 6
findings:
- Every group domain publishes SPF; none publishes CAA and none is DNSSEC-signed.
- privilege.com DMARC is p=none (monitor only) while the rest of the estate is p=reject.
- The group API host api.directlinegroup.co.uk has been serving an expired certificate
since 2026-06-15 while still demanding a client certificate.
- www.privilege.com serves the www.directline.com certificate — the Privilege brand
runs on the shared U K Insurance Limited web estate.
- docs.directline.com is the only host still on TLSv1.2.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/direct-line-group-domain-security"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.