Direct Line Group · Domain Security

Direct Line Group Domain Security

Domain security

Domain security posture for Direct Line Group, probed live across 12 host(s) and 9 registrable domain(s). 11 host(s) serve HTTPS (up to TLSv1.3); 7 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

InsuranceUnited KingdomProperty and CasualtyPersonal LinesMotor InsuranceHome InsuranceCarrierRoadside AssistancePartner Gated

Transport & Host Security

www.directline.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 12:49:05 2027 GMT
www.churchill.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 12:49:05 2027 GMT
www.greenflag.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Mar 3 09:54:18 2027 GMT
www.privilege.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 12:49:05 2027 GMT
www.darwin-insurance.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 30 11:13:55 2027 GMT
www.darwin.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Aug 2 18:53:30 2026 GMT
www.bymiles.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 10 23:59:59 2026 GMT
www.directlineforbusiness.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 13 14:48:51 2026 GMT
api.directlinegroup.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Jun 15 12:34:59 2026 GMT
api.bymiles.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 26 23:59:59 2026 GMT
api.darwin.co.uk
HTTPS: no · HSTS: no
docs.directline.com
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Sep 28 08:47:41 2026 GMT

Domain (DNS/Email) Security

directline.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
churchill.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
greenflag.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
privilege.com
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none
darwin-insurance.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
darwin.co.uk
DNSSEC: no · SPF: yes · DMARC: no · CAA: none
bymiles.co.uk
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
directlineforbusiness.co.uk
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
directlinegroup.co.uk
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

direct-line-group-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of every Direct Line Group brand host, the group
  API host, and the two brand API hosts discovered by DNS enumeration on 2026-07-25
hosts:
- host: www.directline.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 12:49:05 2027 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
  hsts: true
  hsts_max_age: 63072000
- host: www.churchill.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 12:49:05 2027 GMT
  hsts: true
  hsts_max_age: 63072000
- host: www.greenflag.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Mar  3 09:54:18 2027 GMT
  hsts: true
  hsts_max_age: 63072000
- host: www.privilege.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 12:49:05 2027 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
  hsts: true
  hsts_max_age: 63072000
  note: Serves the shared www.directline.com certificate — the Privilege brand site
    runs on the same UK Insurance Limited web estate.
- host: www.darwin-insurance.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 30 11:13:55 2027 GMT
  cert_subject: CN=www.darwin-insurance.com
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  note: The real Darwin brand site. Policies underwritten by U K Insurance Limited
    (the Direct Line Group entity, FCA No. 536726) and arranged/administered by
    iGO4 Limited.
- host: www.darwin.co.uk
  in_group: false
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug  2 18:53:30 2026 GMT
  cert_subject: CN=www.darwin.co.uk
  hsts: false
  note: NOT a Direct Line Group property. Probed and excluded 2026-07-25 — the host
    serves a one-line HTML redirector to /lander, which forwards to
    forsale.godaddy.com/forsale/www.darwin.co.uk, and its /llms.txt states the
    domain is listed for sale on GoDaddy's aftermarket. Retained here only to
    record the exclusion so a later round does not re-adopt it.
- host: www.bymiles.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 10 23:59:59 2026 GMT
  cert_subject: CN=bymiles.co.uk
  hsts: true
  hsts_max_age: 15552000
- host: www.directlineforbusiness.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 13 14:48:51 2026 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=*.directlineforbusiness.co.uk
  hsts: true
  hsts_max_age: 31536000
- host: api.directlinegroup.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Jun 15 12:34:59 2026 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=api.directlinegroup.co.uk
  cert_expired: true
  hsts: null
  http_status: 403
  note: MuleSoft Anypoint production load balancer (dlg-production-load-balancer.lb.anypointdns.net).
    Certificate expired 2026-06-15 and has not been renewed; the server sends a TLS
    CertificateRequest (mutual TLS) and returns an nginx HTTP 403 at every path
    probed. Partner/internal gateway, not a developer surface.
- host: api.bymiles.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 26 23:59:59 2026 GMT
  cert_subject: CN=bymiles.co.uk
  hsts: null
  http_status: 403
  note: Amazon API Gateway (response headers x-amz-apigw-id, x-amzn-errortype ForbiddenException).
    Root returns {"message":"Forbidden"}; /v1/* returns {"message":"Missing Authentication
    Token"}. Gated, undocumented. Discovered 2026-07-25 by DNS enumeration — not
    recorded in the 2026-07-25 initial review.
- host: api.darwin.co.uk
  https: false
  error: 'TLS handshake failed: tlsv1 unrecognized name (no certificate presented for
    this SNI name)'
  note: Resolves to AWS anycast addresses (13.248.169.48, 76.223.54.146) but presents
    no certificate for the name; not a usable public host.
- host: docs.directline.com
  https: true
  tls_version: TLSv1.2
  cert_expires: Sep 28 08:47:41 2026 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=docs.directline.com
  hsts: null
  http_status: 200
  note: Form-based login wall titled "DirectLine - Login"; no reference documentation.
    Lowest TLS version observed across the estate (TLSv1.2).
domains:
- domain: directline.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: churchill.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: greenflag.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: privilege.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
  note: The only group domain with a permissive DMARC policy (p=none — monitor only).
- domain: darwin-insurance.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: mailto:dmarcadmin@darwin-insurance.com
- domain: darwin.co.uk
  in_group: false
  dnssec: false
  caa: []
  spf: true
  dmarc: false
  dmarc_policy: null
  note: Not a group domain — GoDaddy aftermarket listing. Excluded from the summary
    counts below.
- domain: bymiles.co.uk
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: directlineforbusiness.co.uk
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: directlinegroup.co.uk
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
summary:
  scope_note: Counts cover Direct Line Group properties only; www.darwin.co.uk and
    darwin.co.uk are recorded above but excluded because they are not group properties.
  hosts_probed: 11
  https_reachable: 10
  hsts_present: 7
  domains_probed: 8
  dnssec: 0
  caa: 0
  spf: 8
  dmarc: 7
  dmarc_reject: 6
  findings:
  - Every group domain publishes SPF; none publishes CAA and none is DNSSEC-signed.
  - privilege.com DMARC is p=none (monitor only) while the rest of the estate is p=reject.
  - The group API host api.directlinegroup.co.uk has been serving an expired certificate
    since 2026-06-15 while still demanding a client certificate.
  - www.privilege.com serves the www.directline.com certificate — the Privilege brand
    runs on the shared U K Insurance Limited web estate.
  - docs.directline.com is the only host still on TLSv1.2.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/direct-line-group-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.