Direct Line Group · Domain Security
Direct Line Group Domain Security
Domain security
Domain security posture for Direct Line Group, probed live across 12 host(s) and 9 registrable domain(s). 11 host(s) serve HTTPS (up to TLSv1.3); 7 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).
InsuranceUnited KingdomProperty and CasualtyPersonal LinesMotor InsuranceHome InsuranceCarrierRoadside AssistancePartner Gated
Transport & Host Security
www.directline.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Jan 25 12:49:05 2027 GMT
www.churchill.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Jan 25 12:49:05 2027 GMT
www.greenflag.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Mar 3 09:54:18 2027 GMT
www.privilege.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Jan 25 12:49:05 2027 GMT
www.darwin-insurance.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Jan 30 11:13:55 2027 GMT
www.darwin.co.uk
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Aug 2 18:53:30 2026 GMT
www.bymiles.co.uk
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Dec 10 23:59:59 2026 GMT
www.directlineforbusiness.co.uk
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Sep 13 14:48:51 2026 GMT
api.directlinegroup.co.uk
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Jun 15 12:34:59 2026 GMT
api.bymiles.co.uk
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Sep 26 23:59:59 2026 GMT
api.darwin.co.uk
HTTPS: no
· HSTS: no
docs.directline.com
HTTPS: yes
· TLS: TLSv1.2
· HSTS: no
· cert expires: Sep 28 08:47:41 2026 GMT
Domain (DNS/Email) Security
directline.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
churchill.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
greenflag.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
privilege.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=none)
· CAA: none
darwin-insurance.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
darwin.co.uk
DNSSEC: no
· SPF: yes
· DMARC: no
· CAA: none
bymiles.co.uk
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
directlineforbusiness.co.uk
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
directlinegroup.co.uk
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
Source
Domain Security
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of every Direct Line Group brand host, the group
API host, and the two brand API hosts discovered by DNS enumeration on 2026-07-25
hosts:
- host: www.directline.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 25 12:49:05 2027 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
hsts: true
hsts_max_age: 63072000
- host: www.churchill.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 25 12:49:05 2027 GMT
hsts: true
hsts_max_age: 63072000
- host: www.greenflag.com
https: true
tls_version: TLSv1.3
cert_expires: Mar 3 09:54:18 2027 GMT
hsts: true
hsts_max_age: 63072000
- host: www.privilege.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 25 12:49:05 2027 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
hsts: true
hsts_max_age: 63072000
note: Serves the shared www.directline.com certificate — the Privilege brand site
runs on the same UK Insurance Limited web estate.
- host: www.darwin-insurance.com
https: true
tls_version: TLSv1.3
cert_expires: Jan 30 11:13:55 2027 GMT
cert_subject: CN=www.darwin-insurance.com
hsts: true
hsts_max_age: 31536000
hsts_include_subdomains: true
note: The real Darwin brand site. Policies underwritten by U K Insurance Limited
(the Direct Line Group entity, FCA No. 536726) and arranged/administered by
iGO4 Limited.
- host: www.darwin.co.uk
in_group: false
https: true
tls_version: TLSv1.3
cert_expires: Aug 2 18:53:30 2026 GMT
cert_subject: CN=www.darwin.co.uk
hsts: false
note: NOT a Direct Line Group property. Probed and excluded 2026-07-25 — the host
serves a one-line HTML redirector to /lander, which forwards to
forsale.godaddy.com/forsale/www.darwin.co.uk, and its /llms.txt states the
domain is listed for sale on GoDaddy's aftermarket. Retained here only to
record the exclusion so a later round does not re-adopt it.
- host: www.bymiles.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Dec 10 23:59:59 2026 GMT
cert_subject: CN=bymiles.co.uk
hsts: true
hsts_max_age: 15552000
- host: www.directlineforbusiness.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Sep 13 14:48:51 2026 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=*.directlineforbusiness.co.uk
hsts: true
hsts_max_age: 31536000
- host: api.directlinegroup.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Jun 15 12:34:59 2026 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=api.directlinegroup.co.uk
cert_expired: true
hsts: null
http_status: 403
note: MuleSoft Anypoint production load balancer (dlg-production-load-balancer.lb.anypointdns.net).
Certificate expired 2026-06-15 and has not been renewed; the server sends a TLS
CertificateRequest (mutual TLS) and returns an nginx HTTP 403 at every path
probed. Partner/internal gateway, not a developer surface.
- host: api.bymiles.co.uk
https: true
tls_version: TLSv1.3
cert_expires: Sep 26 23:59:59 2026 GMT
cert_subject: CN=bymiles.co.uk
hsts: null
http_status: 403
note: Amazon API Gateway (response headers x-amz-apigw-id, x-amzn-errortype ForbiddenException).
Root returns {"message":"Forbidden"}; /v1/* returns {"message":"Missing Authentication
Token"}. Gated, undocumented. Discovered 2026-07-25 by DNS enumeration — not
recorded in the 2026-07-25 initial review.
- host: api.darwin.co.uk
https: false
error: 'TLS handshake failed: tlsv1 unrecognized name (no certificate presented for
this SNI name)'
note: Resolves to AWS anycast addresses (13.248.169.48, 76.223.54.146) but presents
no certificate for the name; not a usable public host.
- host: docs.directline.com
https: true
tls_version: TLSv1.2
cert_expires: Sep 28 08:47:41 2026 GMT
cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=docs.directline.com
hsts: null
http_status: 200
note: Form-based login wall titled "DirectLine - Login"; no reference documentation.
Lowest TLS version observed across the estate (TLSv1.2).
domains:
- domain: directline.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: churchill.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: greenflag.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: privilege.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: none
note: The only group domain with a permissive DMARC policy (p=none — monitor only).
- domain: darwin-insurance.com
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
dmarc_rua: mailto:dmarcadmin@darwin-insurance.com
- domain: darwin.co.uk
in_group: false
dnssec: false
caa: []
spf: true
dmarc: false
dmarc_policy: null
note: Not a group domain — GoDaddy aftermarket listing. Excluded from the summary
counts below.
- domain: bymiles.co.uk
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: directlineforbusiness.co.uk
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
- domain: directlinegroup.co.uk
dnssec: false
caa: []
spf: true
dmarc: true
dmarc_policy: reject
summary:
scope_note: Counts cover Direct Line Group properties only; www.darwin.co.uk and
darwin.co.uk are recorded above but excluded because they are not group properties.
hosts_probed: 11
https_reachable: 10
hsts_present: 7
domains_probed: 8
dnssec: 0
caa: 0
spf: 8
dmarc: 7
dmarc_reject: 6
findings:
- Every group domain publishes SPF; none publishes CAA and none is DNSSEC-signed.
- privilege.com DMARC is p=none (monitor only) while the rest of the estate is p=reject.
- The group API host api.directlinegroup.co.uk has been serving an expired certificate
since 2026-06-15 while still demanding a client certificate.
- www.privilege.com serves the www.directline.com certificate — the Privilege brand
runs on the shared U K Insurance Limited web estate.
- docs.directline.com is the only host still on TLSv1.2.