Direct Line Group · Domain Security

Direct Line Group Domain Security

Domain security

Domain security posture for Direct Line Group, probed live across 12 host(s) and 9 registrable domain(s). 11 host(s) serve HTTPS (up to TLSv1.3); 7 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

InsuranceUnited KingdomProperty and CasualtyPersonal LinesMotor InsuranceHome InsuranceCarrierRoadside AssistancePartner Gated

Transport & Host Security

www.directline.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 12:49:05 2027 GMT
www.churchill.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 12:49:05 2027 GMT
www.greenflag.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Mar 3 09:54:18 2027 GMT
www.privilege.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 25 12:49:05 2027 GMT
www.darwin-insurance.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 30 11:13:55 2027 GMT
www.darwin.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Aug 2 18:53:30 2026 GMT
www.bymiles.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 10 23:59:59 2026 GMT
www.directlineforbusiness.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 13 14:48:51 2026 GMT
api.directlinegroup.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Jun 15 12:34:59 2026 GMT
api.bymiles.co.uk
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 26 23:59:59 2026 GMT
api.darwin.co.uk
HTTPS: no · HSTS: no
docs.directline.com
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Sep 28 08:47:41 2026 GMT

Domain (DNS/Email) Security

directline.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
churchill.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
greenflag.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
privilege.com
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none
darwin-insurance.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
darwin.co.uk
DNSSEC: no · SPF: yes · DMARC: no · CAA: none
bymiles.co.uk
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
directlineforbusiness.co.uk
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
directlinegroup.co.uk
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

direct-line-group-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of every Direct Line Group brand host, the group
  API host, and the two brand API hosts discovered by DNS enumeration on 2026-07-25
hosts:
- host: www.directline.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 12:49:05 2027 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
  hsts: true
  hsts_max_age: 63072000
- host: www.churchill.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 12:49:05 2027 GMT
  hsts: true
  hsts_max_age: 63072000
- host: www.greenflag.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Mar  3 09:54:18 2027 GMT
  hsts: true
  hsts_max_age: 63072000
- host: www.privilege.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 25 12:49:05 2027 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=www.directline.com
  hsts: true
  hsts_max_age: 63072000
  note: Serves the shared www.directline.com certificate — the Privilege brand site
    runs on the same UK Insurance Limited web estate.
- host: www.darwin-insurance.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 30 11:13:55 2027 GMT
  cert_subject: CN=www.darwin-insurance.com
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  note: The real Darwin brand site. Policies underwritten by U K Insurance Limited
    (the Direct Line Group entity, FCA No. 536726) and arranged/administered by
    iGO4 Limited.
- host: www.darwin.co.uk
  in_group: false
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug  2 18:53:30 2026 GMT
  cert_subject: CN=www.darwin.co.uk
  hsts: false
  note: NOT a Direct Line Group property. Probed and excluded 2026-07-25 — the host
    serves a one-line HTML redirector to /lander, which forwards to
    forsale.godaddy.com/forsale/www.darwin.co.uk, and its /llms.txt states the
    domain is listed for sale on GoDaddy's aftermarket. Retained here only to
    record the exclusion so a later round does not re-adopt it.
- host: www.bymiles.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 10 23:59:59 2026 GMT
  cert_subject: CN=bymiles.co.uk
  hsts: true
  hsts_max_age: 15552000
- host: www.directlineforbusiness.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 13 14:48:51 2026 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=*.directlineforbusiness.co.uk
  hsts: true
  hsts_max_age: 31536000
- host: api.directlinegroup.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Jun 15 12:34:59 2026 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=api.directlinegroup.co.uk
  cert_expired: true
  hsts: null
  http_status: 403
  note: MuleSoft Anypoint production load balancer (dlg-production-load-balancer.lb.anypointdns.net).
    Certificate expired 2026-06-15 and has not been renewed; the server sends a TLS
    CertificateRequest (mutual TLS) and returns an nginx HTTP 403 at every path
    probed. Partner/internal gateway, not a developer surface.
- host: api.bymiles.co.uk
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 26 23:59:59 2026 GMT
  cert_subject: CN=bymiles.co.uk
  hsts: null
  http_status: 403
  note: Amazon API Gateway (response headers x-amz-apigw-id, x-amzn-errortype ForbiddenException).
    Root returns {"message":"Forbidden"}; /v1/* returns {"message":"Missing Authentication
    Token"}. Gated, undocumented. Discovered 2026-07-25 by DNS enumeration — not
    recorded in the 2026-07-25 initial review.
- host: api.darwin.co.uk
  https: false
  error: 'TLS handshake failed: tlsv1 unrecognized name (no certificate presented for
    this SNI name)'
  note: Resolves to AWS anycast addresses (13.248.169.48, 76.223.54.146) but presents
    no certificate for the name; not a usable public host.
- host: docs.directline.com
  https: true
  tls_version: TLSv1.2
  cert_expires: Sep 28 08:47:41 2026 GMT
  cert_subject: C=GB, ST=Kent, L=Bromley, O=Direct Line Insurance Group Plc, CN=docs.directline.com
  hsts: null
  http_status: 200
  note: Form-based login wall titled "DirectLine - Login"; no reference documentation.
    Lowest TLS version observed across the estate (TLSv1.2).
domains:
- domain: directline.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: churchill.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: greenflag.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: privilege.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none
  note: The only group domain with a permissive DMARC policy (p=none — monitor only).
- domain: darwin-insurance.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: mailto:dmarcadmin@darwin-insurance.com
- domain: darwin.co.uk
  in_group: false
  dnssec: false
  caa: []
  spf: true
  dmarc: false
  dmarc_policy: null
  note: Not a group domain — GoDaddy aftermarket listing. Excluded from the summary
    counts below.
- domain: bymiles.co.uk
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: directlineforbusiness.co.uk
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: directlinegroup.co.uk
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
summary:
  scope_note: Counts cover Direct Line Group properties only; www.darwin.co.uk and
    darwin.co.uk are recorded above but excluded because they are not group properties.
  hosts_probed: 11
  https_reachable: 10
  hsts_present: 7
  domains_probed: 8
  dnssec: 0
  caa: 0
  spf: 8
  dmarc: 7
  dmarc_reject: 6
  findings:
  - Every group domain publishes SPF; none publishes CAA and none is DNSSEC-signed.
  - privilege.com DMARC is p=none (monitor only) while the rest of the estate is p=reject.
  - The group API host api.directlinegroup.co.uk has been serving an expired certificate
    since 2026-06-15 while still demanding a client certificate.
  - www.privilege.com serves the www.directline.com certificate — the Privilege brand
    runs on the shared U K Insurance Limited web estate.
  - docs.directline.com is the only host still on TLSv1.2.