Drillster · Domain Security

Drillster Domain Security

Domain security

Domain security posture for Drillster, probed live across 2 host(s) and 1 registrable domain(s). 2 host(s) serve HTTPS (up to TLSv1.3); 2 advertise HSTS. Email/DNS controls: DNSSEC present, SPF present, DMARC present (p=quarantine).

AssessmentsEducationLearningQuizzesTrainingLMSAdaptive LearningCompliance TrainingWebhooks

Transport & Host Security

www.drillster.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Nov 28 19:37:15 2026 GMT
drillster.com
HTTPS: yes · HSTS: yes

Domain (DNS/Email) Security

drillster.com
DNSSEC: yes · SPF: yes · DMARC: yes (p=quarantine) · CAA: yes

Source

Domain Security

drillster-domain-security.yml Raw ↑
generated: '2026-09-06'
method: probed
source: >-
  live DNS/TLS/HTTP probes of the hosts in apis.yml plus the API base host
  (https://www.drillster.com/api/2.1.1). Baseline written by
  0-working/probe-domain-security.py, then corrected by hand — see hsts_note.
hosts:
  - host: www.drillster.com
    role: API host, developer documentation, console, OAuth authorization server
    https: true
    tls_version: TLSv1.3
    cert_expires: Nov 28 19:37:15 2026 GMT
    hsts: true
    hsts_max_age: 31536000
    hsts_include_subdomains: true
    hsts_preload: true
    hsts_header: 'max-age=31536000; includeSubDomains; preload'
  - host: drillster.com
    role: marketing site (separate Next.js application)
    https: true
    hsts: true
    hsts_max_age: 31536000
    hsts_include_subdomains: true
    hsts_preload: false
    hsts_header: 'max-age=31536000; includeSubDomains'
hsts_note: >-
  The automated probe recorded hsts: null for www.drillster.com on this run. That was a false
  negative: a live HEAD of https://www.drillster.com/, of the developer documentation, and of
  https://www.drillster.com/api/2.1.1/version each returned
  strict-transport-security: max-age=31536000; includeSubDomains; preload on 2026-09-06.
  Corrected here with the header quoted verbatim.
response_security_headers:
  observed_on: https://www.drillster.com/api/2.1.1/version
  date: '2026-09-06'
  headers:
    x-content-type-options: nosniff
    x-frame-options: DENY
    referrer-policy: no-referrer
    x-xss-protection: '0'
    cache-control: no-cache, no-store, max-age=0, must-revalidate
domains:
  - domain: drillster.com
    dnssec: true
    caa:
      - 0 issue "pki.goog"
      - 0 issue "letsencrypt.org"
    spf: true
    dmarc: true
    dmarc_policy: quarantine
    caa_note: >-
      An earlier probe (2026-07-11) also recorded digicert.com and comodoca.com issue records;
      the current CAA set is narrower.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/drillster-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.