Farm Credit Administration · Domain Security

Farm Credit Administration Domain Security

Domain security

Domain security posture for Farm Credit Administration, probed live across 5 host(s) and 1 registrable domain(s). 4 host(s) serve HTTPS (up to TLSv1.3); 3 advertise HSTS. Email/DNS controls: DNSSEC present, SPF present, DMARC present (p=reject).

AgricultureFarmsFederal-GovernmentFinanceRegulationsGeospatialOpen-DataBankingLendingGovernment

Transport & Host Security

www.fca.gov
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: 2026-11-01
wgis.fca.gov
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: 2027-01-08
apps.fca.gov
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: 2027-02-12
reports.fca.gov
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: 2026-12-11
ww4.fca.gov
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

fca.gov
DNSSEC: yes · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

farm-credit-administration-domain-security.yml Raw ↑
generated: '2026-09-07'
method: probed
source: >-
  live DNS/TLS/HTTP probes of apis.yml hosts, the ArcGIS REST API host, and every host named in
  FCA's own Vulnerability Disclosure Policy scope section
hosts:
  - host: www.fca.gov
    https: true
    tls_version: TLSv1.3
    cert_expires: '2026-11-01'
    hsts: null
    note: >-
      The public www site is the ONLY probed FCA host with no Strict-Transport-Security header;
      every application host below sets max-age=31536000; preload.
  - host: wgis.fca.gov
    https: true
    tls_version: TLSv1.2
    cert_issuer: Entrust OV TLS Issuing RSA CA 2
    cert_expires: '2027-01-08'
    hsts: max-age=31536000; preload
    role: ArcGIS REST API host (the record's only machine-readable API surface)
  - host: apps.fca.gov
    https: true
    tls_version: TLSv1.2
    cert_issuer: Entrust OV TLS Issuing RSA CA 2
    cert_expires: '2027-02-12'
    hsts: max-age=31536000; preload
    role: FCS Public Directory + Locator web applications
  - host: reports.fca.gov
    https: true
    tls_version: TLSv1.2
    cert_issuer: Entrust OV TLS Issuing RSA CA 2
    cert_expires: '2026-12-11'
    hsts: max-age=31536000; preload
    role: Consolidated Reporting System (CRS) call-report web application
  - host: ww4.fca.gov
    https: null
    note: >-
      DNS resolves to 4.79.206.89 but TCP connect to 443 and 80 times out from the public internet.
      Could not be probed. This is the host behind FCA's own "FCS Data Portal" link.
domains:
  - domain: fca.gov
    dnssec: true
    caa: []
    spf: true
    dmarc: true
    dmarc_policy: reject

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/farm-credit-administration-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.