Fazz · Domain Security

Fazz Domain Security

Domain security

Domain security posture for Fazz, probed live across 3 host(s) and 2 registrable domain(s). 3 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

FintechPaymentsBusiness BankingDisbursementsSoutheast AsiaPayNowVirtual Accounts

Transport & Host Security

www.xfers.io
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Aug 23 03:38:06 2026 GMT
fazz.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 23 07:17:40 2026 GMT
docs.fazz.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Aug 29 07:54:17 2026 GMT

Domain (DNS/Email) Security

fazz.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none
xfers.io
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-07-17'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.xfers.io
  https: true
  tls_version: TLSv1.3
  cert_issuer: Google Trust Services (WE1)
  cert_expires: Aug 23 03:38:06 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  notes: Production Fazz Payments API host (base path /api/v4).
- host: fazz.com
  https: true
  tls_version: TLSv1.3
  cert_issuer: Google Trust Services (WE1)
  cert_expires: Sep 23 07:17:40 2026 GMT
  hsts: false
  notes: Corporate/marketing site; no HSTS header observed on the root response.
- host: docs.fazz.com
  https: true
  tls_version: TLSv1.3
  cert_issuer: Let's Encrypt (YE2)
  cert_expires: Aug 29 07:54:17 2026 GMT
  notes: Developer documentation portal.
domains:
- domain: fazz.com
  dnssec: false
  caa: []
  spf: true
  spf_record: 'v=spf1 include:_spf.google.com include:mail.zendesk.com include:_spf.smtp.mailtrap.live ~all'
  dmarc: true
  dmarc_policy: quarantine
  dmarc_record: 'v=DMARC1; p=quarantine; rua=mailto:dmarc@smtp.mailtrap.live; ruf=mailto:dmarc@smtp.mailtrap.live; rf=afrf; pct=100'
- domain: xfers.io
  dnssec: false
  caa: []
  spf: true
  spf_record: 'v=spf1 include:_spf.google.com include:mailgun.org ~all'
  dmarc: true
  dmarc_policy: quarantine
  dmarc_record: 'v=DMARC1; p=quarantine; rua=mailto:enablethisnexttime@xfers.io'