Food Info · Domain Security

Food Info Domain Security

Domain security

Domain security posture for Food Info, probed live across 2 host(s) and 1 registrable domain(s). 2 host(s) serve HTTPS (up to TLSv1.3); 2 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

NutritionFoodFood CompositionNutrientsDataOpen DataDieteticsRecipesHealthResearch

Transport & Host Security

food-info.org
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 22 14:04:23 2026 GMT
api.food-info.org
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 22 14:04:23 2026 GMT

Domain (DNS/Email) Security

food-info.org
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-08-04'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: food-info.org
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 22 14:04:23 2026 GMT
  hsts: true
  hsts_max_age: 2592000
  security_headers:
    x-content-type-options: nosniff
    x-frame-options: SAMEORIGIN
    referrer-policy: no-referrer
    permissions-policy: camera=(), microphone=(), geolocation=(), interest-cohort=()
- host: api.food-info.org
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 22 14:04:23 2026 GMT
  hsts: true
  hsts_max_age: 2592000
  security_headers:
    x-content-type-options: nosniff
    x-frame-options: DENY
    referrer-policy: strict-origin-when-cross-origin
    permissions-policy: camera=(), microphone=(), geolocation=()
    cross-origin-resource-policy: same-site
domains:
- domain: food-info.org
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
x-evidence:
  fetched: '2026-08-04'
  note: >-
    HSTS and the response security headers were re-observed directly on 2026-08-04 with a live GET
    (https://food-info.org/robots.txt and https://api.food-info.org/api/v1/nutrients). The scripted
    HEAD probe recorded hsts: null because both hosts sit behind a Cloudflare managed challenge that
    rejects non-browser HEAD requests; the values above supersede it.
  hosts_edge: cloudflare in front of fly.io