Great-West Lifeco · Domain Security

Great West Lifeco Domain Security

Domain security

Domain security posture for Great-West Lifeco, probed live across 5 host(s) and 3 registrable domain(s). 5 host(s) serve HTTPS (up to TLSv1.3); 3 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

InsuranceCanadaLife InsuranceHealth InsuranceEmployee BenefitsRetirementWealth ManagementReinsuranceAnnuitiesPartner Gated

Transport & Host Security

www.greatwestlifeco.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 26 23:59:59 2027 GMT
developer.empower.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 29 09:47:12 2026 GMT
api.empower.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 1 06:21:50 2026 GMT
www.canadalife.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 26 23:59:59 2027 GMT
api.canadalife.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Feb 10 23:59:59 2027 GMT

Domain (DNS/Email) Security

greatwestlifeco.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
empower.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
canadalife.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

great-west-lifeco-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.greatwestlifeco.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 26 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 31536000
- host: developer.empower.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 29 09:47:12 2026 GMT
  hsts: true
  hsts_max_age: 15552000
- host: api.empower.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  1 06:21:50 2026 GMT
  hsts: null
  note: >-
    AWS API Gateway. Every anonymous request returns {"message":"Forbidden"},
    so no HSTS header is observable.
- host: www.canadalife.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 26 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
- host: api.canadalife.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Feb 10 23:59:59 2027 GMT
  hsts: null
  note: >-
    Apigee behind a Google Cloud load balancer. Anonymous requests to
    undocumented paths return HTTP 403 at the edge, so no HSTS header is
    observable; /.well-known/openid-configuration and /oauth2/v1/jwks do
    answer 200.
domains:
- domain: greatwestlifeco.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: empower.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: canadalife.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
  dmarc_note: >-
    _dmarc.canadalife.com CNAMEs to _dmarc.reject.canadalife.com; policy
    v=DMARC1; p=reject with Proofpoint rua/ruf reporting.