Insurance Australia Group · Domain Security

Iag Domain Security

Domain security

Domain security posture for Insurance Australia Group, probed live across 13 host(s) and 6 registrable domain(s). 13 host(s) serve HTTPS (up to TLSv1.3); 9 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

InsuranceAustraliaNew ZealandProperty and CasualtyGeneral InsuranceCarrierUnderwritingClaimsBrokerPartner Gated

Transport & Host Security

www.iag.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 6 23:59:59 2026 GMT
apis.iag.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 3 23:59:59 2026 GMT
docs.iag.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 13 23:59:59 2026 GMT
api.iag.com.au
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: Aug 12 23:59:59 2026 GMT
api.cgu.com.au
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: Sep 18 23:59:59 2026 GMT
api.nrma.com.au
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: Sep 18 23:59:59 2026 GMT
api.wfi.com.au
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: Dec 3 23:59:59 2026 GMT
test-api.iag.com.au
HTTPS: yes · TLS: TLSv1.2 · HSTS: yes · cert expires: Dec 3 23:59:59 2026 GMT
api.iag.co.nz
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 17 23:59:59 2026 GMT
www.cgu.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 6 23:59:59 2026 GMT
www.nrma.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 6 23:59:59 2026 GMT
www.iag.co.nz
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 17 23:59:59 2026 GMT
security.iag.com.au
HTTPS: yes · HSTS: no

Domain (DNS/Email) Security

iag.com.au
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
cgu.com.au
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
nrma.com.au
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
wfi.com.au
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
iag.co.nz
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
rollin.com.au
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

iag-domain-security.yml Raw ↑
generated: '2026-07-25'
method: probed
source: live DNS/TLS/HTTP probes of every IAG brand website, Apigee gateway virtual host and ancillary host
summary: >-
  Every IAG host is HTTPS-only and presents a valid certificate. The estate
  splits cleanly in two: the Akamai-fronted brand websites negotiate TLS 1.3,
  while all five Apigee gateway virtual hosts negotiate TLS 1.2. HSTS is present
  everywhere except api.iag.co.nz, but the max-age is weak (86400 = 1 day) on
  every Apigee host and on the NRMA, CGU and IAG NZ brand sites; only
  apis.iag.com.au and docs.iag.com.au set a one-year max-age with
  includeSubDomains, and only apis.iag.com.au sets preload. No IAG domain is
  DNSSEC-signed and no IAG domain publishes a CAA record. Email authentication is
  strong and centrally managed — every domain publishes SPF and a DMARC record
  with p=reject reporting to dmarc.reporting@iag.com.au.
hosts:
- host: www.iag.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Dec  6 23:59:59 2026 GMT'
  hsts: false
  edge: Akamai
- host: apis.iag.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Oct  3 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  hsts_preload: true
  http_status: 403
  edge: Akamai
  note: Host resolves via apis.iag.com.au.edgekey.net. Returns Akamai "Access Denied" for every path.
- host: docs.iag.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Dec 13 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  edge: Azure App Service
  note: >-
    CNAME docs-iag-prod-wap.azurewebsites.net. Redirects to Microsoft Entra ID
    sign-in via Azure Easy Auth. Internal documentation behind SSO.
- host: api.iag.com.au
  https: true
  tls_version: TLSv1.2
  cert_expires: 'Aug 12 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  edge: Apigee Edge
  note: CNAME iag-prod-production.apigee.net. Virtual host https_vhost.
- host: api.cgu.com.au
  https: true
  tls_version: TLSv1.2
  cert_expires: 'Sep 18 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  edge: Apigee Edge
  note: CNAME iag-prod-production.apigee.net. Virtual host https_cgu_vhost.
- host: api.nrma.com.au
  https: true
  tls_version: TLSv1.2
  cert_expires: 'Sep 18 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  edge: Apigee Edge
  note: CNAME iag-prod-production.apigee.net. Virtual host https_nrma_vhost.
- host: api.wfi.com.au
  https: true
  tls_version: TLSv1.2
  cert_expires: 'Dec  3 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  edge: Apigee Edge
  note: Virtual host https_wfi_vhost. Fourth brand virtual host, newly identified this round.
- host: test-api.iag.com.au
  https: true
  tls_version: TLSv1.2
  cert_expires: 'Dec  3 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  edge: Apigee Edge
  note: >-
    CNAME iag-nonprod-test.apigee.net. Non-production Apigee organisation
    (iag-nonprod, env test), publicly resolvable. Newly identified this round.
- host: api.iag.co.nz
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Oct 17 23:59:59 2026 GMT'
  hsts: false
  edge: Akamai
  note: New Zealand business (State/AMI/NZI). Akamai "Access Denied"; no public content.
- host: www.cgu.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Dec  6 23:59:59 2026 GMT'
  hsts: false
  edge: Akamai
- host: www.nrma.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Dec  6 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  hsts_include_subdomains: true
  edge: Akamai
- host: www.iag.co.nz
  https: true
  tls_version: TLSv1.3
  cert_expires: 'Oct 17 23:59:59 2026 GMT'
  hsts: true
  hsts_max_age: 86400
  hsts_include_subdomains: true
  edge: Akamai
- host: security.iag.com.au
  https: true
  http_status: 401
  hsts: false
  note: >-
    HTTP 401 with WWW-Authenticate Basic realm "IBM Verify Identity Access for
    Web". An IBM Verify Identity Access (WebSEAL) reverse proxy, not a public
    security page.
domains:
- domain: iag.com.au
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:_spf.salesforce.com include:spf.protection.outlook.com a:chi-web-01.simprocloud.com include:eventsairmail.com include:service-now.com include:_spf-dc10.sapsf.com -all
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: dmarc.reporting@iag.com.au
- domain: cgu.com.au
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: dmarc.reporting@iag.com.au
  note: >-
    SPF includes mrspf.ebix.com.au and a:ssiw.qvalent.com — independent
    corroboration that CGU transacts over the Ebix Sunrise Exchange broker rail
    and uses Qvalent (Westpac) payment infrastructure.
- domain: nrma.com.au
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: dmarc.reporting@iag.com.au
- domain: wfi.com.au
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: dmarc.reporting@iag.com.au
- domain: iag.co.nz
  dnssec: false
  caa: []
  spf: true
  spf_qualifier: softfail
  dmarc: true
  dmarc_policy: reject
  dmarc_rua: dmarc.reporting@iag.com.au
  note: SPF terminates in ~all (softfail) rather than -all as on the Australian domains.
- domain: rollin.com.au
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 ip6:fdcf:abda:4154::/48 -all
  dmarc: false
  note: >-
    ROLLiN' brand domain. The _dmarc TXT record contains an SPF string, not a
    DMARC policy — a misconfiguration that leaves the domain without a valid
    DMARC record. The SPF itself authorises only an RFC 4193 unique-local IPv6
    range, which cannot originate internet mail.
findings:
- No IAG domain is DNSSEC-signed.
- No IAG domain publishes a CAA record.
- All five Apigee virtual hosts negotiate TLS 1.2, not TLS 1.3.
- HSTS max-age of 86400 on the Apigee hosts is an order of magnitude below the
  31536000 recommended for preload eligibility.
- _dmarc.rollin.com.au contains an SPF record instead of a DMARC policy.