IHG Hotels & Resorts · Domain Security
Ihg Hotels Domain Security
Domain security
Domain security posture for IHG Hotels & Resorts, probed live across 8 host(s) and 2 registrable domain(s). 8 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=none).
TravelUnited KingdomHospitalityHotelsBookingDistributionGDSLoyaltyAffiliatePartner Gated
Transport & Host Security
www.ihg.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Oct 23 23:59:59 2026 GMT
www.ihgplc.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
apis.ihg.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
dev-apis.ihg.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
b2b.ihg.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
partnerconnect.ihg.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
www.ihgagent.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
api.ihg.com
HTTPS: yes
· HSTS: no
Domain (DNS/Email) Security
ihg.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=none)
· CAA: none
ihgplc.com
DNSSEC: no
· SPF: no
· DMARC: no
· CAA: none
Source
Domain Security
generated: '2026-07-28'
method: probed
source: >-
live DNS/TLS/HTTP probes of apis.yml hosts plus every IHG API and edge
hostname found in review.yml. Baseline written by
0-working/probe-domain-security.py, extended with the additional hosts and
the ihgplc.com registrable domain. Probed 2026-07-28.
summary: >-
TLS hygiene is uniformly good — every IHG host that answers negotiates
TLS 1.3 with a valid certificate chain. Everything above the transport is
weak or missing. www.ihg.com, the consumer booking site that carries payment
and loyalty traffic, returns no HSTS header at all. The ihg.com DMARC record
is published but set to p=none, which monitors spoofing rather than
preventing it. Neither ihg.com nor ihgplc.com is DNSSEC-signed and neither
publishes a CAA record, so nothing constrains which CA may issue for these
domains. ihgplc.com — the investor-relations domain — publishes no SPF and no
DMARC record of any kind.
hosts:
- host: www.ihg.com
https: true
tls_version: TLSv1.3
cert_expires: Oct 23 23:59:59 2026 GMT
hsts: false
hsts_max_age: null
server: AkamaiGHost
note: Consumer booking site. Akamai bot defence returns 403 to non-browser clients.
- host: www.ihgplc.com
https: true
tls_version: TLSv1.3
cert_valid: true
hsts: true
hsts_max_age: 15552000
hsts_include_subdomains: true
hsts_preload: true
server: cloudflare
note: Investis-hosted corporate site. The only IHG host with a strong HSTS policy.
- host: apis.ihg.com
https: true
tls_version: TLSv1.3
cert_valid: true
hsts: false
server: AkamaiGHost
http_status: 403
edge: prod-external.ihg.edgekey.net
- host: dev-apis.ihg.com
https: true
tls_version: TLSv1.3
cert_valid: true
hsts: false
server: AkamaiGHost
http_status: 403
edge: np-external.ihg.edgekey.net
note: Non-production external API edge, discovered this round.
- host: b2b.ihg.com
https: true
tls_version: TLSv1.3
cert_valid: true
hsts: false
server: AkamaiNetStorage
http_status: 404
edge: prod-b2b.ihg.edgekey.net
- host: partnerconnect.ihg.com
https: true
tls_version: TLSv1.3
cert_valid: true
hsts: false
server: nginx
http_status: 200
note: >-
The live affiliate programme, running WordPress 5.2.24 — a release line
that has been out of active support for years. No HSTS.
- host: www.ihgagent.com
https: true
tls_version: TLSv1.3
cert_valid: true
hsts: false
server: AkamaiGHost
http_status: 403
note: Travel agent portal; redirects to www.ihg.com/agent-portal, then Akamai-blocked.
- host: api.ihg.com
https: unknown
note: >-
Resolves through ihg.api.mashery.com and sb-ihg.mashery.com. The TLS
connection times out from this client, so no transport assertion is made.
domains:
- domain: ihg.com
dnssec: false
caa: []
spf: true
spf_record: >-
v=spf1 include:_spf.ihg.com include:_spf.google.com include:amazonses.com
include:spf.protection.outlook.com include:_spf.highradius.com
ip4:148.163.135.129 ip4:216.133.255.190 ip4:147.154.153.87 ip4:138.1.67.161
ip4:138.1.65.17 -all
spf_qualifier: '-all'
dmarc: true
dmarc_policy: none
dmarc_reporting: >-
rua to dmarcian and Proofpoint Email Defense; ruf to Proofpoint. fo=1.
note: >-
SPF is well-formed and ends in a hard fail (-all), which is the strong
choice. DMARC is published but p=none: reports are collected and acted on
by two vendors, but no receiver is instructed to quarantine or reject
spoofed IHG mail. For a brand whose loyalty programme is a standing
phishing target, p=none is the weak link.
- domain: ihgplc.com
dnssec: false
caa: []
spf: false
dmarc: false
note: >-
The investor-relations domain publishes neither SPF nor DMARC. Any sender
can spoof @ihgplc.com with no policy signal to receivers.
security_txt: false
vulnerability_disclosure: none-found
trust_center: false
disclosure_note: >-
0-working/probe-security-programs.py returned vdp=none trust=none on
2026-07-28. No /.well-known/security.txt on ihg.com (403 bot-block),
ihgplc.com (404) or partnerconnect.ihg.com (404). trust.ihg.com and
security.ihg.com do not resolve. No bug bounty programme on HackerOne,
Bugcrowd or Intigriti was found. No named certification (SOC 2, ISO 27001,
PCI DSS, HIPAA, FedRAMP) is published on any IHG property; the
responsible-business policy library carries environmental, human-rights,
community and supplier-code documents but no information-security policy.
Because nothing was verified, no VulnerabilityDisclosure, Security,
TrustCenter or Compliance pointer is wired into apis.yml.