Immunai Domain Security
Domain security posture for Immunai, probed live across 3 host(s) and 1 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).
Transport & Host Security
Domain (DNS/Email) Security
Source
Domain Security
generated: '2026-08-04'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.immunai.com
https: true
tls_version: TLSv1.3
cert_expires: Sep 7 23:59:59 2026 GMT
hsts: null
note: >-
No Strict-Transport-Security response header. Served by Flywheel/5.1.0 (managed
WordPress hosting).
- host: api.immunai.com
https: false
tls_version: null
cert_expires: null
hsts: null
dns: 34.110.128.250
http_status: null
note: >-
An A record exists but no Immunai service answers on it. TCP 443 connects to a
Google Cloud front end, then the TLS handshake is reset before any certificate is
presented (no peer certificate available). Port 80 does not answer either. This is
a stale DNS record pointing at a Google Cloud address that no longer terminates for
this hostname — not an Immunai API host.
- host: app.immunai.com
https: false
tls_version: TLSv1.3
cert_expires: Aug 26 23:59:59 2026 GMT
hsts: null
dns: 34.144.219.193
http_status: 403
note: >-
An A record exists but the address is not serving Immunai. TLS completes and
presents a certificate for an unrelated third party — subject CN=*.asa.com.br,
issued by ZeroSSL — so the hostname fails certificate validation for any client.
Ignoring validation, the Google Cloud front end returns 403 Forbidden. This is a
dangling DNS record aimed at a Google Cloud address now held by another tenant.
domains:
- domain: immunai.com
dnssec: false
caa:
- 0 issue "letsencrypt.org"
- 0 iodef "mailto:security@immunai.com"
- 0 issue "amazon.com"
- 0 issue "awstrust.com"
- 0 issuewild "digicert.com"
- 0 issue "amazonaws.com"
spf: true
dmarc: true
dmarc_policy: reject
findings:
- id: dangling-dns-records
severity: informational
hosts:
- api.immunai.com
- app.immunai.com
summary: >-
Two immunai.com subdomains publish A records into Google Cloud address space where
no Immunai service is reachable. app.immunai.com presents a valid certificate for a
wholly unrelated domain (*.asa.com.br), which is the signature of an address
released back to the cloud provider and reallocated to another tenant while the DNS
record was left in place. Recorded as observed fact; no exploitation was attempted
and no takeover is asserted.
observed: '2026-08-04'
- id: no-hsts
severity: informational
hosts:
- www.immunai.com
summary: >-
The primary web host does not send Strict-Transport-Security, so it does not opt
into HSTS preloading or protect against a first-request downgrade.
observed: '2026-08-04'
- id: no-dnssec
severity: informational
hosts:
- immunai.com
summary: The immunai.com zone is not DNSSEC signed.
observed: '2026-08-04'
strengths:
- CAA is published and pins issuance to Let's Encrypt, Amazon and DigiCert.
- CAA carries an iodef reporting address (security@immunai.com) for certificate misissuance.
- SPF is published and DMARC is enforced at policy p=reject.
- TLS 1.3 on the primary web host.
x-evidence:
fetched: '2026-08-04'
method: dig for DNS/CAA/SPF/DMARC; openssl s_client for TLS; curl for HTTP status and headers
note: >-
api.immunai.com and app.immunai.com were recorded as unresolved by the prior
enrichment round. They do resolve; this round probed them directly and recorded the
real state. Neither serves an Immunai API.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/immunai-domain-security"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.