Immune-Onc Therapeutics · Domain Security

Immune Onc Therapeutics Domain Security

Domain security

Domain security posture for Immune-Onc Therapeutics, probed live across 1 host(s) and 2 registrable domain(s). 1 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF absent, DMARC absent.

CompanyBiotechnologyBiopharmaceuticalOncologyImmunotherapyImmuno-OncologyAntibodiesClinical TrialsLife SciencesHealthcareDrug Development

Transport & Host Security

www.immune-onc.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 3 20:57:23 2026 GMT

Domain (DNS/Email) Security

immune-onc.com
DNSSEC: no · SPF: no · DMARC: no · CAA: none
immuneonc.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

immune-onc-therapeutics-domain-security.yml Raw ↑
generated: '2026-08-04'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.immune-onc.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  3 20:57:23 2026 GMT
  hsts: null
domains:
- domain: immune-onc.com
  dnssec: false
  caa: []
  spf: false
  dmarc: false
  mx: [smtp.secureserver.net, mailstore1.secureserver.net]
  note: >-
    Public web domain (Squarespace-hosted marketing site). It publishes MX records and therefore
    accepts mail, but has no SPF TXT record and no _dmarc record, so mail claiming to come from
    @immune-onc.com has no published sender authentication or reporting policy.
- domain: immuneonc.com
  dnssec: false
  caa: []
  spf: true
  spf_record: 'v=spf1 ip4:50.209.135.157/29 include:spf.protection.outlook.com ~all'
  dmarc: true
  dmarc_policy: quarantine
  dmarc_record: 'v=DMARC1; p=quarantine; pct=100'
  mx: [immuneonc-com.mail.protection.outlook.com]
  web: >-
    Its web root resolves and returns 200, but only by redirecting to https://www.immune-onc.com/ —
    it serves no distinct site. Re-probed 2026-08-04 for /.well-known/security.txt,
    /.well-known/agent-card.json, /.well-known/agent.json, /llms.txt and /openapi.json: all 404.
  note: >-
    Corporate mail domain (Microsoft 365), published on the company website as the contact address
    info@immuneonc.com. Distinct from the hyphenated web domain. Added by hand-probe because it is
    never referenced as a host in apis.yml and so is invisible to the automated host walk.
programs:
  vulnerability_disclosure: none
  trust_center: none
  note: >-
    probe-security-programs.py run 2026-08-04 returned `vdp=none trust=none`. No security.txt
    Policy/Contact, no bug-bounty program (HackerOne / Bugcrowd / Intigriti), no responsible- or
    vulnerability-disclosure page, and no trust centre with named certifications (SOC 2, ISO 27001,
    PCI DSS, HIPAA, FedRAMP) was found on any host. Per the pipeline contract no
    vulnerability-disclosure or trust-center artifact is written and no Security, Compliance or
    TrustCenter pointer is wired, because there is nothing verified to point at.
x-evidence:
  probed: '2026-08-04'
  method: dig TXT/MX/CAA + _dmarc lookup, TLS/HTTP HEAD
  findings:
  - No CAA records on either domain — any public CA may issue for these names.
  - No DNSSEC on either domain.
  - No HSTS response header on www.immune-onc.com.
  - >-
    The two domains diverge: the mail domain immuneonc.com is SPF- and DMARC-protected
    (p=quarantine), while the web domain immune-onc.com accepts mail with neither. A look-alike
    sender on the web domain is the unprotected path.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/immune-onc-therapeutics-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.