Lawn Love · Domain Security

Lawn Love Domain Security

Domain security

Domain security posture for Lawn Love, probed live across 2 host(s) and 0 registrable domain(s).

CompanyHome ServicesLawn CareMarketplaceOn-DemandField ServiceSchedulingLocal ServicesConsumer

Transport & Host Security

lawnlove.com
HTTPS: no · HSTS: yes
api.lawnlove.com
HTTPS: no · HSTS: yes

Domain (DNS/Email) Security

Source

Domain Security

lawn-love-domain-security.yml Raw ↑
generated: '2026-07-19'
method: probed
source: dig + curl probes of lawnlove.com and api.lawnlove.com
domain: lawnlove.com
hosts:
- host: lawnlove.com
  tls:
    https: true
    certificate_verified: true
    edge: cloudflare
    application: laravel-vapor
    evidence: >-
      HTTP/2 200 over TLS with ssl_verify_result=0; response carries
      server: cloudflare and x-vapor-base64-encode headers
  hsts:
    present: false
    evidence: no strict-transport-security header on the apex response
  headers:
    cache_control: 'no-cache, private'
    cookies_secure: true
    cookies_samesite: lax
- host: api.lawnlove.com
  tls:
    https: true
    certificate_verified: true
    edge: cloudflare + aws-cloudfront + api-gateway
    evidence: >-
      response headers include x-amz-apigw-id, via 1.1 ... cloudfront.net,
      and server: cloudflare
  hsts:
    present: true
    max_age: 300
    include_subdomains: true
    evidence: 'strict-transport-security: max-age=300; includeSubDomains'
    note: >-
      max-age of 300 seconds is far below the 31536000 (1 year) commonly
      recommended for preload-eligible HSTS
  headers:
    x_frame_options: SAMEORIGIN
    x_content_type_options: nosniff
    referrer_policy: strict-origin-when-cross-origin
    access_control_allow_origin: '*'
dns:
  nameservers:
  - sara.ns.cloudflare.com
  - mitch.ns.cloudflare.com
  a_records:
  - 172.66.174.91
  - 104.20.32.191
  dnssec:
    enabled: false
    evidence: no DS record returned for lawnlove.com
  caa:
    present: false
    evidence: no CAA records returned for lawnlove.com
email:
  spf:
    present: true
    record: 'v=spf1 include:sendgrid.net include:_spf.google.com include:servers.mcsv.net include:mail.zendesk.com ~all'
    policy: softfail
    senders:
    - sendgrid.net
    - _spf.google.com
    - servers.mcsv.net
    - mail.zendesk.com
  dmarc:
    present: true
    record: 'v=DMARC1; p=none; rua=mailto:media@lawnlove.com'
    policy: none
    aggregate_reports: media@lawnlove.com
    note: >-
      p=none is monitor-only and does not instruct receivers to quarantine or
      reject spoofed mail
findings:
- severity: low
  finding: No DNSSEC (no DS record published).
- severity: low
  finding: No CAA record, so any public CA may issue for the domain.
- severity: low
  finding: No HSTS on the apex host; api.lawnlove.com sets only max-age=300.
- severity: low
  finding: DMARC policy is p=none (monitoring only, no enforcement).

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lawn-love-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.