Likeable Local · Domain Security

Likeable Local Domain Security

Domain security

Domain security posture for Likeable Local, probed live across 3 host(s) and 2 registrable domain(s). 3 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF absent, DMARC absent.

CompanySocial MediaMarketingSocial Media ManagementAdvertisingSmall BusinessAgenciesSaaS

Transport & Host Security

storytellit.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 13 06:08:51 2026 GMT
api.storytellit.com
HTTPS: yes · HSTS: no · cert expires: Nov 5 23:59:59 2026 GMT
app.storytellit.com
HTTPS: yes · HSTS: no · cert expires: Oct 24 23:59:59 2026 GMT

Domain (DNS/Email) Security

storytellit.com
DNSSEC: no · SPF: no · DMARC: no · CAA: none
likeablelocal.com
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

likeable-local-domain-security.yml Raw ↑
generated: '2026-08-12'
method: probed
source: >-
  live DNS/TLS/HTTP probes of apis.yml hosts, extended by hand to the production API host and the
  application host discovered in the 2026-08-12 round
hosts:
- host: storytellit.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 13 06:08:51 2026 GMT
  hsts: true
  hsts_max_age: 15768000
- host: api.storytellit.com
  https: true
  cert_expires: Nov  5 23:59:59 2026 GMT
  cert_issuer: Amazon RSA 2048 M04
  hsts: false
  note: >-
    Production API host. Serves the application backend; no HSTS header on any response, so a
    downgrade window exists on first contact.
- host: app.storytellit.com
  https: true
  cert_expires: Oct 24 23:59:59 2026 GMT
  cert_issuer: Amazon RSA 2048 M01
  hsts: false
  note: Login-gated application host behind CloudFront; no HSTS header.
domains:
- domain: storytellit.com
  dnssec: false
  caa: []
  spf: false
  dmarc: false
  note: >-
    The primary brand domain carries only Google site-verification TXT records — no SPF, no DMARC,
    no CAA, no DNSSEC.
- domain: likeablelocal.com
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:_spf.google.com ~all
  dmarc: false
  note: >-
    The legacy brand domain still publishes SPF (Google Workspace) while the current brand domain
    does not, and neither publishes DMARC. Mail authentication regressed across the rebrand.