Home
Lithium
Security
Lithium Domain Security
Domain security
Live TLS/DNS posture across the Khoros, Lithium, Spredfast and flow.ai hosts this provider spans. The headline finding is that the legacy lithium.com apex — still the company's original domain and still serving the Khoros marketing site — presents a TLS certificate that expired on 3 January 2026, so every modern client refuses the connection. HSTS coverage is inconsistent and no domain in the estate is DNSSEC-signed.
Domain security posture for Lithium, probed live across 10 host(s) and 5 registrable domain(s). 10 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=none).
Company MarTech Community Social-Media Customer Engagement Customer-Support Chatbots Messaging Analytics Marketing
Transport & Host Security
khoros.ai
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Sep 3 05:48:31 2026 GMT
developer.khoros.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Oct 3 20:18:28 2026 GMT
api.app.lithium.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Jan 24 23:59:59 2027 GMT
www.lithium.com
HTTPS: yes
· HSTS: yes
· cert expires: Jan 3 19:44:37 2026 GMT
lithium.com
HTTPS: yes
· HSTS: yes
· cert expires: Jan 3 19:44:37 2026 GMT
community.khoros.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: yes
· cert expires: Aug 25 18:51:00 2026 GMT
api.spredfast.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Nov 17 23:59:59 2026 GMT
login.spredfast.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Nov 17 23:59:59 2026 GMT
api.flow.ai
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Oct 13 15:18:06 2026 GMT
api.massrelevance.com
HTTPS: yes
· TLS: TLSv1.3
· HSTS: no
· cert expires: Sep 28 23:59:59 2026 GMT
Domain (DNS/Email) Security
khoros.ai
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=none)
· CAA: none
khoros.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: yes
lithium.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
spredfast.com
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=reject)
· CAA: none
flow.ai
DNSSEC: no
· SPF: yes
· DMARC: yes
(p=quarantine)
· CAA: yes
Source
Domain Security
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.
apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
resolveTurn a domain, URL or GitHub org into the provider it belongs to.
find_cohortsEvery scored population of providers in the catalog.
All 92 tools →
Call it yourself
curl for this page
This security artifact
curl "https://apis.io/api/v1/security/lithium-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no email required.
A second provider on the same verified email joins the account you already have.