May · Domain Security

May Domain Security

Domain security

Domain security posture for May, probed live across 4 host(s) and 2 registrable domain(s). 2 host(s) serve HTTPS (up to TLSv1.3); 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

CompanyHealthDigital HealthParentingPregnancyMaternal HealthConsumer HealthMobile ApplicationEmployee BenefitsFrance

Transport & Host Security

www.may.app
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 20 19:55:02 2026 GMT
may-sante.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 19 19:00:26 2026 GMT
capig.may.app
HTTPS: no · HSTS: no
go.may.app
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

may.app
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none
may-sante.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

may-domain-security.yml Raw ↑
generated: '2026-08-17'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml hosts + certificate-transparency subdomains
note: >-
  May publishes no API, so there is no baseURL and no OpenAPI servers[] host to probe. The
  hosts below are the canonical marketing host, the legacy brand domain that redirects to
  it, and the two additional subdomains found in certificate-transparency logs (crt.sh) for
  *.may.app. Everything sits behind Cloudflare. Neither registrable domain serves HSTS,
  publishes a CAA record, or is DNSSEC-signed; both publish SPF and a DMARC record at
  p=quarantine with pct=90 and sp=none, so subdomain mail is unprotected and 10% of failing
  mail on the organizational domain is still delivered unquarantined. Absence of a record
  here is observed data, not a gap in the probe.
hosts:
- host: www.may.app
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 20 19:55:02 2026 GMT
  cert_issuer: Google Trust Services (WE1)
  hsts: false
  cdn: Cloudflare
  stack: WordPress (Rank Math SEO, WPML, WP Rocket; theme by studiometa)
  note: Canonical marketing host. Apex may.app 301-redirects here.
- host: may-sante.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 19 19:00:26 2026 GMT
  cert_issuer: Google Trust Services (WE1)
  hsts: false
  cdn: Cloudflare
  note: >-
    Legacy brand domain (the URL Serena's portfolio profile lists). Serves a 301 to
    https://www.may.app/ on both the apex and the www host. No content of its own.
- host: capig.may.app
  https: false
  note: >-
    DANGLING CNAME. Found in certificate-transparency logs. Resolves to
    k8s-cloudbridgeingres-9547b3803a-310062026.eu-west-3.elb.amazonaws.com, an AWS
    Kubernetes ingress load balancer in eu-west-3 (Paris) that no longer resolves, so the
    hostname cannot be reached at all (curl: could not resolve host). It is the only trace
    of an application backend anywhere in May's public DNS, and it is decommissioned. A
    dangling CNAME to a deleted ELB is worth the company's attention as a subdomain-takeover
    surface, but it is not an API surface.
- host: go.may.app
  https: false
  note: >-
    Present in certificate-transparency logs but does not resolve in DNS. Almost certainly a
    retired link-shortener/deep-link host (the site's app-download buttons now point at
    app.adjust.com).
domains:
- domain: may.app
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:_mailcust.gandi.net include:_spf.google.com ~all
  dmarc: true
  dmarc_policy: quarantine
  dmarc_record: v=DMARC1; p=quarantine; rua=mailto:antoine@may.app; pct=90; sp=none
  mx: Google Workspace
- domain: may-sante.com
  dnssec: false
  caa: []
  spf: true
  spf_record: v=spf1 include:_spf.google.com ~all
  dmarc: true
  dmarc_policy: quarantine
  dmarc_record: v=DMARC1; p=quarantine; pct=90; sp=none;
  mx: Google Workspace

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/may-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.