Monash University · Domain Security

Monash Domain Security

Domain security

Domain security posture for Monash University, probed live across 5 host(s) and 2 registrable domain(s). 5 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

EducationHigher EducationUniversityResearchAustraliaGroup of EightIdentity FederationResearch ComputingResearch RepositoryCourse Catalog

Transport & Host Security

www.monash.edu
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 12 23:59:59 2026 GMT
idp.monash.edu.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Feb 26 23:59:59 2027 GMT
crams-api.erc.monash.edu
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 31 23:59:59 2027 GMT
hpc.erc.monash.edu.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Jan 2 23:59:59 2027 GMT
docs.erc.monash.edu
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 21 23:59:59 2026 GMT

Domain (DNS/Email) Security

monash.edu
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: yes
monash.edu.au
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: yes

Source

Domain Security

monash-domain-security.yml Raw ↑
generated: '2026-08-19'
method: probed
source: >-
  Live DNS/TLS/HTTP probes of the hosts and domains Monash University itself operates.
  Rescoped 2026-08-19 by the university pipeline: the previous revision probed
  api.figshare.com and the figshare.com domain and recorded the result as Monash's
  security posture. Those are generic vendor hosts shared by every Figshare customer and
  have been dropped — a vendor's TLS and DMARC configuration is not the institution's.
  Only hosts under a Monash-owned registrable domain (monash.edu, monash.edu.au) are
  probed here.
scope:
  included: institution-operated hosts only
  excluded_vendor_hosts:
  - host: api.figshare.com
    reason: generic vendor host, shared by every Figshare customer
  - host: monash.figshare.com
    reason: tenant host on the Figshare platform; TLS terminated by the vendor
  excluded_vendor_domains:
  - domain: figshare.com
    reason: vendor-controlled registrable domain
hosts:
- host: www.monash.edu
  x-operator: institution
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 12 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  edge: cloudflare
  note: >-
    Returns HTTP 403 with cf-mitigated: challenge to non-browser clients — a Cloudflare
    managed bot challenge, not an outage. Live for browsers.
- host: idp.monash.edu.au
  x-operator: institution
  https: true
  tls_version: TLSv1.3
  cert_issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M01
  cert_expires: Feb 26 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 63072000
  hsts_include_subdomains: true
  note: Shibboleth IdP; serves signed SAML 2.0 metadata as application/xml.
- host: crams-api.erc.monash.edu
  x-operator: institution
  https: true
  tls_version: TLSv1.3
  cert_issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
  cert_expires: Jan 31 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 63072000
  hsts_include_subdomains: true
  note: >-
    CRAMS portal. Sends x-frame-options: DENY, x-content-type-options: nosniff and
    referrer-policy: same-origin.
- host: hpc.erc.monash.edu.au
  x-operator: institution
  https: true
  tls_version: TLSv1.3
  cert_issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
  cert_expires: Jan  2 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 31536000
- host: docs.erc.monash.edu
  x-operator: institution
  https: true
  tls_version: TLSv1.3
  cert_issuer: C=AT, O=ZeroSSL GmbH, CN=ZeroSSL RSA DV SSL CA 2
  cert_expires: Oct 21 23:59:59 2026 GMT
  hsts: false
  note: >-
    Only institution host probed without HSTS, and the only one on a domain-validated
    certificate rather than an OV certificate.
domains:
- domain: monash.edu
  x-operator: institution
  dnssec: false
  caa:
  - 0 issue "digicert.com"
  - 0 iodef "mailto:cert-request-l@monash.edu"
  - 0 issuewild "sectigo.com"
  - 0 issue "sectigo.com"
  - 0 issue "amazonaws.com"
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: monash.edu.au
  x-operator: institution
  dnssec: false
  caa:
  - 0 issue "quovadisglobal.com"
  - 0 issuewild "quovadisglobal.com"
  - 0 issuewild "amazonaws.com"
  - 0 iodef "mailto:cert-request-l@monash.edu"
  - 0 issue "amazonaws.com"
  - 0 issuewild "sectigo.com"
  - 0 issue "digicert.com"
  - 0 issue "sectigo.com"
  spf: true
  spf_record: v=spf1 include:_spf.google.com -all
  dmarc: true
  dmarc_policy: reject
  dmarc_subdomain_policy: reject
  dmarc_rua: mailto:05clawtu@ag.dmarcian-ap.com
  note: >-
    Monash's Australian registrable domain, added 2026-08-19. It carries the identity
    federation surface (idp.monash.edu.au) and the eResearch HPC SP, and was absent from
    the previous revision even though the repo's most significant contract lives on it.