Monash Domain Security
Domain security posture for Monash University, probed live across 5 host(s) and 2 registrable domain(s). 5 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).
Transport & Host Security
Domain (DNS/Email) Security
Source
Domain Security
generated: '2026-08-19'
method: probed
source: >-
Live DNS/TLS/HTTP probes of the hosts and domains Monash University itself operates.
Rescoped 2026-08-19 by the university pipeline: the previous revision probed
api.figshare.com and the figshare.com domain and recorded the result as Monash's
security posture. Those are generic vendor hosts shared by every Figshare customer and
have been dropped — a vendor's TLS and DMARC configuration is not the institution's.
Only hosts under a Monash-owned registrable domain (monash.edu, monash.edu.au) are
probed here.
scope:
included: institution-operated hosts only
excluded_vendor_hosts:
- host: api.figshare.com
reason: generic vendor host, shared by every Figshare customer
- host: monash.figshare.com
reason: tenant host on the Figshare platform; TLS terminated by the vendor
excluded_vendor_domains:
- domain: figshare.com
reason: vendor-controlled registrable domain
hosts:
- host: www.monash.edu
x-operator: institution
https: true
tls_version: TLSv1.3
cert_expires: Dec 12 23:59:59 2026 GMT
hsts: true
hsts_max_age: 31536000
edge: cloudflare
note: >-
Returns HTTP 403 with cf-mitigated: challenge to non-browser clients — a Cloudflare
managed bot challenge, not an outage. Live for browsers.
- host: idp.monash.edu.au
x-operator: institution
https: true
tls_version: TLSv1.3
cert_issuer: C=US, O=Amazon, CN=Amazon RSA 2048 M01
cert_expires: Feb 26 23:59:59 2027 GMT
hsts: true
hsts_max_age: 63072000
hsts_include_subdomains: true
note: Shibboleth IdP; serves signed SAML 2.0 metadata as application/xml.
- host: crams-api.erc.monash.edu
x-operator: institution
https: true
tls_version: TLSv1.3
cert_issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
cert_expires: Jan 31 23:59:59 2027 GMT
hsts: true
hsts_max_age: 63072000
hsts_include_subdomains: true
note: >-
CRAMS portal. Sends x-frame-options: DENY, x-content-type-options: nosniff and
referrer-policy: same-origin.
- host: hpc.erc.monash.edu.au
x-operator: institution
https: true
tls_version: TLSv1.3
cert_issuer: C=GB, O=Sectigo Limited, CN=Sectigo Public Server Authentication CA OV R36
cert_expires: Jan 2 23:59:59 2027 GMT
hsts: true
hsts_max_age: 31536000
- host: docs.erc.monash.edu
x-operator: institution
https: true
tls_version: TLSv1.3
cert_issuer: C=AT, O=ZeroSSL GmbH, CN=ZeroSSL RSA DV SSL CA 2
cert_expires: Oct 21 23:59:59 2026 GMT
hsts: false
note: >-
Only institution host probed without HSTS, and the only one on a domain-validated
certificate rather than an OV certificate.
domains:
- domain: monash.edu
x-operator: institution
dnssec: false
caa:
- 0 issue "digicert.com"
- 0 iodef "mailto:cert-request-l@monash.edu"
- 0 issuewild "sectigo.com"
- 0 issue "sectigo.com"
- 0 issue "amazonaws.com"
spf: true
dmarc: true
dmarc_policy: reject
- domain: monash.edu.au
x-operator: institution
dnssec: false
caa:
- 0 issue "quovadisglobal.com"
- 0 issuewild "quovadisglobal.com"
- 0 issuewild "amazonaws.com"
- 0 iodef "mailto:cert-request-l@monash.edu"
- 0 issue "amazonaws.com"
- 0 issuewild "sectigo.com"
- 0 issue "digicert.com"
- 0 issue "sectigo.com"
spf: true
spf_record: v=spf1 include:_spf.google.com -all
dmarc: true
dmarc_policy: reject
dmarc_subdomain_policy: reject
dmarc_rua: mailto:05clawtu@ag.dmarcian-ap.com
note: >-
Monash's Australian registrable domain, added 2026-08-19. It carries the identity
federation surface (idp.monash.edu.au) and the eResearch HPC SP, and was absent from
the previous revision even though the repo's most significant contract lives on it.
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.
MCP server
One button, every client — Claude, Cursor, VS Code and the rest.
https://apis.io/mcp
Tools for security posture
4 MCP tools reach this
find_securityBrowse and filter every security artifact in the catalog.apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.resolveTurn a domain, URL or GitHub org into the provider it belongs to.find_cohortsEvery scored population of providers in the catalog.
Call it yourself
curl for this page
curl "https://apis.io/api/v1/security/monash-domain-security"
curl "https://apis.io/api/v1/security?limit=25"
Discovery needs no key. Ratings and market analysis are Pro.
Get an API key
Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.
A second provider on the same verified email joins the account you already have.