Moore Threads · Domain Security

Moore Threads Domain Security

Domain security

Domain security posture for Moore Threads, probed live across 7 host(s) and 2 registrable domain(s). 6 host(s) serve HTTPS (up to TLSv1.3); 2 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF absent, DMARC absent.

CompanyGPUArtificial IntelligenceMachine-LearningSemiconductorsSpeech RecognitionText-to-SpeechVoiceLLM InferenceCloud ComputingDeveloper ToolsChina

Transport & Host Security

www.mthreads.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Mar 14 23:59:59 2027 GMT
docs.mthreads.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Mar 14 23:59:59 2027 GMT
aibook-api.mthreads.com
HTTPS: no · HSTS: no
aibook-api.mthreads.com:32414
HTTPS: yes · TLS: TLSv1.2 · HSTS: no
aibook-api.mthreads.com:62220
HTTPS: yes · TLS: TLSv1.2 · HSTS: no
aibook-api.mthreads.com:32314
HTTPS: yes · TLS: TLSv1.2 · HSTS: no
coding-plan-endpoint.kuaecloud.net
HTTPS: yes · HSTS: no

Domain (DNS/Email) Security

kuaecloud.net
DNSSEC: no · SPF: no · DMARC: no · CAA: none
mthreads.com
DNSSEC: no · SPF: yes · DMARC: no · CAA: none

Source

Domain Security

moore-threads-domain-security.yml Raw ↑
generated: '2026-08-26'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.mthreads.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Mar 14 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 15724800
- host: docs.mthreads.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Mar 14 23:59:59 2027 GMT
  hsts: true
  hsts_max_age: 15724800
- host: aibook-api.mthreads.com
  https: false
  note: >-
    Port 443 is closed on this host. The AIBook APIs are served on non-standard high ports
    (32414 TTS, 62220 ASR, 32314 voice conversion), each probed separately below.
- host: 'aibook-api.mthreads.com:32414'
  https: true
  tls_version: TLSv1.2
  cert_valid: true
  hsts: false
  note: TTS. Handshake completes and the certificate chain validates; probes from the United States intermittently time out mid-handshake.
- host: 'aibook-api.mthreads.com:62220'
  https: true
  tls_version: TLSv1.2
  cert_valid: true
  hsts: false
  note: ASR. Verified with an unauthenticated request returning HTTP 400 over a validated TLS 1.2 channel (ECDHE-RSA-AES128-GCM-SHA256).
- host: 'aibook-api.mthreads.com:32314'
  https: true
  tls_version: TLSv1.2
  cert_valid: true
  hsts: false
  note: Streaming voice conversion.
- host: coding-plan-endpoint.kuaecloud.net
  https: true
  cert_valid: true
  hsts: false
  note: >-
    KUAE Cloud Coding Plan inference endpoint. Fronted by a Volcengine ALB
    (alb-xohaibke0f7k54ov5eie2tco.cn-beijing.volcenginealb.com). No Strict-Transport-Security
    header is returned, unlike the mthreads.com web hosts which set max-age=15724800.
domains:
- domain: kuaecloud.net
  dnssec: false
  caa: []
  spf: false
  dmarc: false
  note: >-
    The KUAE Cloud API domain carries no SPF, no DMARC, no CAA and no DNSSEC — weaker than the
    mthreads.com corporate domain, which at least publishes SPF.
- domain: mthreads.com
  dnssec: false
  caa: []
  spf: true
  dmarc: false
findings:
- The three AIBook API listeners run TLS 1.2 with no HSTS, while the marketing hosts run TLS 1.3 with HSTS — the API surface is the weaker half of the estate.
- No host on either domain publishes CAA records, so any public CA may issue for mthreads.com or kuaecloud.net.
- DNSSEC is unsigned on both domains and DMARC is absent on both.
checked: '2026-08-26'

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/moore-threads-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.