PayMongo · Domain Security

Paymongo Domain Security

Domain security

Domain security posture for PayMongo, probed live across 3 host(s) and 1 registrable domain(s). 3 host(s) serve HTTPS; 0 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

PaymentsFinTechPhilippinesSoutheast AsiaGCashE-WalletCard Payments

Transport & Host Security

paymongo.com
HTTPS: yes · HSTS: no · cert expires: Feb 20 23:59:59 2027 GMT
api.paymongo.com
HTTPS: yes · HSTS: no · cert expires: Feb 20 23:59:59 2027 GMT
docs.paymongo.com
HTTPS: yes · HSTS: no

Domain (DNS/Email) Security

paymongo.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: yes

Source

Domain Security

Raw ↑
generated: '2026-07-17'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: paymongo.com
  https: true
  server: CloudFront
  cert_expires: Feb 20 23:59:59 2027 GMT
  hsts: null
- host: api.paymongo.com
  https: true
  cert_expires: Feb 20 23:59:59 2027 GMT
  auth_required: true
  probe_status: 401
  hsts: null
- host: docs.paymongo.com
  https: true
  note: developers.paymongo.com issues a 301 redirect to docs.paymongo.com
domains:
- domain: paymongo.com
  dnssec: false
  caa:
  - 0 issue "pki.goog"
  - 0 issue "amazon.com"
  - 0 issue "digicert.com"
  - 0 issue "globalsign.com"
  - 0 issue "letsencrypt.org"
  - 0 iodef "mailto:caa-violations@paymongo.com"
  spf: true
  spf_record: v=spf1 include:_spf.createsend.com include:_spf.google.com include:7079113.spf03.hubspotemail.net ~all
  dmarc: true
  dmarc_policy: quarantine
  dmarc_note: p=quarantine; sp=quarantine; pct=25; rua/ruf mailto:dmarc-report@paymongo.com
notes: >-
  api.paymongo.com and paymongo.com both serve valid TLS certificates (expiry
  Feb 20 2027) fronted by AWS CloudFront. api.paymongo.com/v1 returns HTTP 401
  without credentials, confirming enforced authentication. A CAA record scopes
  issuance to a defined set of CAs with an iodef violation contact. SPF and
  DMARC (quarantine) are published. No HSTS header was observed on the probed
  hosts at probe time, and no /.well-known/security.txt was found (HTTP 404).