Phone Com · Domain Security

Phone Com Domain Security

Domain security

Transport and DNS security posture probed for the Phone.com public API host and marketing host. Absence of a record is valid, expected data.

Domain security posture for Phone Com, probed live across 2 host(s) and 0 registrable domain(s).

CompanyVoIPTelephonyBusiness PhoneSMSVideo ConferencingCommunicationsAPI

Transport & Host Security

api.phone.com
HTTPS: no · HSTS: no
www.phone.com
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

Source

Domain Security

phone-com-domain-security.yml Raw ↑
generated: '2026-07-20'
method: probed
source: manual probe (curl/dig)
type: DomainSecurity
description: >-
  Transport and DNS security posture probed for the Phone.com public API host
  and marketing host. Absence of a record is valid, expected data.
hosts:
- host: api.phone.com
  tls: true
  http_version: HTTP/2
  hsts: false
  note: Returns HTTP 401 without a token (all endpoints require OAuth). TLS negotiated successfully.
- host: www.phone.com
  tls: true
  http_version: HTTP/2
  hsts: false
dns:
  domain: phone.com
  dnssec: false
  caa: false
  spf: true
  spf_record: "v=spf1 ip4:72.1.46.0/23 include:_spf.google.com include:spf.mandrillapp.com include:stspg-customer.com include:spf.smtp2go.com include:_spf.salesforce.com include:amazonses.com include:spf.protection.outlook.com ~all"
  dmarc: true
  dmarc_policy: none
  dmarc_record: "v=DMARC1; p=none; sp=none; rua=mailto:dmarc@phone.com"
findings:
- SPF and DMARC are published (DMARC at monitor-only p=none).
- No DNSSEC (no DS record) and no CAA record at the apex.
- HSTS not observed on either the API or marketing host.