RE/MAX · Domain Security

Re Max Domain Security

Domain security

Domain security posture for RE/MAX, probed live across 8 host(s) and 2 registrable domain(s). 8 host(s) serve HTTPS (up to TLSv1.3); 2 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=quarantine).

Real-EstateUnited StatesBrokerageProperty ListingsMLSRESOIDXPropTechFranchisingMortgageRentals

Transport & Host Security

www.remax.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 12 23:59:59 2026 GMT
www.remax.eu
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Sep 15 04:19:21 2026 GMT
apidocs.datahub.remax.eu
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Aug 30 03:54:38 2026 GMT
listingsapi-test.datahub.remax.eu
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 11 22:50:38 2026 GMT
api.datahub.remax.eu
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Oct 12 23:59:59 2026 GMT
oauth.datahub.remax.eu
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Oct 12 23:59:59 2026 GMT
datahub.remax.eu
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Oct 2 23:59:59 2026 GMT
listing-api-remaxeu.bwscloud.tech
HTTPS: yes · TLS: TLSv1.2 · HSTS: no · cert expires: Nov 19 23:59:59 2026 GMT

Domain (DNS/Email) Security

remax.com
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none
remax.eu
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-07-26'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.remax.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Dec 12 23:59:59 2026 GMT
  hsts: null
- host: www.remax.eu
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 15 04:19:21 2026 GMT
  hsts: false
- host: apidocs.datahub.remax.eu
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug 30 03:54:38 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: listingsapi-test.datahub.remax.eu
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 11 22:50:38 2026 GMT
  hsts: true
  hsts_max_age: 31536000
  hsts_include_subdomains: true
  hsts_preload: true
  note: Postman-hosted documentation; the strongest transport posture in the estate
- host: api.datahub.remax.eu
  https: true
  tls_version: TLSv1.2
  cert_expires: Oct 12 23:59:59 2026 GMT
  hsts: false
  note: the production Datahub API host negotiates TLS 1.2 and sets no HSTS
- host: oauth.datahub.remax.eu
  https: true
  tls_version: TLSv1.2
  cert_expires: Oct 12 23:59:59 2026 GMT
  hsts: false
  note: >-
    the OAuth authorization server negotiates TLS 1.2 and sets no HSTS, while
    also carrying tokens in query strings
- host: datahub.remax.eu
  https: true
  tls_version: TLSv1.2
  cert_expires: Oct  2 23:59:59 2026 GMT
  hsts: false
- host: listing-api-remaxeu.bwscloud.tech
  https: true
  tls_version: TLSv1.2
  cert_expires: Nov 19 23:59:59 2026 GMT
  hsts: false
  note: staging Listings API on a third-party vendor domain, outside RE/MAX DNS control
domains:
- domain: remax.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
- domain: remax.eu
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: quarantine
observations:
- >-
  No CAA records on either registrable domain, so any public CA may issue for
  remax.com or remax.eu.
- >-
  No DNSSEC on either domain.
- >-
  DMARC is enforced only at p=quarantine, not p=reject, on both domains.
- >-
  remax.com serves a DNS wildcard (CNAME customers.kvcore.com). The control probe
  zzzznotreal.remax.com resolves identically to developer.remax.com,
  developers.remax.com, docs.remax.com, status.remax.com and trust.remax.com -
  none of those hostnames is a service RE/MAX runs. A wildcard that answers on
  443 for every conceivable subdomain is itself a security-relevant posture
  (subdomain-confusion and phishing surface).
- >-
  api.remax.com is a dangling CNAME to api.remax-prod.booj.io, which returns
  NXDOMAIN - a classic subdomain-takeover shape left behind by the decommissioned
  booj platform.
- >-
  The API and OAuth hosts negotiate TLS 1.2 and set no HSTS, while the two
  Postman documentation hosts (which carry no data) are TLS 1.3 with HSTS
  preload. The transport hardening is inverted relative to where the risk is.
programs:
  security_txt: absent on every host probed
  vulnerability_disclosure: none published
  trust_center: >-
    none. trust.remax.com answers 403 only because of the remax.com wildcard; it
    is not a trust center.
  probe: 0-working/probe-security-programs.py returned vdp=none trust=none (2026-07-26)

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/re-max-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.