Red Energy · Domain Security

Red Energy Domain Security

Domain security

Domain security posture for Red Energy, probed live across 3 host(s) and 2 registrable domain(s). 3 host(s) serve HTTPS (up to TLSv1.3); 1 advertise HSTS. Email/DNS controls: DNSSEC present, SPF present, DMARC present (p=reject).

EnergyAustraliaUtilitiesElectricityGasEnergy RetailConsumer Data RightCDRProduct Reference DataSmart MeteringOpen Data

Transport & Host Security

www.redenergy.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 12 03:45:46 2026 GMT
cdr.energymadeeasy.gov.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Jan 31 23:59:59 2027 GMT
public.cdr.redenergy.com.au
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 18 23:59:59 2026 GMT

Domain (DNS/Email) Security

redenergy.com.au
DNSSEC: yes · SPF: yes · DMARC: yes (p=reject) · CAA: none
energymadeeasy.gov.au
DNSSEC: no · SPF: yes · DMARC: yes (p=quarantine) · CAA: yes

Source

Domain Security

Raw ↑
generated: '2026-07-27'
method: probed
source: >-
  Live DNS/TLS/HTTP probes of the apis.yml and OpenAPI servers[] hosts, run by
  0-working/probe-domain-security.py, then corrected by hand for HSTS: the
  script's HEAD-based check returned null on all three hosts, but a GET against
  a path each host actually serves showed public.cdr.redenergy.com.au does send
  Strict-Transport-Security. Corrections are marked.
hosts:
- host: www.redenergy.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 12 03:45:46 2026 GMT
  hsts: null
  hsts_note: >-
    Undetermined. Every request returns HTTP 403 with a Cloudflare bot challenge,
    so no response from the origin was observed. Absence of the header on the
    challenge page is not evidence about the site.
  http_status: 403
- host: cdr.energymadeeasy.gov.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Jan 31 23:59:59 2027 GMT
  hsts: false
  hsts_note: >-
    Confirmed absent. GET /red-energy/cds-au/v1/energy/plans returned HTTP 200
    with no strict-transport-security header. Fronted by Amazon CloudFront and
    API Gateway.
  http_status: 200
  security_headers:
    access-control-allow-origin: '*'
    access-control-expose-headers: x-v, Retry-After, x-fapi-interaction-id
- host: public.cdr.redenergy.com.au
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 18 23:59:59 2026 GMT
  hsts: true
  hsts_max_age: 63072000
  hsts_include_subdomains: true
  hsts_corrected: true
  hsts_note: >-
    Corrected from the script's null. GET /cds-au/v1/discovery/status returned
    strict-transport-security "max-age=63072000; includeSubDomains;" on
    2026-07-27. The script probed the host root, which returns an nginx 404 with
    no security headers.
  http_status: 200
  security_headers:
    strict-transport-security: max-age=63072000; includeSubDomains;
    x-content-type-options: nosniff
    x-frame-options: DENY
    access-control-allow-origin: '*'
    access-control-allow-headers: Range,x-v,x-min-v
    access-control-expose-headers: Content-Length,x-v,x-min-v
domains:
- domain: redenergy.com.au
  dnssec: true
  caa: []
  caa_note: No CAA record published — any public CA may issue for this domain.
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: energymadeeasy.gov.au
  dnssec: false
  caa:
  - 0 issuewild "amazontrust.com"
  - 0 issuewild "awstrust.com"
  - 0 issuewild "amazon.com"
  - 0 issuewild "amazonaws.com"
  spf: true
  dmarc: true
  dmarc_policy: quarantine
  note: Australian Energy Regulator host, not a Red Energy domain.
findings:
  strong:
    - DNSSEC signed on redenergy.com.au.
    - DMARC at p=reject on redenergy.com.au — the strictest policy.
    - TLS 1.3 on all three hosts.
    - Two-year HSTS with includeSubDomains on the CDR public base URI.
  gaps:
    - No CAA record on redenergy.com.au.
    - No security.txt on any host (see well-known/red-energy-well-known.yml).
    - No vulnerability disclosure programme or trust centre found.

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/red-energy-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no email required.

A second provider on the same verified email joins the account you already have.