ShopBack · Domain Security

Shopback Domain Security

Domain security

Domain security posture for ShopBack, probed live across 3 host(s) and 2 registrable domain(s). 3 host(s) serve HTTPS (up to TLSv1.3); 2 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

CompanyPaymentsCashbackRewardsLoyaltyE-CommerceBuy Now Pay LaterPoint Of SaleCheckoutSingapore

Transport & Host Security

www.shopback.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 4 06:58:02 2026 GMT
docs.shopback.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Sep 25 20:52:34 2026 GMT
prod-merchant-service.hoolah.co
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Oct 26 07:54:49 2026 GMT

Domain (DNS/Email) Security

shopback.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none
hoolah.co
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-08-02'
method: probed
source: live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts
hosts:
- host: www.shopback.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct  4 06:58:02 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: docs.shopback.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Sep 25 20:52:34 2026 GMT
  hsts: true
  hsts_max_age: 31536000
- host: prod-merchant-service.hoolah.co
  https: true
  tls_version: TLSv1.3
  cert_expires: Oct 26 07:54:49 2026 GMT
  hsts: null
domains:
- domain: shopback.com
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: reject
- domain: hoolah.co
  dnssec: false
  caa: []
  spf: true
  dmarc: true
  dmarc_policy: none