SoFi Technologies · Domain Security

Sofi Technologies Domain Security

Domain security

Domain security posture for SoFi Technologies, probed live across 7 host(s) and 2 registrable domain(s). 6 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

FintechPaymentsBankingCard IssuingBanking as a ServicePersonal FinanceLendingACHISO 20022DisputesIdentity VerificationWebhook

Transport & Host Security

www.sofi.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: no · cert expires: Dec 8 23:40:23 2026 GMT
tech.sofi.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 8 22:20:35 2026 GMT
docs.tech.sofi.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 13 00:06:15 2026 GMT
api.sofi.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Dec 8 23:40:23 2026 GMT
sandbox.gpsrv.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Oct 18 02:13:14 2026 GMT
sandbox-api.gpsrv.com
HTTPS: yes · HSTS: no
developer.sofi.com
HTTPS: no · HSTS: no

Domain (DNS/Email) Security

sofi.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: yes
gpsrv.com
DNSSEC: no · SPF: yes · DMARC: yes (p=none) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-09-06'
method: probed
source: >-
  live DNS/TLS/HTTP probes of the hosts this record names, run by
  0-working/probe-domain-security.py and then hand-corrected to drop two rows the script derived
  from placeholder server values - see excluded below.
hosts:
  - host: www.sofi.com
    https: true
    tls_version: TLSv1.3
    cert_expires: Dec  8 23:40:23 2026 GMT
    hsts: null
    note: >-
      Answers 403 to any non-browser client (Cloudflare bot challenge) while serving a real 317 KB
      page. Live, not dead.
  - host: tech.sofi.com
    https: true
    tls_version: TLSv1.3
    cert_expires: Oct  8 22:20:35 2026 GMT
    hsts: true
    hsts_max_age: 31536000
    hsts_include_subdomains: true
  - host: docs.tech.sofi.com
    https: true
    tls_version: TLSv1.3
    cert_expires: Oct 13 00:06:15 2026 GMT
    hsts: true
    hsts_max_age: 31536000
  - host: api.sofi.com
    https: true
    tls_version: TLSv1.3
    cert_expires: Dec  8 23:40:23 2026 GMT
    hsts: true
    hsts_max_age: 31536000
    hsts_include_subdomains: true
    note: Live nginx behind Cloudflare; every probed path returns 404. No public contract here.
  - host: sandbox.gpsrv.com
    https: true
    tls_version: TLSv1.3
    cert_expires: Oct 18 02:13:14 2026 GMT
    hsts: true
    hsts_max_age: 63072000
    hsts_include_subdomains: true
    note: The Sandbox dashboard where clients read their Sandbox API connection details.
  - host: sandbox-api.gpsrv.com
    https: unknown
    note: >-
      TCP connect times out from an arbitrary source. The Sandbox API host is IP-allowlisted, which
      is consistent with credentials being bound to a registered requesting IP.
  - host: developer.sofi.com
    https: false
    note: >-
      NXDOMAIN. This host was the humanURL on this record before 2026-09-06 and never existed; the
      pointer has been removed.
domains:
  - domain: sofi.com
    dnssec: false
    caa:
      - 0 issue "pki.goog"
      - 0 issue "amazon.com"
      - 0 issuewild "amazon.com"
      - 0 issuewild "globalsign.com"
      - 0 issuewild "godaddy.com"
      - 0 issuewild "pki.goog"
    spf: true
    dmarc: true
    dmarc_policy: reject
  - domain: gpsrv.com
    dnssec: false
    caa: []
    spf: true
    dmarc: true
    dmarc_policy: none
    note: >-
      The legacy Galileo processing domain that still hosts every API server template. DMARC is
      p=none - monitor only, no enforcement - on the domain that carries the platform's entire
      callable surface, while sofi.com itself is at p=reject. Mail is behind Proofpoint.
excluded:
  - value: client.domain.com
    reason: >-
      Not a SoFi host. It is the placeholder server in the Events API and External Trans API
      contracts, where the CLIENT hosts the endpoint. The automated probe treated it as a real
      host and would have recorded a third party's SPF and DMARC posture as SoFi's.
  - value: example.client.domain.com
    reason: Same - the Auth API's client-hosted placeholder server.
maintainers:
  - FN: Kin Lane
    email: kin@apievangelist.com

Work with this as data

Every security artifact here is available over the APIs.io API and to AI agents over MCP.

MCP server

One button, every client — Claude, Cursor, VS Code and the rest.

https://apis.io/mcp

Tools for security posture

4 MCP tools reach this
  • find_securityBrowse and filter every security artifact in the catalog.
  • apis_io_searchSTART HERE — APIs, providers and tags for one query, each with its total.
  • resolveTurn a domain, URL or GitHub org into the provider it belongs to.
  • find_cohortsEvery scored population of providers in the catalog.
All 92 tools →

Call it yourself

curl for this page
This security artifact
curl "https://apis.io/api/v1/security/sofi-technologies-domain-security"
All security posture
curl "https://apis.io/api/v1/security?limit=25"

Discovery needs no key. Ratings and market analysis are Pro.

Get an API key

Free tier, no form to fill in. Signing in shares your email address with us — we store it to create your key and to recognise you if you sign in with another provider. See our Privacy Policy and Terms.

A second provider on the same verified email joins the account you already have.