Tigera Domain Security
TLS/HSTS posture per host and DNS security records per registrable domain. Both public domains (tigera.io, calicocloud.io) publish SPF and a DMARC policy of p=reject; neither publishes DS records, so DNSSEC is not signed. tigera.io publishes no CAA record; calicocloud.io does, restricting issuance to Google Trust Services, DigiCert and Let's Encrypt. Every reachable host negotiates TLS 1.3 with HSTS at one year or more, and status.calicocloud.io is preload-eligible.
Domain security posture for Tigera, probed live across 5 host(s) and 2 registrable domain(s). 4 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).
Transport & Host Security
Domain (DNS/Email) Security
Source
Domain Security
Work with this as data
Every security artifact here is available over the APIs.io API and to AI agents over MCP.