Twitter/X · Domain Security

Twitter X Domain Security

Domain security

Domain security posture for Twitter/X, probed live across 4 host(s) and 1 registrable domain(s). 4 host(s) serve HTTPS (up to TLSv1.3); 4 advertise HSTS. Email/DNS controls: DNSSEC absent, SPF present, DMARC present (p=reject).

CompanySocialSocial MediaPostsReal-TimeStreamingNewsDeveloper Platform

Transport & Host Security

x.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Aug 26 06:29:58 2026 GMT
api.x.com
HTTPS: yes · TLS: TLSv1.3 · HSTS: yes · cert expires: Aug 26 06:29:58 2026 GMT
docs.x.com
HTTPS: yes · HSTS: yes
developer.x.com
HTTPS: yes · HSTS: yes

Domain (DNS/Email) Security

x.com
DNSSEC: no · SPF: yes · DMARC: yes (p=reject) · CAA: none

Source

Domain Security

Raw ↑
generated: '2026-07-21'
method: probed
source: >-
  live DNS/TLS/HTTP probes of apis.yml + OpenAPI hosts, run manually on
  2026-07-21 (probe-domain-security.py structurally excludes x.com/twitter.com
  hosts via its social-domain filter, so the identical probes were executed by
  hand: curl -I for HTTPS/HSTS, openssl s_client for TLS version and cert
  expiry, dig for DNSKEY/DS/CAA/TXT/_dmarc).
hosts:
- host: x.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug 26 06:29:58 2026 GMT
  hsts: true
  hsts_max_age: 631138519
  hsts_include_subdomains: true
- host: api.x.com
  https: true
  tls_version: TLSv1.3
  cert_expires: Aug 26 06:29:58 2026 GMT
  hsts: true
  hsts_max_age: 631138519
  hsts_include_subdomains: true
- host: docs.x.com
  https: true
  hsts: true
  hsts_max_age: 63072000
- host: developer.x.com
  https: true
  hsts: true
  hsts_max_age: 631138519
  hsts_include_subdomains: true
domains:
- domain: x.com
  dnssec: false
  caa: []
  spf: true
  spf_policy: '-all (hard fail); Google, Salesforce, Oracle email delivery included'
  dmarc: true
  dmarc_policy: reject