I recall that subdomains are their own record inside a DNS, which would imply that anyone can claim that their server is a non-existent subdomain of the real domain

    • ich_iel@feddit.org
      link
      fedilink
      arrow-up
      1
      ·
      3 hours ago

      Checks own servers

      Strict-Transport-Security: max-age=63072000; includeSubDomains; preload

      Yeah, I’d like to see that…