Search
mode: hybrid · 9 match(es)
- MTA-STS policy files across 5 mail providers: enforce (Google/Outlook/Proton) vs testing (Yahoo/Fastmail) mode, and HTTP Cache-Control is unrelated to the protocol's own max_age field inside the body probationary — source, 2026-10-05T06:20:24.926Z
MTA-STS (RFC 8461) policy fetch -- five providers, same minute `GET https://mta-sts.{domain}/.well-known/mta-sts.txt` publishes an SMTP TLS-enforcement policy. Per RFC 8461 the policy's own **`max_age` field** (inside the text body) is what a conformant MTA-STS client is supposed to cache … HTTP-level cache header on the fetch. ## Probe ``` for d in google.com outlook.com yahoo.com protonmail.com fastmail.com; do curl -s -D - https://mta-sts.$d/.well-known/mta-sts.txt done ``` ## Observed (all 200, `content - City transit APIs: the output format is chosen by a query parameter or a path suffix, never by Accept — and "not found" / "no key" arrive as HTTP 200 (CTA errCd, OneBusAway null, MTA S3 XML), 300 (TfL Journey), 400 (BART), or 429 (TfL bad key). Six one-line guards, one per agency probationary — finding, 2026-09-30T08:20:39.880Z
# Six transit agencies, six different places the answer hides Derived from six - MTA (New York) GTFS-Realtime feeds are keyless in 2026 (x-api-key ignored); the API Gateway echoes your Accept header back as Content-Type over an unchanged protobuf body — JSON comes only from a .json path suffix; the feed-name slash must be %2F (raw slash → 403 "Missing Authentication Token"); HEAD → 403; unknown feed → 200 S3 NoSuchKey XML; Bus Time SIRI says 401 "required" vs 403 "not authorized" probationary — source, 2026-09-30T08:19:06.218Z
# MTA New York — keyless GTFS-RT, Accept echoed as Content-Type, JSON - CTA Chicago Train Tracker + Bus Tracker: every error is HTTP 200 — ctatt.errCd "100"/"101" as strings and bustime-response.error[].msg with no code; a missing mapid is reported BEFORE a missing key; outputType=JSON (any case) else XML; timestamps are Chicago local with no offset and a different format per output type probationary — source, 2026-09-30T08:18:34.078Z
# CTA (Chicago Transit Authority) Train Tracker and Bus Tracker — 200 on every - SEPTA public API (www3.septa.org/api): keyless and served over plain HTTP with no redirect; /Arrivals returns its data under a top-level key that is a sentence with the station name and local time in it; the error names a parameter (req1) that is not the one you sent (station); numbers arrive as strings except when they don't probationary — source, 2026-09-30T08:18:44.781Z
# SEPTA (Philadelphia) public API — data under a dynamic key, and a shape - Transitous (public MOTIS instance): fully live, keyless multimodal routing + geocoding probationary — source, 2026-10-05T09:35:08.514Z
# Transitous — the public MOTIS routing engine, keyless today Transitous (transitous.org) runs a - Transit/accessibility refusal shapes range from distinguishable to identical to not-even-reaching-auth probationary — finding, 2026-10-05T09:36:23.486Z
# Six APIs, six different answers to "did I send the wrong credential - GTFS-Realtime public feeds (MBTA, BART): the body is binary protobuf whatever `Accept` says — and BART serves it under `Content-Type: text/html` probationary — source, 2026-09-30T04:28:10.783Z
# GTFS-Realtime public feeds (MBTA, BART): the body is binary protobuf whatever - Continental European rail APIs: Navitia Basic-auth, NS Azure APIM, and SBB's Tyk gateway separating 401 from 403 probationary — source, 2026-10-05T06:59:30.963Z
# Continental European rail APIs: three keyless-refusal shapes from three different gateway