Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations83 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records1 A records, 1255 ms lookupPASS
| A | 37.16.20.230 |
| AAAA | 2a09:8280:1::42:42ec:0 |
| CNAME | — |
| NS | ns.zocalo.net, adns2.ucsc.edu, adns1.ucsc.edu |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt3.aspmx.l.google.com 10 alt4.aspmx.l.google.com |
| TXT | sending_domain1048611=42e1dff1f7750da727e684cc0fff85782d9236257a3e7e03409e658b8c... SPF v=spf1 include:_spf.mlsend.com include:_spf.google.com ip4:66.85.64.0/23 ip4:66... dtm-domain-verification=rC0pX3ESCPq-6oxgeeXR7bZxSbwXhtsGMOPkdyM2hCE google-site-verification=b3tRHeWaOAfxcEB0rCMXu_kfVSZB5O1sAJUXwQMlXY8 jamf-site-verification=Jl1UW-gVKdRe1z4RQepaSQ google-site-verification=YqGdNoAzlHV5CA2ymYS-eRmxx0p2inj3w_ZHzxYKcR4 google-site-verification=9ihceAEfByq2aXDNn377UMW-tKjSuBwvmeEElF0Nagc google-site-verification=MAYcPln8bHyLVcZSoij9rWOtqe6TA0zWvPLwr5x-lBg google-site-verification=hTFQkUsHT0UnNiY0UlB9FE640Fw61mIcQTzjhHwvMvw google-site-verification=qjSZFDGXMoROf_06GrfaDCGOxKhGwIZWPy1JyvuFPQg MS=BBDA09048FF123AA4DE4F66003797504E47CD473 9O98HIXRENZDBS4B49HG3EGSGUMD1SB71E1OLS1WG docusign=92d2ff42-85b4-49d3-a7d4-ff6206c6b7da atlassian-domain-verification=LT04D8PQ6rZDOYwwtkO66srjecUfj6tf1GAHT3MwwC9wt9hRhz... amazonses:OLdo8B8RSoAxJeaMNhByxa+OHC80Gzqzze41wXllhgE= apple-domain-verification=XO9icURQtTK4967R 2o4e1vfscfmdnoc50n5n46n340 virtru-site-verify=PbFPJQrlhOQuDphjnRmvQBT7NLpufe9o8IIjwsUb google-site-verification=YKp9SeXigjb7PuNbHQlI53u7up6azjlipnWnMcQDl8A atlassian-domain-verification=o4jKqspwzy6t1dhudUEPmQkJQXHUCdA4N1FBCLN2EU345AFSuN... brevo-code:22a68b537c51751441d18a254169d3ff atlassian-sending-domain-verification=3e2c66df-563a-4582-96d2-4644733430b9 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
ARedirect Chain1 redirect(s), 627 ms totalPASS
https://ucsc.edu
402 ms · HTTP/1.1
https://www.ucsc.edu
225 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://ucsc.edu | 301 | 402 ms | HTTP/1.1 | Fly/6db5e6d7a8 (2026-04-20) |
| 2 | https://www.ucsc.edu | 200 | 225 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 6 URLsPASS
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Sitemap: https://www.ucsc.edu/wp-sitemap.xml
A+Domain Intelligenceucsc.edu — 39 years, 9 months oldPASS
410 days
July 31, 2027
83 days
Issued by Let's Encrypt
39 years, 9 months
Registered January 29, 1987
Status unknown
Protects against DNS spoofing
Unknown
2a09:8280:1::42:42ec:0
Registrar unknown