Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BTLS Certificate Expiry & Recommendations317 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records3 A records, 38 ms lookupPASS
| A | 54.163.203.83, 44.193.165.2, 44.206.204.180 |
| AAAA | 2600:1f18:2148:bc02:6c3c:658f:8bcf:4bf7, 2600:1f18:2148:bc00:bb41:6176:22ce:6757, 2600:1f18:2148:bc01:b693:b462:3ebf:eff0 |
| CNAME | — |
| NS | ns-513.awsdns-00.net, ns-421.awsdns-52.com, ns-1827.awsdns-36.co.uk, ns-1168.awsdns-18.org |
| MX | 10 aspmx.l.google.com 20 alt1.aspmx.l.google.com 30 aspmx5.googlemail.com 30 aspmx2.googlemail.com 30 aspmx3.googlemail.com 30 aspmx4.googlemail.com |
| TXT | 994564986-4236403 detectify-verification=87a64c3bf3301354588d90672bd1b74e google-site-verification=v2_0BdJWKUR2kM7Ysv_QB9LhCqd2Xn6QCZiInuaRwFc google-site-verification=cusX3h3wUlq3D6vk24INmIXpuJdQ46-uKjIAM9Of8Lo SPF v=spf1 include:mailgun.org -all |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 317 ms totalPASS
https://docker.io
293 ms · HTTP/1.1
https://www.docker.com/
24 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://docker.io | 302 | 293 ms | HTTP/1.1 | |
| 2 | https://www.docker.com/ | 200 | 24 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
If permanent, use 301 instead.
302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.
Learn more ▾ ▴
Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).
Source: Google Search Central
A+IPv6 ReadinessIPv6 reachable (98 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 15 URLsPASS
User-agent: *
Allow: /wp-admin/admin-ajax.php
Disallow: /wp-admin/
Disallow: /pricing/contact-sales/bss-cc-thankyou/
Disallow: /pricing/contact-sales/bss-thankyou/
Disallow: /company/contact-thank-you/
Disallow: /thank-you-subscribing-docker-weekly/
Disallow: /pricing/contact-sales2/
Disallow: /cdn-cgi/
Disallow: /static/
Disallow: /c/
Disallow: /p/
Disallow: /products/telepresence-for-docker/thank-you/
Disallow: /style-guide/
Disallow: /search/
Allow: /ja-jp/wp-admin/admin-ajax.php
Disallow: /ja-jp/wp-admin/
Disallow: /ja-jp/pricing/contact-sales/bss-cc-thankyou/
Disallow: /ja-jp/pricing/contact-sales/bss-thankyou/
Disallow: /ja-jp/company/contact-thank-you/
Disallow: /ja-jp/thank-you-subscribing-docker-weekly/
Disallow: /ja-jp/pricing/contact-sales2/
Disallow: /ja-jp/cdn-cgi/
Disallow: /ja-jp/static/
Disallow: /ja-jp/c/
Disallow: /ja-jp/products/telepresence-for-docker/thank-you/
Disallow: /ja-jp/style-guide/
Sitemap: https://www.docker.com/sitemap_index.xml
Sitemap: https://www.docker.com/ja-jp/sitemap_index.xml
- https://www.docker.com/post-sitemap1.xml
- https://www.docker.com/post-sitemap2.xml
- https://www.docker.com/post-sitemap3.xml
- https://www.docker.com/post-sitemap4.xml
- https://www.docker.com/post-sitemap5.xml
- https://www.docker.com/page-sitemap.xml
- https://www.docker.com/contributor-sitem...
- https://www.docker.com/contributor-sitem...
- https://www.docker.com/contributor-sitem...
- https://www.docker.com/news-sitemap.xml
- https://www.docker.com/customer-sitemap....
- https://www.docker.com/event-sitemap.xml
- https://www.docker.com/newsletter-sitema...
- https://www.docker.com/video-sitemap.xml
- https://www.docker.com/local-sitemap.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencedocker.io — via Gandi SAS, 13 years, 6 months oldPASS
185 days
December 17, 2026
317 days
Issued by Amazon
13 years, 6 months
Registered December 17, 2012
Status unknown
Protects against DNS spoofing
Unknown
2600:1f18:2148:bc02:6c3c:658f:8bcf:4bf7
Gandi SAS
Expiry timeline
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.
Source: ICANN / domain-security best practice