Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FIPv6 ReadinessActionIPv6 records exist but unreachableFIX
Having AAAA records but an unreachable server is worse than no AAAA — clients may experience delays before falling back to IPv4.
Advertising IPv6 (AAAA records) without a reachable server means IPv6-preferring clients silently fail every connection.
Learn more ▾ ▴
Modern browsers prefer IPv6 if AAAA exists (Happy Eyeballs algorithm). If the IPv6 server isn't reachable, browsers fall back to IPv4 — but with seconds of added latency per request. Either fix IPv6 reachability or remove the AAAA records.
Source: RFC 8305 (Happy Eyeballs)
BTLS Certificate Expiry & Recommendations65 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records2 A records, 8 ms lookupPASS
| A | 104.17.5.3, 104.17.6.3 |
| AAAA | 2606:4700::6811:503, 2606:4700::6811:603 |
| CNAME | — |
| NS | — |
| MX | — |
| TXT | — |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.
Learn more ▾ ▴
SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.
Source: RFC 7208 (SPF)
A+Redirect ChainNo redirects — direct accessPASS
https://www.backblaze.com
120 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://www.backblaze.com | 200 | 120 ms | HTTP/1.1 | cloudflare |
A+Crawlabilityrobots.txt present, sitemap with 3677 URLsPASS
# robots.txt for https://www.backblaze.com/
User-agent: *
Disallow: /api/install_backblaze
Disallow: /win32/
Disallow: /mac/
Disallow: /linux/
Disallow: /gift/
Disallow: /gift_download/
Disallow: /gen/
Disallow: /fix_billing_problem.htm
Disallow: /partials/
Disallow: /feed/
Disallow: /?
Sitemap: https://www.backblaze.com/sitemap.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: www
HTTP → HTTPS
Consistent
A+Domain Intelligencebackblaze.com — via Cloudflare, Inc., 19 years, 3 months old, hosted on CloudflarePASS
291 days
April 2, 2027
65 days
Issued by Google Trust Services
19 years, 3 months
Registered April 2, 2007
Enabled
Protects against DNS spoofing
Cloudflare
ASN AS13335
104.17.5.3
Cloudflare, Inc.