Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSFIX
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
HTTP version does not redirect to HTTPS
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BRedirect Chain2 redirect(s), 343 ms totalREVIEW
https://kcl.ac.uk
86 ms · HTTP/1.1
http://www.kcl.ac.uk/
151 ms · HTTP/1.1
https://www.kcl.ac.uk/
106 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://kcl.ac.uk | 301 | 86 ms | HTTP/1.1 | Apache |
| 2 | http://www.kcl.ac.uk/ | 301 | 151 ms | HTTP/1.1 | |
| 3 | https://www.kcl.ac.uk/ | 200 | 106 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
Each redirect adds latency. Try to minimize the chain to 1 hop.
Redirect chain — each hop adds latency; combine into one redirect where possible.
Source: Google Search Central / web.dev
Redirect directly from https://kcl.ac.uk to https://www.kcl.ac.uk/
Redirect chain could be flattened to one hop — server config tweak removes intermediate latency.
Source: web.dev
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations77 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 114 ms lookupPASS
| A | 137.73.130.135 |
| AAAA | — |
| CNAME | — |
| NS | ns3.ja.net, ndc-cns-ext-01.kcl.ac.uk, sdc-cns-ext-01.kcl.ac.uk |
| MX | 10 kcl-ac-uk.mail.protection.outlook.com |
| TXT | atlassian-domain-verification=tEMVhRUAW5I5TcB2MpxJK5NqpGlZaxXhjcgeCkI38iF2uqYMTR... lhar5275808q50u0rgoi2hv2th access-domain-verification=b4f117add86134c15bc6af45c586d52c1dc3fbef295a24c44df1e... d365mktkey=3m45obrzfsf55yx7bodvq2e4y d365mktkey=U40wPivVnKD2mdPsfcyp3KL4uHFzMDqE9IGPGCUPsVsx QuoVadis=464926dd-3346-40d0-9c07-d83b020145a2 f5prjl21ovt00uh84dq5fif5sv d365mktkey=1eyk3mas6821z0hk0klgty9e1 google-site-verification=unigyXqSZPjlPT6WqAjMbQxLN2y7R2rRpdyIx1ADm7o openai-domain-verification=dv-GBaYyXh1c726aQ6IVBEIDhmC mentimeter-ca093c67-df6a-4f4c-932c-39986086ae09 SPF v=spf1 include:spf1.kcl.ac.uk include:spf2.kcl.ac.uk include:spf3.kcl.ac.uk incl... d365mktkey=graYmRAY1uhzEtBesJ2kRr4oTE7pwLb8MCrYJ3YAnt4x d365mktkey=qaOemMFxXpKH0bv5cCmrcyoffiFQndAOyAxBxVT5PZcx mistral-domain-verification=093f85f4e68804c5deb819f7e40acf81695da60c v=msv1t=930e30397d884fbc545b35c8c2fcc1 amazonses:kC7acEJaQ3xz8xKZ3nihcIuYwq6gqpVYx3P40/k03xM= AppID=00000000400C027C d365mktkey=30fzj5wnfwh30u4b1sheedari docusign=2d1e7df6-f14e-46be-88cb-4d3fb3b05abd i9b7v1h1kapv6ej5qbf63bllt3 bda19b01-941d-4022-a8a3-914b7ee33d3d cfq8ik3p7puuh50hj6t7dgiama |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 3629 URLsPASS
User-agent: *
Disallow: *?ContensisTextOnly=true*
Disallow: /search/ # Stop Google indexing our search
Disallow: /business/people/*-*
Disallow: /monitoring/
Disallow: /home
Disallow: /it/owa.aspx
Disallow: /onlinecourses/
Disallow: /health/research/specialistcentres/cib/people/bbsrcfellows/flatterssarah*
Disallow: /archive/events/*
Disallow: /online/postgraduate-loans*
Disallow: /form-containers*
Disallow: /study-at-kings/sitemap
Disallow: /study/modules*
Disallow: /study-at-kings/
Disallow: /study-at-kings/landing/your-step-by-step-guide-to-kings
# Disallow: /offer-holders/
Disallow: /archive/news/kings/newsrecords/2011/11november/indiainstituteavanthachair
Disallow: /*ContensisTextOnly=*
Disallow: /*search_keywords=*
Disallow: /study/undergraduate/events/on-demand/watch
Disallow: /study/postgraduate-taught/events/on-demand/watch
Disallow: /sport-and-wellness/
# IN01723209 - hide the thank you pages
Disallow: /study/postgraduate-taught/prospectus-thankyou
Disallow: /study/undergraduate/prospectus-thankyou
#Disallow: /offer-holders
Disallow: *page=*
Disallow: *categories=*
Disallow: *s=*
Disallow: *cat=*
Disallow: *term=*
Disallow: *researchCategories=*
Disallow: *utm_*
Disallow: *fbclid=*
Disallow: *platform=*
Disallow: *letter=*
Disallow: *unibuddy=*
Disallow: *alp_source=*
Disallow: *keyword=*
Disallow: *pageIndex=*
Disallow: *li_fat_id=*
Disallow: /campuslife/acservices/accessibilitytestcompleted.aspx
Disallow: /accessibilitytest
Disallow: /research/accessibility-test-for-compliance-with-wcag-2.2-aa-standards
Disallow: /events/test-accessibility-for-compliance-with-wcag-2.2-standards
Disallow: /study/accessibility-test-for-wcag-2.2-aa-compliance-standards
Disallow: /jobs/role/accessibility-test-for-wcag-2.2-standards-compliance
Disallow: /international-foundation/programme/international-foundation-brochure
#Disallow: /study/postgraduate-taught/offer-holders
#Disallow: /study/undergraduate/offer-holders
Disallow: /test
Disallow: *ref=*
Disallow: *alp_oi=*
Disallow: *trk=*
Disallow: *adobe_mc=*
Disallow: *elqTrackid=*
Disallow: *ftag=*
Disallow: *source=*
Disallow: *FORM=*
Disallow: *mc_cid=*
Disallow: *msdynttrid=*
Disallow: *source=*
Disallow: *HootPostID=*
Disallow: *Socialprofile=*
Disallow: *Socialnetwork=*
Disallow: *app_v2=*
Disallow: *location=*
Disallow: *locator=*
Disallow: *go=*
Disallow: *%2525*
Sitemap: https://www.kcl.ac.uk/sitemap.xml
Sitemap: https://www.kcl.ac.uk/sitemap1.xml
Sitemap: https://www.kcl.ac.uk/sitemap2.xml
Sitemap: https://www.kcl.ac.uk/sitemap3.xml
Sitemap: https://www.kcl.ac.uk/sitemap4.xml
Sitemap: https://www.kcl.ac.uk/sitemap5.xml
Sitemap: https://www.kcl.ac.uk/sitemap6.xml
Sitemap: https://www.kcl.ac.uk/sitemap7.xml
Sitemap: https://www.kcl.ac.uk/sitemap8.xml
Sitemap: https://www.kcl.ac.uk/sitemap9.xml
User-agent: SiteimproveBot-Crawler
Allow: /
# User-agent: Baiduspider
# Disallow: /
User-agent: FAST-WebCrawler/0.2
Disallow: /
User-agent: Yanga WorldSearch Bot v1.1/beta
Disallow: /
User-agent: slurp
Disallow: /wrap/pmwiki/
User-agent: Twiceler-0.9
Disallow: /
A+Domain Intelligencekcl.ac.uk — via No registrar listed. This domain is directly registered with Nominet., hosted on JANET Jisc Services Limited, GBPASS
Unknown
77 days
Issued by Sectigo Limited
Unknown
Status unknown
Protects against DNS spoofing
JANET Jisc Services Limited, GB
ASN AS786
137.73.130.135
No registrar listed. This domain is directly registered with Nominet.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice