Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations73 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 48 ms lookupPASS
| A | 104.20.23.243, 172.66.149.158 |
| AAAA | 2606:4700:10::6814:17f3, 2606:4700:10::ac42:959e |
| CNAME | — |
| NS | tony.ns.cloudflare.com, april.ns.cloudflare.com |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt4.aspmx.l.google.com 10 alt3.aspmx.l.google.com |
| TXT | SPF v=spf1 include:_spf.google.com include:aspmx.pardot.com include:mail.zendesk.com... pardot800983=c44249c9f5da1bfbf33a10a397235d219b4be95e98457f7d4652d3bf374e9784 0ed1fe018af8dc85cf7c7248b38c5d99c7c16a8d3f cursor-domain-verification-zk8d33=e13JxdZX9VUWNfxzdRhTPWP5x apple-domain-verification=Eb1jiiZT9U7Gbcrq openai-domain-verification=dv-BPbxA2vBQDwvlQ6F0XMR8ABA security_policy=https://www.raspberrypi.org/contact/security/ docusign=d8ff0ddb-5029-434e-a283-e1988b187710 google-site-verification=KmsnTP6T5_z55dGozUBNTaSoLzJTRbOedayCBLN7CPA facebook-domain-verification=wqki2a0ywwv9og53cciqrgjbmacrqs onetrust-domain-verification=42e0b0ebebca4b958dc4bd5308713ee9 uber-domain-verification=5c327d91-2402-4dee-b998-9f79e37efa9a security_contact=mailto:security@raspberrypi.org security_contact=https://keybase.io/rpfwebteam |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 292 ms totalPASS
https://raspberrypi.org
110 ms · HTTP/1.1
https://www.raspberrypi.org/
183 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://raspberrypi.org | 301 | 110 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.raspberrypi.org/ | 200 | 183 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 11 URLsPASS
User-agent: *
Disallow: /forms/*
Disallow: /esi/*
Disallow: /wp/wp-admin/
Allow: /wp/wp-admin/admin-ajax.php
Sitemap: https://www.raspberrypi.org/sitemap_index.xml
- https://www.raspberrypi.org/post-sitemap...
- https://www.raspberrypi.org/page-sitemap...
- https://www.raspberrypi.org/at-home-site...
- https://www.raspberrypi.org/resource-sit...
- https://www.raspberrypi.org/piweekly-sit...
- https://www.raspberrypi.org/product-site...
- https://www.raspberrypi.org/category-sit...
- https://www.raspberrypi.org/post_tag-sit...
- https://www.raspberrypi.org/resource-cat...
- https://www.raspberrypi.org/product_cate...
- https://www.raspberrypi.org/author-sitem...
A+Domain Intelligenceraspberrypi.org — via Tucows Domains Inc., 17 years, 10 months oldPASS
1188 days
September 15, 2029
73 days
Issued by Let's Encrypt
17 years, 10 months
Registered September 15, 2008
Enabled
Protects against DNS spoofing
Unknown
2606:4700:10::6814:17f3
Tucows Domains Inc.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice