Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations42 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Submit your domain to hstspreload.org to be added to the Chrome preload list
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records4 A records, 266 ms lookupPASS
| A | 185.199.108.153, 185.199.109.153, 185.199.110.153, 185.199.111.153 |
| AAAA | 2606:50c0:8000::153, 2606:50c0:8001::153, 2606:50c0:8002::153, 2606:50c0:8003::153 |
| CNAME | — |
| NS | ns1.dnsimple.com, ns2.dnsimple-edge.net, ns3.dnsimple.com, ns4.dnsimple-edge.org |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt4.aspmx.l.google.com 10 alt3.aspmx.l.google.com |
| TXT | SPF v=spf1 a include:mailgun.org include:_spf.google.com ~all google-site-verification=G4LSozoSHu-VTikiPg46zrfaZB5ZyvSmPwI7UVVRpr0 google-site-verification=jOj-OEpQd2DpoqUGCv7RaYRKcYUV27f9YW6PlMosn4w google-site-verification=ve8Pd7VtlazAz-W0SkxefaesyTiwtljiBgiMr4lTDEQ google-site-verification=xdkGeGJgOi1M8ARiyRnk8cLRarr4VU6BVnys-Rs2D2s globalsign-domain-verification=fk2SH1LhIKwBvZpVs2blkxrNOlHK4sWqH0v3Ui59Jv |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
A+Redirect ChainNo redirects — direct accessPASS
https://brew.sh
145 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://brew.sh | 200 | 145 ms | HTTP/1.1 | GitHub.com |
A+IPv6 ReadinessIPv6 reachable (2 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 90 URLsPASS
User-agent: *
Allow: /
Disallow:
Sitemap: https://brew.sh/sitemap.xml
# Algolia-Crawler-Verif: E7447A9ABE2B96C8
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencebrew.sh — via 1API GmbH, 13 years, 3 months oldPASS
280 days
March 22, 2027
42 days
Issued by Let's Encrypt
13 years, 3 months
Registered March 22, 2013
Status unknown
Protects against DNS spoofing
Unknown
2606:50c0:8000::153
1API GmbH
Expiry timeline
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.
Source: ICANN / domain-security best practice