Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BCrawlabilityno robots.txt, no sitemapREVIEW
robots.txt is optional but recommended. It tells search engine crawlers which pages to index.
No robots.txt — crawlers fetch /robots.txt and get 404; not breaking but means default crawl behavior with no directives or sitemap reference.
Learn more ▾ ▴
A minimal robots.txt with `User-agent: * / Allow: / / Sitemap: https://example.com/sitemap.xml` covers the basics. Without it, crawlers behave fine but lose the sitemap signal and can't be selectively blocked from crawl-traps.
Source: robotstxt.org
A sitemap helps search engines discover and index your pages more efficiently.
No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.
Learn more ▾ ▴
A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.
Source: sitemaps.org / Google Search Central
No robots.txt found
This is fine for most sites — a missing robots.txt allows all crawling by default.
No sitemap found
Adding a sitemap helps search engines discover your pages.
BTLS Certificate Expiry & Recommendations170 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records1 A records, 296 ms lookupPASS
| A | 216.165.61.24 |
| AAAA | — |
| CNAME | — |
| NS | ns4.nyu.edu, ns1.nyu.net, ns2.nyu.org |
| MX | 10 mxa-00256a01.gslb.pphosted.com 10 mxb-00256a01.gslb.pphosted.com |
| TXT | fastly-domain-delegation-z2mk2ugh5up86i4m3az9-289772-2020-09-23 MS=DC3CF354465F9F4FB5A01B09FBFF180ED22F296C infoblox-domain-mastery=34facf1fc7d3bbbc27457d106c559122e02312d49fde17ae8af4fc8e... SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:mail.zendesk.com inc... amazonses:570vvekbLUPOzboZxNoWw+sQztEzLFPmxOpAnKV2bcw= Sendinblue-code:e570a8676ae98699a5ff860a7eff1f38 d365mktkey=wrgr4CmP8fLV3AGrcx3N8ppM80ssEtRxg1EvuEn3YL8x notion-domain-verification=SPirDap4YasviSkGht7tvBz1Q6flwoQMQjfY5gC0RuD sprout-social-8f958e49-63d8-4bfc-9826-271d23da83cc apple-domain-verification=b6TUc4cksQQdpGfJ formstack-domain-verification=92470a030e0c70d94bc0f74574679e7e smartsheet-site-validation=nhaTPBPFyQPTo87tE7JYDUOzHmkSWQ94 1password-site-verification=7PVAWVJIPJH6PBUL24EYBA2GQE brevo-code:45b781e69c3502b604156676945c1a5a mandrill_verify.weV9vV4c5CxYgyg5rdIX3g censys-domain-verification=gW6wBmek3RvgWxn-gVUHCOqRfKjuGKJB5xGZHj3N1FTw docusign=dd188105-e05e-45be-95e9-3fbf59fc4a45 e2ma-verification=kv5eb duo_sso_verification=WTYBcV6czONMrarxL7YUdpWbXrsnglElX9TsJCwW7J5XSEVh5asGM0CDeqk... cisco-ci-domain-verification=5f8c1a91a88665fdf1306c4d97c57901e8f2b9134a468e369ac... MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDJe9uQvNP61RpaFRKJNGfkpYiyJ5/GNSoCizWm2guv... e2ma-verification=ruzcb apple-domain-verification=cGRUsgQrf98HFTVr neat-pulse-domain-verification-9v8BGLM=3f2a3344-0174-4eaf-b982-7efe3e83fbb2 google-site-verification=zYK4YgpQpLb40VbmgUANCDqzDBkd6JWxG89WBqW-AvE atlassian-domain-verification=wBl6PljSgaRhrZFeBYJmqW9h0irs5eYWCr4gCFcYpodIiXdhot... google-site-verification=-5tfUFiJkZOeA4CLwhvxUV_9sv3_k1j4LwpwA_eWz3A MS=ms25525126 docusign=a6da09da-1d59-4ede-baad-41ce0f74dd59 MS=ms46861818 adobe-idp-site-verification=d9edc0076f1d016844f8cb979364915c0407390e3fd34be8922a... cmverification-2022 openai-domain-verification=dv-qwQyMcxw8InCnG2WTqxg7wJJ drift-domain-verification=f2f0cda12b9a530f386b71c8fe79981375c876029c5b491606fe89... 82OWAZWDRS1RMM6JHOBC0JJF26SQLAO344GD276PD d365mktkey=wiyHM4COTROERLhtFKfxLmXtPO25ZmPPeKGwIvUsv1Ax zapier-domain-verification-challenge=cf19207c-42d6-4983-9372-cb01572729a2 airslate-domain-verification={C8C31474-7200-0000-0000D981} airtable-verification=dda843c916cb87d00978ad8654a4aa76 apple-domain-verification=gUTv6Uz1Gdi14obE |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
ARedirect Chain1 redirect(s), 599 ms totalPASS
https://nyu.edu
422 ms · HTTP/1.0
https://www.nyu.edu/
176 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://nyu.edu | 302 | 422 ms | HTTP/1.0 | BigIP |
| 2 | https://www.nyu.edu/ | 405 | 176 ms | HTTP/1.1 | CloudFront |
See the visual redirect chain in the HTTP Probe tab →
If permanent, use 301 instead.
302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.
Learn more ▾ ▴
Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).
Source: Google Search Central
AURL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Use 301 (permanent) instead of 302 (temporary)
A+Domain Intelligencenyu.edu — 40 years, 1 months old, hosted on NYU-DOMAIN - New York University, USPASS
410 days
July 31, 2027
170 days
Issued by Internet2
40 years, 1 months
Registered October 8, 1986
Status unknown
Protects against DNS spoofing
NYU-DOMAIN - New York University, US
ASN AS12
216.165.61.24
Registrar unknown