Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations54 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add includeSubDomains to the HSTS directive
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records5 A records, 10 ms lookupPASS
| A | 104.17.250.203, 104.17.251.203, 104.17.252.203, 104.17.253.203, 104.17.254.203 |
| AAAA | 2606:4700::6811:facb, 2606:4700::6811:fbcb, 2606:4700::6811:fccb, 2606:4700::6811:fdcb, 2606:4700::6811:fecb |
| CNAME | — |
| NS | noah.ns.cloudflare.com, amanda.ns.cloudflare.com |
| MX | 0 isaca-org.mail.protection.outlook.com |
| TXT | MS=ms57298346 00da0000000ku9nmaw 5JY7oZquhjaBhlmHkRcWfg 8763052itpqkaj9e3d1icn03c0 kilb7e6kbq77vmvkhvkul9gqm0 ZOOM_verify_gwGqpMDDYeMZxHV8vel1th asv=485a5ce97f8a647a5bb768d8cf3fc9ac 8d2b84b1fc8a4642a9b0a751033a3172.isaca.org canva-site-verification=mQpt_Rwlu0n0EgKwqmD5Yw miro-verification=1d3ad7c11bd875de9a80077ec626eb7d89db1413 linkedin-site-verification=f9f6eb98-287f-4ffc-89a2-3dac3158e396 google-site-verification=SC6MDLvy3TaZMj_jTOcnYlZkLMEFi18357zOaWAlDm4 google-site-verification=arfDw2jKw4ahKNMrBEBEPjt9XnEDmdwFa7D2t9Fxh1U pexip-ms-tenant-domain-verification=67166909-ffbe-4eeb-a7ea-78fff6e99562 nnOnkXYce+Y+WY1IrUCPBk/DwnbXI7+2gDPgnGgw6RIztxBdAUYiwdnbaaMiGtbCIiNPfOMoHiw2JHIT... adobe-idp-site-verification=f161e9ea5bad522f35f1adbad853dcc7e96fdf40b75a604d0a52... atlassian-domain-verification=WjcyDcIxfhe6HedXsDaoP5MQPWyWPZ5molGRGTfQTVUZnAyKNX... figma-domain-verification=3d4ce7bb69eaf7e30cb1aadda8f9ed65c366d15c99448ccf5b0d1e... SPF v=spf1 ip4:50.31.141.71 ip4:50.225.38.99 ip4:50.31.141.65 ip4:192.254.116.40 ip4... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 512 ms totalPASS
https://isaca.org
25 ms · HTTP/1.1
https://www.isaca.org/
487 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://isaca.org | 301 | 25 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.isaca.org/ | 200 | 487 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 5355 URLsPASS
User-agent: *
Crawl-delay: 10
Disallow: /cart
Disallow: /billing
Disallow: /shipping
Disallow: /review
Disallow: /payment
Disallow: /login
Disallow: /logout
Disallow: /myisaca
Disallow: /myisaca/
Disallow: /conferences/register/profile
Disallow: /membership/professional-profile
Disallow: /membership/recent-graduate-profile
Disallow: /membership/student-profile
Disallow: /create-account
Disallow: /forgot-password
Disallow: /thank-you
Disallow: /search
Disallow: /*.pdf$
Disallow: /api/
Disallow: /Coveo/
Disallow: /coveo
Disallow: /SiteCollectionImages/
Disallow: /layouts/
Disallow: /devops/
Disallow: /-/media/files/*
Disallow: /media library/Files/
Disallow: /Media Library/Files/
Disallow: /media library/files/
User-agent: seekport
Disallow: /
User-agent: Swiftbot
Disallow: /
User-agent: PaperLiBot
Disallow: /
User-agent: garlik
Disallow: /
User-agent: hypefactors
Disallow: /
User-agent: weborama
Disallow: /
User-agent: dotbot
Disallow: /
User-agent: CCBot
Disallow: /
Sitemap: https://www.isaca.org/sitemap.xml
A+Domain Intelligenceisaca.org — via Nom-iq Ltd. dba COM LAUDE, 31 years, 4 months oldPASS
329 days
May 9, 2027
54 days
Issued by Google Trust Services
31 years, 4 months
Registered May 8, 1995
Enabled
Protects against DNS spoofing
Unknown
2606:4700::6811:facb
Nom-iq Ltd. dba COM LAUDE
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice