Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DTLS Certificate Expiry & RecommendationsAction13 days until leaf cert expires — 3 issues to addressFIX
Certificate validity
Recommended actions
- Renew certificate — 13 days remaining
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Use 301 (permanent) instead of 302 (temporary)
A+DNS Records1 A records, 115 ms lookupPASS
| A | 147.181.37.238 |
| AAAA | 2a04:9a00:1003:4003:f816:3eff:fe96:4aca |
| CNAME | — |
| NS | ns3.rijksoverheidnl.org, ns2.rijksoverheidnl.eu, ns0.rijksoverheidnl.com, ns1.rijksoverheidnl.nl |
| MX | 10 mail.ssonet.nl 10 mail2.ssonet.nl |
| TXT | cOruXHy56jeDWAxhaaveMxKsYop8QYASjfSw6DqktHCastQElEQXdgBcdQAOGaWo XGrWWV8gwBMvAbNGFpBgfFNmKsKjtFSCNXdMGsGgSywBsfF8vB3fpLrI0bgqB1Rl google-site-verification=FhSrXm8YVYClzzQ4w8Xt_tkFAux6Z5cu5972RYa-vFc 87CXbG0bNzV3Hwm764sNrAXUjfKlKYyoVUknBItIiD3IpoOBM58ozr3qknjUFHzJ WOlaixdsZMPoCcH9AqQdnRufu4zsKnB3FQVyTRl3w6DYsH9BG48691FrRUC4TOuF yCCAGIVU0n0biXE7oWs3zDnqNeaU6q425FPDhVd2Ytkv2e35eEKijGUmQLvL0XVd HfOHlCBnOFCJlwmwFeMVsxfTcYE03ImjGCurkWBgNMPVpYI2O11frR7TetQnlXGv FPG4Fp4avYPPTeCa8iuRlgVq0nF12OPMDaAqqxGozzaILyYqWPKHthVOdm4HdSW0 5oea3rWMAtq8XXSM5Hu4pJyJaCv4R5b7F5D9t87RdghEYPfVjkCeBlge1JcUv9Sg VBAgjDyYFeEJwiw6ZA2ciHJqh3II66ur6nB0eg7hQTz1K5Dki0RPK9VdDiZpH4qK google-site-verification=ES_24ZFioUsjVXStod0U7Y85TD6PlOGAfMKrAmA-CHg kpLhGcGs6BBLpIXQj6UaUOvQGYSwDiO4Xl9H4vnxtP4eJa8nsWtBt6t2oENktvv3 9dFcmWxYt1jWaQvirESEmMyAu8YWsvJV9LDi4XXXOGypEgml1vaUE9bClE9OsiTC s1Ofz02DFl5BBNxGBMMGHiJ4aaxDs7Ud8MK4LIlr27NqAVb0enWpGP1CamS2eVQM tlv88t108j04bvcy47p27gh97fxvg4mz 4LF7bqxE4d9riTDy5E690DHsIEt0bSDvbAWHQfkDv8WlgbE0waZ5w9pLq0fmjbae uDeq8fHhD8Ft2jfiUhPQif0ClDALHClOyFLVQQUTNzRwaPmY2YY7kFMQhOcNQ47d MO0xtcbPu35sPIEy9xGXljwZVoaWsy5kDrZlBvT9ve0xUXwGl2FdevTJejuVKfa0 0Kqo8wnSGfDVr1BnI5ZlxmQ5REz233dojhIDiOWliO5Q5WzMlN2CTQ42pZp0yAhY W53UnihMblUAWdSQUOTj5JQHY61U7G6LruioVIWMWQYInD8zzBlXiJhV03PtYnyC qbrxaDDBCoDBCHVEfRye5GXwBnFp6p8O0kc7TNkEmLB573cs1B90V1d2x7Xg4KqL google-site-verification=nivXOjznF9srb1-tPe0QjgoiJ5CaWhv_NjgE8rNp6Hk Brw4Xg6kHVuf36vaSFHnujLbo6V0SXy6tRyBQPNyX9FrcwyR7S8igS42wtcPeDpb google-site-verification=4OgZZJGOhpcK-Kh2hwb42ODOhJn2DV2AZ-mXLoiAibE google-site-verification=OQuv-2QlbTTGD_KgqNCtSOM5c61KNO8j2ERMDU2IKJE google-site-verification=1BumELEzy0NmynOxUn0yTNhFUxZ5mt-XY36o3XksFLo oWBWKsPfaRHrb0F9vLNdxRLBWS3AfiPKWo1hs8D6yI8iUeAjidFb8TwkPDy1KF19 j7fFrOfEGhYvjujYkHu4/w9X3waboVOJUBHuxEPOCrQWwjRfauXWBNfEPyHUbzHldp3wLF038LXXHfUp... NW6UbzgWsDPXloOSdn7l3NdO7Li03lTxirOQKqEWNNrNBnYetFnr0NTUIn5dTauK CTL2keM4M8XOgL4A8cXWyETv9B7tCBtARwvWssoBE3SrxaCfepzYEwBLwSuWPfDE uAzvfngveqeLLLpXwLc3so9494by09w7su4e0IoK7WDwJWyow1crJF4CDL5nvLBH SPF v=spf1 include:_spf_mx.solvinity.com a:mx01-koop.solvinity.com a:mx02-koop.solvi... google-site-verification=QFF2xuF8IsnzJIYwJ12FodnOx-pvHgZGj4j752bh_GI fbdRbAMSIImajCW9jxjr0k0iHjGe0VABDQzHQQGpCoNPhXwWBjBTeauXuT7kwmtl 92S7kG6kN2iOHttRP2crc8457R7BIuiL07A2q1EhnTzb2DgNX8EWwmleSYH4bn7W rT6qGYJTR1WarFYLEyyyF04x4nmglWgHRJ6o1PQcoVe7C4N8ud8RXgouirG3W1AJ google-site-verification=LyneHHyffFWUUtzQTw5a1bDawJFziWaPZ_UGc0E1flg MS=ms88871473 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://overheid.nl
180 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://overheid.nl | 200 | 180 ms | HTTP/1.1 |
A+IPv6 ReadinessIPv6 reachable (39 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 157 URLsPASS
#############################
# Global settings
#############################
Sitemap: https://www.overheid.nl/sitemap.xml
#############################
# Google
#############################
User-agent: Googlebot
Disallow: /dienstverlening/
Disallow: /zoekresultaat/
Disallow: /resultpage/
Disallow: /berichten-over-uw-buurt/
Allow: /
User-agent: Googlebot-Image
Disallow: /dienstverlening/
Disallow: /zoekresultaat/
Disallow: /resultpage/
Disallow: /berichten-over-uw-buurt/
Allow: /
User-agent: Googlebot-Video
Disallow: /dienstverlening/
Disallow: /zoekresultaat/
Disallow: /resultpage/
Disallow: /berichten-over-uw-buurt/
Allow: /
# Google AI / data usage extensions
User-agent: Google-Extended
Disallow: /
User-agent: Google-CloudVertexBot
Disallow: /
#############################
# Bing
#############################
User-agent: Bingbot
Disallow: /dienstverlening/
Disallow: /zoekresultaat/
Disallow: /resultpage/
Disallow: /berichten-over-uw-buurt/
Crawl-delay: 10
Allow: /
#############################
# AI / LLM crawlers
#############################
# OpenAI
User-agent: GPTBot
Disallow: /
User-agent: OAI-SearchBot
Disallow: /
# Anthropic
User-agent: ClaudeBot
Disallow: /
User-agent: CCBot
Disallow: /
# Perplexity
User-agent: PerplexityBot
Disallow: /
# Apple
User-agent: Applebot
Disallow: /
User-agent: Applebot-Extended
Disallow: /
# ByteDance / TikTok
User-agent: Bytespider
Disallow: /
User-agent: TikTokSpider
Disallow: /
#############################
# Sogou and variants
#############################
User-agent: Sogou web spider
Disallow: /
User-agent: Sogou inst spider
Disallow: /
User-agent: Sogou Pic Spider
Disallow: /
User-agent: Sogou spider2
Disallow: /
#############################
# Catch-all
#############################
User-agent: *
Disallow: /dienstverlening/
Disallow: /zoekresultaat/
Disallow: /resultpage/
Disallow: /berichten-over-uw-buurt/
Allow: /
A+Domain Intelligenceoverheid.nl — via Rijksoverheid, 27 years, 9 months oldPASS
Unknown
13 days
Issued by CERTSIGN SA
27 years, 9 months
Registered December 4, 1998
Enabled
Protects against DNS spoofing
Unknown
2a04:9a00:1003:4003:f816:3eff:fe96:4aca
Rijksoverheid
Expiry timeline
Recommended actions
- Renew the TLS certificate or verify auto-renewal is working
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice