Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BRedirect Chain2 redirect(s), 126 ms totalREVIEW
https://nationalarchives.gov.uk
20 ms · HTTP/1.1
https://www.nationalarchives.gov.uk/
24 ms · HTTP/1.1
https://webarchive.nationalarchives.gov....
82 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://nationalarchives.gov.uk | 302 | 20 ms | HTTP/1.1 | CloudFront |
| 2 | https://www.nationalarchives.gov.uk/ | 301 | 24 ms | HTTP/1.1 | nginx/1.31.0 |
| 3 | https://webarchive.nationalarchives.gov.... | 200 | 82 ms | HTTP/1.1 | Caddy |
See the visual redirect chain in the HTTP Probe tab →
Each redirect adds latency. Try to minimize the chain to 1 hop.
Redirect chain — each hop adds latency; combine into one redirect where possible.
Source: Google Search Central / web.dev
If permanent, use 301 instead.
302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.
Learn more ▾ ▴
Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).
Source: Google Search Central
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations225 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryAWS CloudFront (FunctionGeneratedResponse from cloudfront)REVIEW
A+DNS Records4 A records, 26 ms lookupPASS
| A | 108.156.91.91, 108.156.91.122, 108.156.91.64, 108.156.91.84 |
| AAAA | — |
| CNAME | — |
| NS | ns-1370.awsdns-43.org, ns-1869.awsdns-41.co.uk, ns-193.awsdns-24.com, ns-859.awsdns-43.net |
| MX | 0 nationalarchives-gov-uk.mail.protection.outlook.com |
| TXT | 846jem2oirp3mngnueg5cv0m1s 846jem2oirp3mngnueg5cv0m1s. DbUsQo5WRLre2nHvaSRgFtqTkgPZDZY7rIPVW4a9vTo1E+QkQfJpadWWSwUS6NidNqeeI7aQ3t/LnwUL... EbGfXflNGhMh7JzrFOb7h7MTvLiVaRIxYYGnKCPSh2IxW6TQImNWabOkMc2fy6MqcTeCpOt+aW7ImcKl... MS=ms12671644 MS=ms21432841 atlassian-domain-verification=r3F9wApaSrzb3LEZYWDvtHrq2EliAFlXN8HjfJfccbW9hKAUot... auvufc5kkpbmio2cjbre0c5b5s citrix.mobile.ads.otp=va0hf6mjsfcsyeq0xsi5d citrix.mobile.ads.otp=zc90r1sevn933lx8md2h eiq728gltupdvicj4bpr528pvf google-site-verification=4vd4W6SkujHXmItMtu5h9GJQ6qlByNLD9dvirB3yGsY google-site-verification=V6BXUotS4Hx1B62e5odVfkCa_qO2tYfF7XO7eQgUnxE google-site-verification=ooULoOpdvjOxMLrAStHVbmjpEohdTyWem4-JTgGWZVg msfpkey=5d7d2qnmxcyx7zxojedu9nv5j msfpkey=7carxvs9m8398sxexojer8bh5 SPF v=spf1 a ip4:89.197.114.128/25 ip4:72.55.140.81 ip4:72.32.24.120 ip4:34.102.239.... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 2 URLsPASS
# Tells Scanning Robots Where They Are And Are Not Welcome
User-agent: Googlebot
Disallow: /help-with-your-research/research-guides/birth-marriage-death-england-and-wales
Disallow: /help-with-your-research/research-guides/birth-marriage-and-death-certificates
Disallow: /help-with-your-research/research-guides/adoptions
Disallow: /help-with-your-research/research-guides/electoral-registration
Disallow: /help-with-your-research/research-guides/living-people
Disallow: /help-with-your-research/research-guides/historical-nhs-patient-records/
User-agent: Bingbot
Disallow: /help-with-your-research/research-guides/birth-marriage-death-england-and-wales
Disallow: /help-with-your-research/research-guides/birth-marriage-and-death-certificates
Disallow: /help-with-your-research/research-guides/adoptions
Disallow: /help-with-your-research/research-guides/electoral-registration
Disallow: /help-with-your-research/research-guides/living-people
Disallow: /help-with-your-research/research-guides/historical-nhs-patient-records/
User-agent: Slurp
Disallow: /help-with-your-research/research-guides/birth-marriage-death-england-and-wales
Disallow: /help-with-your-research/research-guides/birth-marriage-and-death-certificates
Disallow: /help-with-your-research/research-guides/adoptions
Disallow: /help-with-your-research/research-guides/electoral-registration
Disallow: /help-with-your-research/research-guides/living-people
Disallow: /help-with-your-research/research-guides/historical-nhs-patient-records/
User-agent: DuckDuckBot
Disallow: /help-with-your-research/research-guides/birth-marriage-death-england-and-wales
Disallow: /help-with-your-research/research-guides/birth-marriage-and-death-certificates
Disallow: /help-with-your-research/research-guides/adoptions
Disallow: /help-with-your-research/research-guides/electoral-registration
Disallow: /help-with-your-research/research-guides/living-people
Disallow: /help-with-your-research/research-guides/historical-nhs-patient-records/
User-agent: * # applies to all robots
Disallow: /_404-tests
Disallow: /1939-data-room
Disallow: /08-10-13scripts
Disallow: /08-10-13styles
Disallow: /abc123
Disallow: /about/record-transfer-spring-2015
Disallow: /academic
Disallow: /accessions/accprograms/
Disallow: /advanceorders
Disallow: /advanceorders/includes/
Disallow: /advanceorders/js/
Disallow: /amp-blog.htm
Disallow: /archives/
Disallow: /beta/
Disallow: /book-a-reading-room-visit/
Disallow: /bookshop/account.aspx
Disallow: /bookshop/App_Code/
Disallow: /bookshop/basket.aspx
Disallow: /bookshop/Bin/
Disallow: /bookshop/Controls/
Disallow: /bookshop/coupn.aspx
Disallow: /bookshop/digital_receipt.aspx
Disallow: /bookshop/ordercomplete.aspx
Disallow: /bookshop/process_order.aspx
Disallow: /bookshop/receiptfailure.aspx
Disallow: /bookshop/searchresult.aspx
Disallow: /bookshop/titleshow.asp
Disallow: /bookshop/xml/
Disallow: /Bridging
Disallow: /business
Disallow: /cab/
Disallow: /cabinetpaperssearch
Disallow: /catalogue
Disallow: /celebratingcensus
Disallow: /census
Disallow: /chat
Disallow: /clickandbuy
Disallow: /conferences/
Disallow: /conferencesclosed
Disallow: /contact/form/
Disallow: /contact-us/*/form
Disallow: /cover-it-live/
Disallow: /currency/
Disallow: /customerrors/
Disallow: /dc-framework/
Disallow: /dc-guidance/
Disallow: /dc-riskassessment/
Disallow: /dc-service/
Disallow: /dc-training/
Disallow: /design-guide/
Disallow: /digexpress
Disallow: /digitalcontinuity
Disallow: /digitalexpress/
Disallow: /discovery
Disallow: /document_handling
Disallow: /documentsonline
Disallow: /documentphotos/
Disallow: /documents/archives/ArchivesObsolete
Disallow: /documents/information-management/imr-guidance-and-appendices.pdf
Disallow: /documents/mog.pdf
Disallow: /documents/old/
Disallow: /dol
Disallow: /droid/
Disallow: /e179/includes/
Disallow: /e179/scripts/
Disallow: /ecards
Disallow: /editorial/
Disallow: /educationservice
Disallow: /edwardii-conference
Disallow: /emergency.htm
Disallow: /empire-at-war
Disallow: /enewsletter
Disallow: /enewsletter/global/
Disallow: /enewsletter/includes/
Disallow: /equity
Disallow: /equity/includes/
Disallow: /equity/scripts/
Disallow: /ero
Disallow: /ERORecords
Disallow: /eventsbooking
Disallow: /eventsbooking/email_templates/
Disallow: /eventsbooking/includes/
Disallow: /eventsbooking/scripts/
Disallow: /failover
Disallow: /Filestore/
Disallow: /foi/pubscheme/
Disallow: /gazettestender
Disallow: /gettingstarted
Disallow: /gcs
Disallow: /gwdb
Disallow: /ia/
Disallow: /hospitalrecords/includes/
Disallow: /househistory
Disallow: /ichora5
Allow: /images/news/
Allow: /images/news/112/
Allow: /images/about/
Allow: /images/home/
Allow: /images/visit/
Disallow: /ImageViewer/
Disallow: /information-principles
Disallow: /information-management/manage-information/places-of-deposit/
Disallow: /includes/
Disallow: /irlist/includes/
Disallow: /labs-maintenance.htm
Disallow: /labs-unavailable.htm
Disallow: /legion
Disallow: /livingin1901
Disallow: /livingthepoorlife
Disallow: /localhistory
Disallow: /media
Disallow: /militaryhistory
Disallow: /museum
Disallow: /museum/includes/
Disallow: /mypage
Disallow: /news/999-snow.htm
Disallow: /news/372.htm
Disallow: /online/includes
Disallow: /pas-198
Disallow: /podcasts
Disallow: /poor_law
Disallow: /portal
Disallow: /preservation
Disallow: /presspreview/
Disallow: /pronom
Disallow: /pronom/product/
Disallow: /pronom/vendor/
Disallow: /recordsmanagement
Disallow: /records/old/
Disallow: /registration
Disallow: /registration/includes/
Disallow: /registration/js/
Disallow: /religiousarchives
Disallow: /rt2014v2/
Disallow: /search/
Disallow: /search.htm
Disallow: /search/name_search.aspx
Disallow: /searchthearchives
Disallow: /sepia/images
Disallow: /SFACS
Disallow: /shop/record-copying-beta.htm
Disallow: /shop/record-copying-faqs-beta.htm
Disallow: /spanish-civil-war
Disallow: /streamline
Disallow: /TNACRL
Disallow: /towton
Disallow: /transfer
Disallow: /video
Disallow: /webarchive/orphans/
Disallow: /wdytya
Disallow: /xml
Disallow: /yourarchives
Disallow: /zzz/
Sitemap: http://www.nationalarchives.gov.uk/sitemaps/sitemap-index.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencenationalarchives.gov.uk — via Verizon UK Limited, 23 years, 8 months old, hosted on AWSPASS
182 days
December 12, 2026
225 days
Issued by Amazon
23 years, 8 months
Registered December 12, 2002
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
18.238.55.7
Verizon UK Limited
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice