Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations89 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 94 ms lookupPASS
| A | 104.18.36.77, 172.64.151.179 |
| AAAA | 2606:4700:440a::ac40:97b3, 2a06:98c1:310c::6812:244d |
| CNAME | — |
| NS | gold.foundationdns.org, gold.foundationdns.net, gold.foundationdns.com |
| MX | 10 dc-gov.mail.protection.outlook.com |
| TXT | e2ma-verification=0ftgb atlassian-domain-verification=SCPCosHrMpfZMNEZ7IYaUq6Ac5ppg2hur0/fPcugNgMjTanjqP... e2ma-verification=eqdcb atlassian-domain-verification=HBFa0J1nnLYQXtaF6A4FUobWV5aGo9vDIcZNpCBrknhg2Hqlc5... SPF v=spf1 include:spf.dc.gov include:spf.protection.outlook.com include:_spf.salesf... nintex.63ab41b73ec889c959e10f0f e2ma-verification=ke0cb ca3-3043cd8cf3294d9dbb74306c1be8268e apple-domain-verification=bUVKiynGDHggfm2M 0623ce5ff4a54aac0bf3aee8028c6916 f2d5c8ee-f8c7-4225-bf4d-ca3182d90521 _ru7oasmkxjqmvd1sq6egawf38c55g9h e2ma-verification=48kgb z0h7s6hh9j22hkmh0nnfgynl8sbbbflq d21267d5-b0d5-4ad8-899e-bf9671bddd90 xsplit_verify=iW959K7ib3vWMz39vOZZeW8D634c2nOHhYHL miro-verification=facd5cba00b67cf22e44a894772f03a83229caa8 _qypuppcst3hdm3exdjfptuegikgiuym e2ma-verification=3pdcb atlassian-domain-verification=CluP9fDYk2ngB7am1rTvO9A1kMabQkb/TkYPQczNQbsRNxbyUs... cisco-ci-domain-verification=466b7642db91eb6b16a8cfabe7f95d22cec5e3517fefbe79829... adobe-idp-site-verification=264b923e-12ae-4166-ab00-02887d548e49 adobe-sign-verification=258c2dc712ea1a1cd7c46c46f54b6805 1a18a358-3fe8-448f-966e-12bc9cab47bb docusign=d9af5032-0a97-4165-9917-dff3d6a7db15 duo_sso_verification=XP4aA0C8Q05cQKgtcvIiRCepIAA7GqfPFdrdrMi0IkloIX6X1z0NSDVrwxS... _hrc9ytg6gmss9lnzdx3jwwg2ko0mq8e 3pcp1p4wfqv20kddcyv1vyfsw24tbb5l |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://dc.gov
68 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://dc.gov | 200 | 68 ms | HTTP/1.1 | cloudflare |
A+IPv6 ReadinessIPv6 reachable (16 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 2748 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: SemrushBot
Disallow: /
User-agent: bytespider
Disallow: /
User-agent: *
Crawl-delay: 10
# CSS, JS, Images
Allow: /misc/*.css$
Allow: /misc/*.css?
Allow: /misc/*.js$
Allow: /misc/*.js?
Allow: /misc/*.gif
Allow: /misc/*.jpg
Allow: /misc/*.jpeg
Allow: /misc/*.png
Allow: /modules/*.css$
Allow: /modules/*.css?
Allow: /modules/*.js$
Allow: /modules/*.js?
Allow: /modules/*.gif
Allow: /modules/*.jpg
Allow: /modules/*.jpeg
Allow: /modules/*.png
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /themes/*.css$
Allow: /themes/*.css?
Allow: /themes/*.js$
Allow: /themes/*.js?
Allow: /themes/*.gif
Allow: /themes/*.jpg
Allow: /themes/*.jpeg
Allow: /themes/*.png
# Directories
Disallow: /includes/
Disallow: /misc/
Disallow: /modules/
Disallow: /profiles/
Disallow: /scripts/
Disallow: /themes/
# Files
Disallow: /CHANGELOG.txt
Disallow: /cron.php
Disallow: /INSTALL.mysql.txt
Disallow: /INSTALL.pgsql.txt
Disallow: /INSTALL.sqlite.txt
Disallow: /install.php
Disallow: /INSTALL.txt
Disallow: /LICENSE.txt
Disallow: /MAINTAINERS.txt
Disallow: /update.php
Disallow: /UPGRADE.txt
Disallow: /xmlrpc.php
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips/
Disallow: /node/add/
Disallow: /search/
Disallow: /user
Disallow: /user/
Disallow: /user/register/
Disallow: /user/password/
Disallow: /user/login/
Disallow: /user/logout/
# Paths (no clean URLs)
Disallow: /?q=admin/
Disallow: /?q=comment/reply/
Disallow: /?q=filter/tips/
Disallow: /?q=node/add/
Disallow: /?q=search/
Disallow: /?q=user/password/
Disallow: /?q=user/register/
Disallow: /?q=user/login/
Disallow: /?q=user/logout/
- https://dc.gov/
- https://dc.gov/release/mayor-bowser-expands-summer-youth-employment-program-22-24-year-olds
- https://dc.gov/release/bowser-administration-announces-new-radio-encryption-protocol-first-responders
- https://dc.gov/release/dc-snow-emergency-goes-effect-7-am-tuesday-february-17
- https://dc.gov/snow217
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencedc.gov — via get.gov, 26 years, 2 months oldPASS
60 days
August 12, 2026
89 days
Issued by Google Trust Services
26 years, 2 months
Registered June 22, 2000
Enabled
Protects against DNS spoofing
Unknown
2606:4700:440a::ac40:97b3
get.gov
Expiry timeline
Recommended actions
- Renew the domain or enable auto-renewal to prevent accidental expiry
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice