Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations73 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 82 ms lookupPASS
| A | 52.31.103.110 |
| AAAA | — |
| CNAME | — |
| NS | a1-90.akam.net, a28-64.akam.net, a22-67.akam.net, a6-66.akam.net, a7-67.akam.net, a3-65.akam.net |
| MX | 10 eu-smtp-inbound-1.mimecast.com 10 eu-smtp-inbound-2.mimecast.com |
| TXT | MS=ms16735680 MS=ms48193102 atlassian-domain-verification=-3LQBDgJTX7pUVyv8d7smY8GTnoRuZ8d2C0PgVyxvNQz9zRI4v... lovable_verification=Z0qbKniTTDLcS8wFZeiz sv5d3g1w28m8lzwxwhmjh0p282zbbq63 fq8mrqsy6cmhwvl98n44v012smr4d8dv onetrust-domain-verification=f51eaa9ef0fe46eabdfa2cbd169f9a46 sophos-domain-verification=6435915acc806b91de732dea5ca3f2895879e708e0b7cb0d6f7a6... z1njbshlm0126sywdfl9dtzvpp67ymqm ses_domain_verification = CRDvM9uvWCF4NLIkJ7lvfKfthlvFYw5i/nBO1NQGJ2g= _8ee8fbc500fd7550e7cac474510ecd82.sdgjtdhdhz.acm-validations.aws. nngtbz97bx2dh7hq91r3n1pr6gvmbbq5 ivnbta4doml7fuho7t5uhsb5ue google-site-verification=HM2HHLevaszSuedN_LE3UpjFoHxc1Uufu7S_eKzkghI apple-domain-verification=NCZ4d0nmcntXWHzx canva-site-verification=gq-UWsS-vHONOjdPXwF-2w t8wc8mdcjnhb16444qlpsq364y7ygl62 l10kvz100xtwdfq5lfn2zpmp4xw7v3hy miro-verification=25163c5b869973b59bca2f90f562e5ae2916fcaa 0OnFhDXtUnDltu0JK1B8aBbMrJ/9P6MEYLpMoOXslvPXiPCewbZLL3oDvHvR8calt7jqrYSkLqfpLoqu... _globalsign-domain-verification=FfcMiT6K33eLcc_BCTbKlrAoP6GT784fFgSvVq1jAx _fa5422c17361986a9b27bde85ac7c6d9.historical-collection.rsc.org. fr0z912zwkvmjmrycrb0mnbqkbt79kq4 SPF v=spf1 redirect=7zu651uf._spf._d.mim.ec google-site-verification=WmYilO5lM8Vz6-6gaQWwyNHVGiVKp7GNSJqEtYUG3qk google-site-verification=GUBQBUB4UYaCCC5mloNeHAMOBvtWKQDnymPQYHbXFuk globalsign-domain-verification=0BF0B7C56B0EB0C67FE08BF84EFE9669 _ofqkrn9j012cp2bb790fbb6q4fwu5ke MS=E9015CFA1FA5382B1800C8B255C3765172561891 h5rnlrlmvo5eclt6e2i4mkkvfu bmg3xvp0b1vqqph6fnlcqsm2twfcvs77 2ce17811ee |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 277 ms totalPASS
https://rsc.org
108 ms · HTTP/1.1
https://www.rsc.org/
169 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://rsc.org | 301 | 108 ms | HTTP/1.1 | |
| 2 | https://www.rsc.org/ | 200 | 169 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 4168 URLsPASS
##ACAP version=1.0
# allow contracted search
User-agent: gsa-crawler
Disallow:
# block GuideBot
User-agent: Guidebot
Disallow: /
# block robots
User-agent: *
Disallow: /Membership/Memberzone/
Disallow: /is/
Disallow: /publishing/journals/rssfeed.asp
Disallow: /pdf/members/newsletters/womenchemists_apr02.pdf
Disallow: /AboutUs\News/PressReleases/2009/UVToothBleaching.asp
Disallow: /Publishing/ChemScience/Volume/2009/03/Turning_the_light_off_on_tooth_bleaching.asp
Disallow: /Publishing/EdSymp/
Disallow: /Publishing/ATHENS_index.asp
Disallow: /images/EdSymp2010_reportforweb_tcm18-185058.pdf
Disallow: /Labs/
Disallow: /placesofchemistry/
Disallow: /rsc-id/
# Editors symposium files
Disallow: /images/WorkshopA_Impact_tcm18-177392.ppt
Disallow: /images/WorkshopB_EditorialBoards_tcm18-177393.ppt
Disallow: /images/_WorkshopC_peer%20review%20workshop_tcm18-179104.ppt
Disallow: /images/WorkshopD_ChemSpider_tcm18-177395.ppt
Disallow: /images/WorkshopE_eplatform_tcm18-177396.ppt
Disallow: /images/WorkshopF_Intl%20Dev_tcm18-177397.ppt
Disallow: /images/WorkshopG_SUNAM_RSCEditors_tcm18-177398.ppt
Disallow: /images/WorkshopH_SocialMedia_tcm18-177399.ppt
Disallow: /images/WorkshopI_OpenAccess_tcm18-177400.ppt
Disallow: /images/WorkshopJ_CelinaRamjoue_tcm18-177401.ppt
# allow contracted search
ACAP-crawler: gsa-crawler
# User-agent: gsa-crawler
# block GuideBot
ACAP-crawler: Guidebot
# User-agent: Guidebot
ACAP-disallow-crawl: /
# Disallow: /
# block robots
ACAP-crawler: *
# User-agent: *
ACAP-disallow-crawl: /Membership/Memberzone/
ACAP-disallow-crawl: /Labs/
ACAP-disallow-crawl: /placesofchemistry/
# Disallow: /Membership/Memberzone/
ACAP-disallow-crawl: /is/
# Disallow: /is/
ACAP-disallow-crawl: /publishing/journals/rssfeed.asp
# Disallow: /publishing/journals/rssfeed.asp
# Yahoo crawl
User-agent: Slurp
crawl-delay: 30
#Conference Pages
Disallow: /membership/benefits/join_acs.asp
Disallow: /chemistryworld/subscribe_acs.asp
#Exam File for Robert Bowles
Disallow: /Education/SchoolStudents/Olympiad/paper2011.asp
# e-Membership
Disallow: /Membership/e-Membership/app-help.asp
#HD75942 11:11 08/02/2012
Disallow: /suppdata/
# Denial URLs
Disallow: /chemistryworld/_denial.asp
Disallow: /education/eic/_denial.asp
Disallow: /publishing/_denial.asp
Disallow: /publishing/currentawareness/_denial.asp
Disallow: /publishing/journals/_denial.asp
Disallow: /membership/_denial.asp
# Block AhrefsBot and AhrefsSiteAudit
User-agent: AhrefsBot
Disallow: /
User-agent: AhrefsSiteAudit
Disallow: /
Sitemap: https://www.rsc.org/sitemap.xml
A+Domain Intelligencersc.org — via Network Solutions, LLC, 33 years, 3 months old, hosted on AWSPASS
1463 days
June 16, 2030
73 days
Issued by Sectigo Limited
33 years, 3 months
Registered June 17, 1993
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
52.31.103.110
Network Solutions, LLC
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice