Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CCrawlabilityActionrobots.txt present, sitemap with 164 URLsREVIEW
Disallow: / for all user-agents prevents search engines from indexing any page. This will remove the site from search results.
Disallow: / in robots.txt blocks every search crawler — the site becomes invisible in organic search.
Learn more ▾ ▴
Common deployment mistake: a staging robots.txt with `User-agent: * / Disallow: /` ships to prod. The site falls out of search results within days. Verify your robots.txt is the production-intended version. If this is intentional (private site), no action needed.
Source: Google Search Central
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: Googlebot
User-agent: Bingbot
User-agent: Twitterbot
Crawl-delay: 5
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
#Ui Pages
Allow: /people/*
Allow: /education/*
Allow: /articles/*
Allow: /credits/*
Allow: /projects/*
Allow: /chapters/*
Allow: /organization/*
Allow: /community/*
Allow: /resources/*
Allow: /store/*
Allow: /merchandise/*
Allow: /help/*
Allow: /contactus
Allow: /leedaddenda/*
User-agent: bedrockbot
Allow: /perform/*
Allow: /articles/*
Allow: /education/*
Allow: /credits/*
Allow: /education-listing/*
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /sites/default/files/*.pdf
Disallow: /sites/default/files/*.doc
Disallow: /sites/default/files/*.docx
Disallow: /sites/default/files/*.xls
Disallow: /sites/default/files/*.xlsx
Disallow: /sites/default/files/*.ppt
Disallow: /sites/default/files/*.pptx
Disallow: /README.txt
Disallow: /web.config
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /search/
Disallow: /user/register/
Disallow: /user/password/
Disallow: /user/login/
Disallow: /user/logout/
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password/
Disallow: /index.php/user/register/
Disallow: /index.php/user/login/
Disallow: /index.php/user/logout/
User-agent: *
Disallow: /
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations322 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 99 ms lookupPASS
| A | 172.66.140.116, 172.66.134.150 |
| AAAA | 2606:4700:10::ac42:8c74, 2606:4700:10::ac42:8696 |
| CNAME | — |
| NS | nina.ns.cloudflare.com, art.ns.cloudflare.com |
| MX | 0 usgbc-org.mail.protection.outlook.com |
| TXT | atlassian-domain-verification=wIX9Gbo0fgTYgFcEEjMWKgdWaj6C79AhoTJwuwI6LxdmW0r6Ph... SPF v=spf1 ip4:66.150.113.91/32 ip4:72.32.154.0/24 ip4:72.32.217.0/24 ip4:72.32.243.... smartsheet-site-validation=j3b6yGdRPH6BxLgNVcRDh5-vR1ZM3HDm 7116e21ec95141e39a59775f806806ea google-site-verification=HzApLQOl-d4MlUIFd0mRuYNazmSkRasVekRVuY0uYRI google-site-verification=_7X8df_j_-cvvSNq8c7L6z8oRAlQqos8R-iSQyl1E0Y google-site-verification=rftUr-nz71pFfL2BeXYb4v7drtHudo9c3UnZdIAWD1w blitz=mu-d6a2e3e2-f4c0e8a1-59115055-321b6c2f ufTTHKbjEAwsJuNCvvsUBrS0h+HPlhUiMOuAkxI6juBoCExL5eejSSyNqJXeyMVqNRJ7IdB/yPMepgVw... v=DKIM1;t=s;p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCn798hW2rMZm+iW7EEsbQsjR7t57... pardot413862=2dc49ff8d20c5c54d0aad6674f401b58ce2e7f5c93ac4161ae8002a296e64dd3 notion-domain-verification=gUQ4adR8LUaHLVKlIY6dpfzqRR6D65TmWP8ie7Hgydh smartsheet-site-validation=xIoKZ_leTYDB8y7fIltH6itfsE5Icd8l v=verifydomain MS=ms41471662 atlassian-domain-verification=GVLfB3Ld6wcglQaObTuNIiK5eIw2aXP7keKvRyRE5ZmXP6OKdX... figma-domain-verification=004a2a95ce6cff6448a3495dc96389bfc437b235e3ac0ba962447a... dropbox-domain-verification=kewrkh6e1rpa miro-verification=84bc4563ae07463018d23c0509b9cdd47a1d0de2 anthropic-domain-verification-6e0aj4=KlQL33en8pr1Ee83UUt8iQbsI 133c4af53f09da02aa4f4af0d400bddd8234aec03c4982a7e2f265103d9c7fcc 00d400000009uedeau blitz=mu-82bbced8-545e6867-9f252e8d-9d534997 sophos-domain-verification=ca7be9b5058c2ba7ea511d8dfee0199c3ceb3e5abf969f674d947... IepxpxUACWbaekmBNvlGHQXmXpFGV8Rz72pk+VmKiY7reCIcthTDjy43C3qJJ2mnXGO0Zw0nKzVGGYTi... google-site-verification=aZwjgbxwI66QRPXZLYsIGq9V7mdcNQnwhIJej_fNjOY MS=ms99119295 google-site-verification=_5Ff80ZihUQ4Boj_EQPG0a2OdwNZ34XmPTNSUDqzUJU |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 168 ms totalPASS
https://usgbc.org
63 ms · HTTP/1.1
https://www.usgbc.org/
105 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://usgbc.org | 301 | 63 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.usgbc.org/ | 200 | 105 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
ADomain Intelligenceusgbc.org — via Tucows Domains Inc., 30 years, 2 months oldPASS
24 days
July 10, 2026
322 days
Issued by Sectigo Limited
30 years, 2 months
Registered July 11, 1996
Not enabled
Protects against DNS spoofing
Unknown
2606:4700:10::ac42:8c74
Tucows Domains Inc.
Expiry timeline
Recommended actions
- Renew the domain or enable auto-renewal to prevent accidental expiry
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Consider enabling auto-renewal to prevent accidental expiration.
Domain expiry approaching — renew immediately and ensure auto-renew + alerting are configured.
Source: ICANN renewal policy
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice