Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BDNS Records2 A records, 35 ms lookupREVIEW
| A | 2.18.188.228, 23.211.135.130 |
| AAAA | — |
| CNAME | www.nvidia.com.edgekey.net |
| NS | — |
| MX | — |
| TXT | — |
| CAA | Lookup not available with standard resolver |
A CNAME at the zone apex can break MX and NS records. Use ALIAS/ANAME or A records instead.
CNAME at the apex (example.com) breaks every other apex record (MX, TXT, NS) — DNS-protocol violation per RFC 1034.
Learn more ▾ ▴
RFC 1034 forbids CNAME alongside other records at the same name. Some DNS providers offer ALIAS / ANAME / flattened-CNAME records that work around this — use those instead. Otherwise apex-level CNAME breaks email (no MX), domain ownership verification (no TXT), and more.
Source: RFC 1034
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.
Learn more ▾ ▴
SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.
Source: RFC 7208 (SPF)
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations290 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryAkamaiREVIEW
ARedirect Chain1 redirect(s), 27 ms totalPASS
https://www.nvidia.com
17 ms · HTTP/1.1
https://www.nvidia.com/es-es/
10 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://www.nvidia.com | 307 | 17 ms | HTTP/1.1 | AkamaiGHost |
| 2 | https://www.nvidia.com/es-es/ | 200 | 10 ms | HTTP/1.1 | Apache |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 51 URLsPASS
#
# Welcome to NVIDIA
#
#@@@@@@@@@@@@@@@@@@@@@@@@@@@///////////////////////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@@@@@///////////////////////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@@@@%#@#////////////////////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@//////////@@@@@@@@@@@@///////////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@//////@@@@@@@@/////////@@@@@@@///////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@//////@@@@@@//////@@@@@@@//////@@@@@@////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@//////@@@@@//////@@@@///@@@@@@@/////&@@@@@//////////////@@@@@@@@@@@@@@@@@@
#@@@@@@//////@@@@////@@@@@@@/////@@@@/////@@@@@@///////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@/////@@@@/////@@@@@////////////@@@@@///////@//////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@//////@@@@/////@@@/////////@@@@@///////@@@@@@@@//////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@//////@@@@@/////@@@@@@@@@@////////@@@@@@@@@@@//////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@//////@@@@@@@/////////////@@@@@@@@@@@///////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@/////////%/////@@@@@@@@@@@@@/////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@&///@@@@@@@@///////////////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@@@@@///////////////////////////////////@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
#@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@@
#
# We dig it when people read our code! Check out the jobs while you're here.
# https://www.nvidia.com/en-us/about-nvidia/careers/
#
# Or check out our YouTube channel for our latest
# https://www.youtube.com/user/nvidia
#
# Last updated 19 Nov 2025 by LC
sitemap: https://www.nvidia.com/sitemap_index.xml
# AI Agents
User-agent: ai2bot
User-agent: anthropic-ai
User-agent: Amazonbot
User-agent: Amazon-kendra
User-agent: Applebot-extended
User-agent: AutoGPT
User-agent: BedrockBot
User-agent: Bytespider
User-agent: CCBot
User-agent: Chatglm-spider
User-agent: ChatGPT
User-agent: ChatGPT-User
User-agent: Claudebot
User-agent: Claude-user
User-agent: Claude-search
User-agent: Claude-web
User-agent: Cohere-ai
User-agent: Cotoyogi
User-agent: Deepseek
User-agent: Deepseek Chat
User-agent: Deepseekbot
User-agent: DuckAssistBot
User-agent: DuckDuckBot
User-agent: FacebookBot
User-agent: Geminiios
User-agent: Google-Extended
User-agent: Googleagent-manier
User-agent: GPTBot
User-agent: Grok
User-agent: ia-archiver
User-agent: iaskbot
User-agent: iaskspider
User-agent: ICC-crawler
User-agent: Linerbot
User-agent: Metaaib
User-agent: Meta-externalagent
User-agent: Meta-externalfetcher
User-agent: Meta-llama
User-agent: Mistralai-user
User-agent: NovaAct
User-agent: OAI-Searchbot
User-agent: Pangubot
User-agent: Perplexity
User-agent: PerplexityBot
User-agent: Perplexity-user
User-agent: Phindbot
User-agent: PoeBot
User-agent: Qwen
User-agent: Sogou
User-agent: Timpibot
User-agent: Tongyi
User-agent: Wenxiaobai
User-agent: Xinghuo
User-agent: Youbot
User-agent: Yuanbaobot
Allow: /*.llms.txt$
Allow: /*.md$
Allow: https://www.nvidia.com/llms.txt
User-agent: Googlebot
User-agent: Googlebot Smartphone
User-agent: Google AdsBot
User-agent: Bingbot
Disallow: /*.md$
Disallow:/*.llms.txt$
User-agent: *
# Gated Content
Disallow: /content/g/*
Disallow: /content/gated-pdfs/*
Disallow: /content/*/gated-resources/*
Disallow: /content/*/gated-pdfs/*
Disallow: /gated-resources/*
# GF Forums
Disallow: /*?topicPage=
Disallow: /*&topicPage=
Disallow: /*?commentPage=
Disallow: /*&commentPage=
Disallow: /admin/
Disallow: /attach/
Disallow: /content/experience-fragments/*
Disallow: /content/forms/
Disallow: /content/license/driver_license.aspx
Disallow: /content/nvidiaGDC.*\.(?!png|jpg|svg).+$
Disallow: /content/temp/*
Disallow: /ddl2*
Disallow: /email-verify/*
Disallow: /forms/*
Disallow: /*/geforce/release-notes/GFE/Rich/*
Disallow: /*/geforce/release-notes/GFN/Rich/*
Disallow: /*/geforce/release-notes/GFNB/Rich/*
Disallow: /*/geforce/comparisons/*
Disallow: /*/geforce/billboards/*
Disallow: /*/geforce/news/gfecnt/*
Disallow: /processFind*
Disallow: /props/
Disallow: /*.swf$
# Parameters
Disallow: /*[?&]accessToken=*
Disallow: /*[?&]cid=*
Disallow: /*[?&]eid=*
Disallow: /*[?&]hstc=*
Disallow: /*[?&]jso=*
Disallow: /*[?&]link=*
Disallow: /*[?&]lx=*
Disallow: /*[?&]ncid=*
Disallow: /*[?&]nv_excludes=*
Disallow: /*[?&]nvid=*
Disallow: /*[?&]page=*
Disallow: /*[?&]ref=*
Disallow: /*[?&]srsltid=*
Disallow: /*[?&]section=*
Disallow: /*[?&]target=*
Disallow: /*[?&]topicpage=*
Disallow: /*[?&]utm*
# GTC Fixes
Disallow: /*[?&]regcode=*
Disallow: /*[?&]wcmmode=*
Disallow: /*/gtc/gtc-chatbot/*
- https://www.nvidia.com/en-gb/en-gb.sitem...
- https://www.nvidia.com/cs-cz/cs-cz.sitem...
- https://www.nvidia.com/da-dk/da-dk.sitem...
- https://www.nvidia.com/de-at/de-at.sitem...
- https://www.nvidia.com/de-ch/de-ch.sitem...
- https://www.nvidia.com/de-de/de-de.sitem...
- https://www.nvidia.com/es-es/es-es.sitem...
- https://www.nvidia.com/fi-fi/fi-fi.sitem...
- https://www.nvidia.com/fr-be/fr-be.sitem...
- https://www.nvidia.com/fr-fr/fr-fr.sitem...
- https://www.nvidia.com/it-it/it-it.sitem...
- https://www.nvidia.com/nb-no/nb-no.sitem...
- https://www.nvidia.com/nl-nl/nl-nl.sitem...
- https://www.nvidia.com/pl-pl/pl-pl.sitem...
- https://www.nvidia.com/ro-ro/ro-ro.sitem...
- https://www.nvidia.com/ru-ru/ru-ru.sitem...
- https://www.nvidia.com/sv-se/sv-se.sitem...
- https://www.nvidia.com/tr-tr/tr-tr.sitem...
- https://www.nvidia.com/es-la/es-la.sitem...
- https://www.nvidia.com/pt-br/pt-br.sitem...
- https://www.nvidia.com/en-us/en-us.sitem...
- https://www.nvidia.com/en-au/en-au.sitem...
- https://www.nvidia.com/en-in/en-in.sitem...
- https://www.nvidia.com/ja-jp/ja-jp.sitem...
- https://www.nvidia.com/ko-kr/ko-kr.sitem...
- https://www.nvidia.com/en-sg/en-sg.sitem...
- https://www.nvidia.com/zh-tw/zh-tw.sitem...
- https://www.nvidia.cn/zh-cn.sitemap.xml
- https://www.nvidia.com/en-eu/en-eu.sitem...
- https://www.nvidia.com/en-me/en-me.sitem...
- https://www.nvidia.com/he-il/he-il.sitem...
- https://www.nvidia.com/en-my/en-my.sitem...
- https://www.nvidia.com/en-ph/en-ph.sitem...
- https://www.nvidia.com/id-id/id-id.sitem...
- https://www.nvidia.com/vi-vn/vi-vn.sitem...
- https://www.nvidia.com/th-th/th-th.sitem...
- https://www.nvidia.com/ar-sa/ar-sa.sitem...
- https://www.nvidia.com/en-sa/en-sa.sitem...
- https://www.nvidia.com/ru-am/ru-am.sitem...
- https://www.nvidia.com/uk-ua/uk-ua.sitem...
- https://www.nvidia.com/es-ar/es-ar.sitem...
- https://www.nvidia.com/es-cl/es-cl.sitem...
- https://www.nvidia.com/es-mx/es-mx.sitem...
- https://www.nvidia.com/en-ua/en-ua.sitem...
- https://www.nvidia.com/es-py/es-py.sitem...
- https://www.nvidia.com/en-am/en-am.sitem...
- https://www.nvidia.com/content/dam/sitem...
- https://www.nvidia.com/content/dam/sitem...
- https://www.nvidia.com/content/dam/sitem...
- https://www.nvidia.com/content/dam/sitem...
- https://www.nvidia.com/gtc/sitemap_index...
AURL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: www
HTTP → HTTPS
Use 301 (permanent) instead of 302 (temporary)
A+Domain Intelligencenvidia.com — via SafeNames Ltd., 33 years, 5 months old, hosted on AWSPASS
2804 days
April 21, 2034
290 days
Issued by DigiCert Inc
33 years, 5 months
Registered April 20, 1993
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
34.194.97.138
SafeNames Ltd.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033