Skip to content
https://lacounty.gov

Infrastructure

· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
86
GRADE
B
FIX
0
REVIEW
4
PASS
5
INFO
0
Probed from Madrid, Spain
200 OK
Checks
9
5 PASS 4 REVIEW
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
REVIEW
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Critical::
HTTP version does not redirect to HTTPS
Got: HTTP 200 Expected: 301 redirect to HTTPS

www / non-www

301https://www.lacounty.gov/
200https://lacounty.gov/

Preferred variant: non-www

HTTP → HTTPS

200http://lacounty.gov/

HTTP version does not redirect to HTTPS

B
HTTP Probe Timing
Total 969 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
REVIEW
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
180 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
96 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
100 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
777 ms
Total Time Total request time from DNS lookup through full response.
970 ms

Connection waterfall

DNS Lookup 180 ms TCP Connect 96 ms TLS Handshake 100 ms Server Processing 401 ms Content Transfer 192 ms
B
TLS Certificate Expiry & Recommendations
197 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

197
days left
0d 30d 60d 90d+

Recommended actions

  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A
DNS Records
2 A records, 934 ms lookup
PASS
2 A records, 934 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 45.60.171.78, 45.60.151.78
Info::
No IPv6 (AAAA) records
Info::
4 nameserver(s) configured
Got: lrci-ib-e04.isd.lacounty.gov, lrci-ib-e03.isd.lacounty.gov, dci-ib-e02.isd.lacounty.gov, dci-ib-e01.isd.lacounty.gov
Info::
2 mail exchanger(s) configured
Info::
CAA records not checked
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Info::
SPF record present in TXT
Warning::
DNS resolution is slow (934 ms)
Slow DNS adds latency to every page load. Consider a faster DNS provider.
Got: 934 ms
A45.60.171.78, 45.60.151.78
AAAA
CNAME
NSlrci-ib-e04.isd.lacounty.gov, lrci-ib-e03.isd.lacounty.gov, dci-ib-e02.isd.lacounty.gov, dci-ib-e01.isd.lacounty.gov
MX
10 mxa-002da105.gslb.pphosted.com
10 mxb-002da105.gslb.pphosted.com
TXT
gTtEyCVZDyP70oqPvofaFS9d6iu1J61TZvEQGVErfMZ9ral+f1t0+wIjwMfAv1X7DgRisqaTt9CsWtGl...
SPF v=spf1 include:spf1.lacounty.gov include:spf2.lacounty.gov include:spf3.lacounty...
globalsign-domain-verification=e397dfdea71940bfcc168554ba58c56b
cq51vtki48g3gg89a8m3iqtahb
safebreach-domain-verification=b37ac52f-ead0-423c-9290-49c2ed5c9950
ZOOM_verify_UYvq32Qz4RZJreNeBIWWe2
globalsign-domain-verification=F6AF70082288C457C8718D51E646E139
smartsheet-site-validation=zNN3XlhKB6fuWuawWrjjsJUjOd-eL2IA
3kkt9dl1lm9dpqg0anohpkhd1p
google-site-verification=tuVDuiauWz_dg9qSfA2uJYR7-cmtn0N-TqqRYiGVeXo
globalsign-domain-verification=61610AE053F5E6DD54AFE43690953B3F
u91d4bv33oe357rd3dd2tfmlg7
google-site-verification=9kN9Zk8w373BEUyZIU3L13w9CdFSa9tjbCRDJ8BE-K0
dtm-domain-verification=EZK9JlcSDZpAcENe0c2PMTpXy5jPWFQS2aWcquRDIx0
y68hJCZte7k9KiGVINQZlGXUVfsfEbrEwyu+RUVuI+lUzzuOd2bDA4py8I/fg2F1SPewbKE51ihkDInJ...
vqqdr8qdqisnfe3r15m7n8menr
ca1k5lb7uvsu53kgqnmdij1irn
globalsign-domain-verification=9643E80AE21E8133955704677CD4EF1B
MS=ms34739264
7c5e7npjg7hnhbveulf62v7mlq
a2l3v2m98762g8oehjmp4qgi8r
_globalsign-domain-verification=z_J4aZzeMftlFWu9iuiaJhUs_a6nQ5h4Fhn81D-aIa
apple-domain-verification=glgsRV4NAcXO2Kpb
globalsign-domain-verification=4e6d98b3e3ec0bf844d114976e50bec8
globalsign-domain-verification=3BF47C6BEE012B669CDA7F94B35A0F0B
globalsign-domain-verification=DE36FF66FE3CBAF41D4D4630B1E813C2
l6c6fi1it9c83mfgqu57n34hte
globalsign-domain-verification=F89755881A99C6E89F3BFA710089ABDC
CAALookup not available with standard resolver
Resolved in 934 ms

CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.

Why this matters

Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.

Slow DNS adds latency to every page load. Consider a faster DNS provider.

Why this matters

DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.

Source: DNS performance benchmarks

A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://lacounty.gov

https://lacounty.gov

387 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://lacounty.gov200387 msHTTP/1.1
A+
Crawlability
robots.txt present, sitemap with 9 URLs
PASS
robots.txt present, sitemap with 9 URLs
Info::
robots.txt is present
Got: 162 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 9 entries
Info::
Sitemap index with 9 child sitemaps
Info::
robots.txt does not reference a sitemap
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.

Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.

Why this matters

robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.

Source: sitemaps.org

robots.txt 200 OK
Size 162 B Sitemaps referenced 0 User-agents *, MJ12bot Blocking No — crawling allowed
User-agent: *
Disallow: /wp-admin/*/
Disallow: /wp-content/plugins/
Disallow: /wp-login.php/
Disallow: /wp-content/ai1wm-backups/

User-agent: MJ12bot
Disallow: /
A+
Domain Intelligence
lacounty.gov — via get.gov, 20 years, 3 months old, hosted on INCAPSULA - Incapsula Inc, US
PASS
lacounty.gov — via get.gov, 20 years, 3 months old, hosted on INCAPSULA - Incapsula Inc, US
Info::
Domain registered until Apr 7, 2027 (11 months remaining)
Info::
DNSSEC is not enabled
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Info::
Registrar: get.gov
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Info::
Hosting: INCAPSULA - Incapsula Inc, US
Got: AS19551
Domain expiry

296 days

April 7, 2027

SSL certificate

197 days

Issued by Sectigo Limited

Domain age

20 years, 3 months

Registered May 4, 2006

DNSSEC

Not enabled

Protects against DNS spoofing

Hosting

INCAPSULA - Incapsula Inc, US

ASN AS19551

45.60.151.78

Registrar

get.gov

Unlocked 2 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Enable DNSSEC to protect visitors from DNS spoofing
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar get.gov
Created May 4, 2006 (20 years, 3 months ago)
Expires April 7, 2027 (11 months)
Last Updated March 10, 2026
Name Servers dns1.lacountydns.com, lrcd1.lacounty.gov
DNSSEC Not enabled
Registrant REDACTED FOR PRIVACY
Hosting
IP Address 45.60.151.78
ASN AS19551 (INCAPSULA - Incapsula Inc, US)
Provider INCAPSULA - Incapsula Inc, US
Data source: rdap (0.6s)

DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.

Why this matters

Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.

Learn more

DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.

Source: ICANN / RFC 4033

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A+
CDN & Delivery
Incapsula (HIT: 34)
PASS
Incapsula (HIT: 34)
Info::
Site is served via Incapsula CDN
Got: x-iinfo: 12-8744600-8733589 2NNN RT(1776889622036 101) q(0 1 1 1) r(3 3)
Info::
CDN cache status: HIT: 34
CDN Detected: Incapsula
Provider Incapsula Cache Status HIT: 34 Evidence x-iinfo: 12-8744600-8733589 2NNN RT(1776889622036 101) q(0 1 1 1) r(3 3)
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback