Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations35 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records1 A records, 97 ms lookupPASS
| A | 217.114.94.2 |
| AAAA | — |
| CNAME | — |
| NS | doug.ns.cloudflare.com, harmony.ns.cloudflare.com |
| MX | 10 de-smtp-inbound-1.mimecast.com 20 de-smtp-inbound-2.mimecast.com |
| TXT | apple-domain-verification=Q7KwgmChGjUIkAjJT8Su-e81y48GoIDKdrWJKZCflGI google-site-verification=M2p2oNOfIy17Ci7kj8vS9RH4YKCf6lfxyH4aa-pro_E google-site-verification=3p_UqtkCzX5Qgaf4Qa8vCVOADcQxlaimwxDIPDPU3J4 Digicert Order # 00498813. Optimizely contact: Dogan Ugurlu
<dogan@optimizely.c... 00D4J0000002msD=1TBPz00000000hZ figma-domain-verification=1912c435587480ca0caf3a2a631b9a603d1924f3b3d08d196d40ae... Verification for Edgecast SSL through Digicert. Digicert Order # 00351809. Edgec... tiktok-developers-site-verification=ByD4LcSV0qZsix2Klx0Nc7RAXij2HDSZ google-site-verification=hAhAgheovxOO3XfPfburDkCSlbH7vMMnkySYj8kdFj8
atlassian-domain-verification=fVxueGq1T9CLx1FmNDg7+//C3Q8kRlgPyJ92oiCabOlE0FQgW... dropbox-domain-verification=1gn35nocfdjx google-site-verification=rdgHG3OphS2vyHzppjAgA_u--2ji3VeA81Xk4CUb5Kw google-site-verification=5I-ImxYUlKGA58rILw7HPg4bhErsy6qZig37I-DQTG4 loaderio=9f2321067d0a5ed2165da78a078a2125 Verification for the SSL cert for help.optimizely.com Digicert Order # 00435673.... docker-verification=c49faaa6-b68f-4a4a-9695-97144c0ec13d amazonses:xxLSLODJvdUPkNOdqLqR2X5AnhJzIWBvgvVvH5XYwsY= Demonstration of domain control for DigiCert order #00399883. Please send the ap... cursor-domain-verification-t5qp01=phvHwGecfsDxZ5DGLaUpqt9QT google-site-verification=m6s7sFYopEJQ9Be_DjLt4DFj88Q8sYnsVnA149u6rwc google-site-verification=RGGeHfceOB0_bznjJqtJJjVfjtUE3ZR2KpgzRfCcH90 apple-domain-verification=9Mq9EOa61FT430k8 teams.optimizely.com dmb9xl3d5frmkq48vddtsf6cy73jg48c adobe-idp-site-verification=edbef1f3fcf34f3db2121d4b6aa25e37b75e61879e526da209fb... google-site-verification=MnJ3tcQo7PaOcyYyN73AjK83tEDmOOYoV8SCT2U6oZE _globalsign-domain-verification=xACDE3CJMcS0Ud2e9XTDQ7O7axmXzPg8Mp9rDVIgaT google-site-verification=4JvIJnZJei_AHvqRmTRfA0DoBo9VA96bgQSsqH0Impw protonmail-verification=2c10e0613f5e323cafcac05b050c42a119f7c0c6 docker-verification=4f9e8898-2616-42e6-8622-0258237a99fd yahoo-verification-key=rqHgBmOodEcddj/DjNqpnG8i+HAdLJTUNNmf/ewF0oU= docker-verification=81db037f-4d8d-4b97-8480-45e23568bad7 cdn-pci.optimizely.com 8x3658gpctg4h1vbnzmm2432bxsfxcz0 MS=ms12641694 k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDEp2HXojOuMp8W2mYAQWb4SCkK/OCr/ly... google-site-verification=hY82UoEGpukg4bWtEBMnoEDu4U_kFECFAI61SyxjKek segment-site-verification=AaQwxphohytWn6ITgojBF75WGyY6FTle hcp-domain-verification=2e64a27c64e94e6e763e934ce2b1a5574d32e0493348013cfa12289e... docusign=78f5a0dc-5599-4771-939a-7479d9f19a15 docker-verification=11bd769c-c17a-405b-9a6d-dad70ad9e237 docker-verification=4463daac-0d0c-4db8-ba57-eda20ab9f85f Verification for the SSL for www.optimizely.com. Digicert Order # 00502638. Opti... carta-domain-verification-j5c0wv=PVHGuxCt3hpJ6mlHJnunPYJlm SPF v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email ~all google-site-verification=RNDBwtT0w-dC7jgY2h4a785AmbqEXI7epedh-8cCg1g docusign=5ef03274-ba7e-4497-b1c8-68822293b6df bugcrowd-verification=976ed661be12db673bc241ab9adedd78 google-site-verification=YTf8W8ct20t0_Pk4CWBP3WIlzYoa-AbATixOVOSX1So google-site-verification=HPlj5QbZTQcYZ7ZrWKvVw6TGQ6Js8mjkP-lRHU272aY docker-verification=eba70851-4749-43b1-a985-f7f5d39cd100 openai-domain-verification=dv-At5TJCxtaR4p3AcFNaOZnDkn google-site-verification=QIwh-a1egznd9cJo_qy_IC1E2qkyZCCxGPmyKMTQdQo zapier-domain-verification-challenge=ec9e02b0-2df0-4698-b412-b58a2e23fa8b gitkraken-domain-verification=428606b7bda6111075c267457625b3dc0c0efb46f5498e1027... mixpanel-domain-verify=400a27dd-7cc3-468a-8564-e4f52d40c058 MS=ms74851995 google-site-verification=I398ijOehdDlmeyNnoTWkurrboteERLDPcsh0lTE5_g _globalsign-domain-verification=f-B_7ErtvSe_2e1SkhSsTab6DQA-AVd2vcvY3gqskQ Verification for the SSL for blog.optimizely.com. Digicert Order # 00406293. Opt... Verification for the SSL for maven.optimizely.com. Digicert
Order # 00584621. O... google-site-verification=bmI8Jpu2KjE37aLb4usDSXAIVPd7ueI6gUeQpAFtjXA facebook-domain-verification=wley07odaemi4l7vay725u95yq4g07 docker-verification=b94f46f3-6bae-44db-8c8e-ee1ce8d49b4b anthropic-domain-verification-4gkavj=TJnFfngBQ8OlXRrgx0BEn6Jg8 mongodb-site-verification=9UVwoclVFO1wQoSS1RiFxUMm8F2d9tUj jetbrains-domain-verification=7qb4k14glpb935e05fm71x4w8 google-site-verification=fT1I_jd2XGik8XySrXwOdkUFLVt2FqmiIoVjWgkuPU8 browserstack-domain-verification=1ce32231-8d2e-47ff-a13f-b3313f9466b3 google-site-verification=F9cHkOOFB7B48BIiVW5OjoWxz8olRXaP2JefPKVPYv4 google-site-verification=awCCHxysSWlId2pJybFVzs-Z_YoSd2tOhGlbnu1NWsk FMTFZVQRM docker-verification=06453662-1054-405b-b2ee-f2d9eeb6d443 loaderio-69745689fd1dbf2e7a4fef37b749c433 8x3658gpctg4h1vbnzmm2432bxsfxcz0 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 433 ms totalPASS
https://optimizely.com
30 ms · HTTP/1.1
https://www.optimizely.com/
403 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://optimizely.com | 301 | 30 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.optimizely.com/ | 200 | 403 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 7052 URLsPASS
User-agent: *
Disallow: /utils/
Disallow: /qa-testing/
Disallow: /*error-pages
Disallow: /*thank-you
Disallow: /*download
Disallow: /@vite
Disallow: /archived
Sitemap: https://www.optimizely.com/sitemap.xml
Sitemap: https://www.optimizely.com/videositemap.xml
A+Domain Intelligenceoptimizely.com — via GoDaddy.com, LLC, 16 years, 5 months old, hosted on EPISERVER_AS, SEPASS
211 days
January 11, 2027
35 days
Issued by Google Trust Services
16 years, 5 months
Registered January 11, 2010
Enabled
Protects against DNS spoofing
EPISERVER_AS, SE
ASN AS30811
217.114.94.2
GoDaddy.com, LLC
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice