Skip to content
https://netflix.com

Infrastructure

· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
85
GRADE
B
FIX
2
REVIEW
2
PASS
5
INFO
0
Probed from Sao Paulo, Brazil
301 Moved Permanently
Checks
9
5 PASS 2 REVIEW 2 FIX
D
Redirect Chain
Action
2 redirect(s), 1825 ms total
FIX
2 redirect(s), 1825 ms total
Warning::
2 redirects before reaching final URL
Each redirect adds latency. Try to minimize the chain to 1 hop.
Info::
WWW normalization redirect
Info::
Uses 302 (temporary) redirect
If permanent, use 301 instead.
Got: https://www.netflix.com/
Warning::
Redirect overhead: 1825 ms total
Got: 1825 ms

https://netflix.com

391 ms · HTTP/1.1

301

https://www.netflix.com/

487 ms · HTTP/1.1

302

https://www.netflix.com/br-en/

947 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://netflix.com301391 msHTTP/1.1envoy
2https://www.netflix.com/302487 msHTTP/1.1envoy
3https://www.netflix.com/br-en/200947 msHTTP/1.1envoy

See the visual redirect chain in the HTTP Probe tab →

Each redirect adds latency. Try to minimize the chain to 1 hop.

Why this matters

Redirect chain — each hop adds latency; combine into one redirect where possible.

Source: Google Search Central / web.dev

If permanent, use 301 instead.

Why this matters

302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.

Learn more

Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).

Source: Google Search Central

D
CDN & Delivery
Action
No CDN detected
FIX
No CDN detected
Warning::
No CDN detected
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN detected

Consider using a CDN to improve global delivery speed and reduce origin load.

C
Crawlability
Action
robots.txt present, sitemap with 23414 URLs
REVIEW
robots.txt present, sitemap with 23414 URLs
Info::
robots.txt is present
Got: 3790 bytes
Critical::
robots.txt blocks all crawlers
Disallow: / for all user-agents prevents search engines from indexing any page. This will remove the site from search results.
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 23414 entries
Info::
Sitemap index with 23414 child sitemaps
Info::
robots.txt references sitemap

Disallow: / for all user-agents prevents search engines from indexing any page. This will remove the site from search results.

Why this matters

Disallow: / in robots.txt blocks every search crawler — the site becomes invisible in organic search.

Learn more

Common deployment mistake: a staging robots.txt with `User-agent: * / Disallow: /` ships to prod. The site falls out of search results within days. Verify your robots.txt is the production-intended version. If this is intentional (private site), no action needed.

Source: Google Search Central

robots.txt 200 OK
Size 3790 B Sitemaps referenced 1 User-agents Adidxbot, YJ-WSC, googlebot, YandexSitelinks, Twitterbot, Googlebot-Video, YandexMobileBot, SeznamBot, ClaudeBot, Yeti, Applebot, bingbot, Baiduspider-video, NaverBot, Baiduspider-mobile, YandexWebmaster, Claude-User, Baiduspider, Baiduspider-image, Google-Extended, PerplexityBot, *, YandexBot, YandexVideo, Yahoo Pipes 1.0, OAI-SearchBot, Yandex, Y!J-WSC, GPTBot, Facebot, facebookexternalhit, ChatGPT-User, Claude-SearchBot, AdsBot-Google Blocking Yes — all crawlers blocked
User-agent: *
Disallow: /

User-agent: googlebot
User-agent: Googlebot-Video
User-agent: Applebot
User-agent: bingbot
User-agent: Baiduspider
User-agent: Baiduspider-mobile
User-agent: Baiduspider-video
User-agent: Baiduspider-image
User-agent: NaverBot
User-agent: Y!J-WSC
User-agent: YJ-WSC
User-agent: Yeti
User-agent: Yandex
User-agent: YandexBot
User-agent: YandexMobileBot
User-agent: YandexVideo
User-agent: YandexWebmaster
User-agent: YandexSitelinks
User-agent: SeznamBot
User-agent: facebookexternalhit
User-agent: GPTBot
User-agent: ChatGPT-User
User-agent: OAI-SearchBot
User-agent: Google-Extended
User-agent: ClaudeBot
User-agent: Claude-User
User-agent: Claude-SearchBot
User-agent: PerplexityBot
Allow: /

Disallow: /accountstatus
Disallow: /AccountStatus
Disallow: /aui/inbound
Disallow: /authenticate
Disallow: /autologin
Disallow: /clearcookies
Disallow: /companies
Disallow: /editpayment
Disallow: /emailunsubscribe
Disallow: /error
Disallow: /eula
Disallow: /geooverride
Disallow: /help
Disallow: /imagelibrary
Disallow: /learnmorelayer
Disallow: /learnmorelayertv
Disallow: /login
Disallow: /loginhelp
Disallow: /loginhelp/lookup
Disallow: /loginhelpsucess
Disallow: /LoginHelp
Disallow: /password
Disallow: /logout
Disallow: /Logout
Disallow: /mcd
Disallow: /modernizr
Disallow: /n/
Disallow: /notamember
Disallow: /notfound
Disallow: /notices
Disallow: /nrdapp
Disallow: /optout
Disallow: /overviewblockseeother
Disallow: /popup/codewhatisthis
Disallow: /popupdetails
Disallow: /PopupDetails
Disallow: /popupprivacypolicy
Disallow: /privacypolicychanges
Disallow: /registration
Disallow: /rememberme
Disallow: /signout
Disallow: /signurl
Disallow: /subscriptioncancel
Disallow: /tastesurvey
Disallow: /termsofusechanges
Disallow: /tvsignup
Disallow: /upcomingevents
Disallow: /verifyidentity
Disallow: /whysecure

Disallow: /arabic
Disallow: /Arabic
Disallow: /chinese
Disallow: /Chinese
Disallow: /korean
Disallow: /Korean

Disallow: /airtel
Disallow: /anan
Disallow: /bouyguestelecom
Disallow: /britishairways
Disallow: /brutus
Disallow: /comhem
Disallow: /courts
Disallow: /csl
Disallow: /elisa
Disallow: /entertain
Disallow: /FireTV
Disallow: /firetv
Disallow: /freemonth
Disallow: /kpn
Disallow: /lg
Disallow: /maxis
Disallow: /Maxis
Disallow: /meo
Disallow: /Meo
Disallow: /orangefrance
Disallow: /Panasonic
Disallow: /panasonic
Disallow: /playstation
Disallow: /proximus
Disallow: /qantas
Disallow: /samsung
Disallow: /Sony
Disallow: /sony
Disallow: /talktalk
Disallow: /tdc
Disallow: /telenor
Disallow: /telfort
Disallow: /tim
Disallow: /virginaustralia
Disallow: /vodafone
Disallow: /vodafonedemobilelaunch
Disallow: /xboxone
Disallow: /xfinity
Disallow: /xs4all
Disallow: /ziggo

Disallow: /accountaccess
Disallow: /AccountAccess
Disallow: /BillingActivity
Disallow: /browse
Disallow: /browse/*
Allow: /browse/genre/*
Disallow: /CancelPlan
Disallow: /ChangePlan
Disallow: /changeplan
Disallow: /deviceManagement
Disallow: /DoNotTest
Disallow: /EditProfiles
Disallow: /email
Disallow: /EmailPreferences
Disallow: /entrytrap
Disallow: /HdToggle
Disallow: /LanguagePreferences
Disallow: /ManageDevices
Disallow: /ManageProfiles
Disallow: /MoviesYouveSeen
Disallow: /NewWatchInstantlyRSS
Disallow: /NewWatchInstantlyRSS/*
Disallow: /payment
Disallow: /Payment
Disallow: /phonenumber
Disallow: /pin
Disallow: /profiles
Disallow: /profiles/*
Disallow: /ProfilesGate
Disallow: /search
Disallow: /search/*
Disallow: /viewingactivity
Disallow: /WiViewingActivity
Disallow: /yourAccount
Disallow: /youraccount
Disallow: /YourAccount
Disallow: /YourAccountPayment

User-agent: AdsBot-Google
User-agent: Twitterbot
User-agent: Adidxbot
Allow: /

User-agent: Yahoo Pipes 1.0
User-agent: Facebot
Disallow: /
Allow: /tudum

Sitemap: https://www.netflix.com/sitemap/index

sitemap.xml 200 OK
Type Sitemap Index URLs 23414 entries Valid XML Yes
Child Sitemaps:
B
TLS Certificate Expiry & Recommendations
308 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

308
days left
0d 30d 60d 90d+

Recommended actions

  • Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+
DNS Records
3 A records, 111 ms lookup
PASS
3 A records, 111 ms lookup
Info::
Resolves to 3 IPv4 address(es)
Got: 52.3.144.142, 54.237.226.164, 3.230.129.93
Info::
Has 3 IPv6 (AAAA) record(s)
Got: 2600:1f18:631e:2f85:93a9:f7b0:d18:89a7, 2600:1f18:631e:2f83:49ee:beaa:2dfd:ae8f, 2600:1f18:631e:2f84:4f7a:4092:e2e9:c617
Info::
4 nameserver(s) configured
Got: ns-1372.awsdns-43.org, ns-1984.awsdns-56.co.uk, ns-659.awsdns-18.net, ns-81.awsdns-10.com
Info::
5 mail exchanger(s) configured
Info::
CAA records not checked
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Info::
SPF record present in TXT
Info::
DNS resolution time: 111 ms
Got: 111 ms
A52.3.144.142, 54.237.226.164, 3.230.129.93
AAAA2600:1f18:631e:2f85:93a9:f7b0:d18:89a7, 2600:1f18:631e:2f83:49ee:beaa:2dfd:ae8f, 2600:1f18:631e:2f84:4f7a:4092:e2e9:c617
CNAME
NSns-1372.awsdns-43.org, ns-1984.awsdns-56.co.uk, ns-659.awsdns-18.net, ns-81.awsdns-10.com
MX
1 aspmx.l.google.com
5 alt1.aspmx.l.google.com
5 alt2.aspmx.l.google.com
10 aspmx2.googlemail.com
10 aspmx3.googlemail.com
TXT
1password-site-verification=BXCRTZRWNVG4PFLIYFIBWSYHX4
5f5a7676-2a28-4400-a64e-465626e5ff6b
8cd468d7d5994fcc9d350683a8cb07a1
anthropic-domain-verification-vxqysx=XDtJHKRTpvy6QvuMuyVMXbMxT
apple-domain-verification=Ohlo8qLyb9N4JaIm
apple-domain-verification=U1j_Aj0pS5fid78Cag85YGM14jHrzxM-S2ICXc8rGxg
appspace-domain-verification=59cd40985507690b0ac0e2c83d24dd6dfa24c7d7571f00b7401...
asv=4853f01b1e9226ed9d0031284948059f
atlassian-domain-verification=TX0Efjn8bXAu0o9GAHyYowM0mcu4oDPHFf10cqaDXFCvU9tRB7...
canva-site-verification=DW6T-OKEapKu9QB9ChMocw
deepl-domain-verification=f6610dd4c1414006bd6382c115542467
docker-verification=5f9a055c-22b9-4d40-be7f-5af4171e1e71
docusign=f249396f-8150-48f8-8bd2-705be6e03826
docusign=f3d36bef-ec7d-42e5-9334-626611acb127
dropbox-domain-verification=htwo11xk2yl1
e6060ec6-b362-4acb-9a1f-b80e99d17753
facebook-domain-verification=k65vedr09b2tp2q144ho1zewp3xsc6
freepik-domain-verification=eeb4ee5ff6237e57ea15d2369b574c68
google-site-verification=9DgwSKXMlFzcnW-HuGWef6aVVHWDCQNehxHTq0Ps9IA
google-site-verification=F6fRKDfeR1Uqz8qJvmH3HmQQxpu9JYY9GJUFeV3hU3Y
google-site-verification=VQKoV3pv-QYIDfbQa1N4r97x8W07veRTK6JhWUavIuc
google-site-verification=Wn4h4x_Gf8Zs5qiw88ZingFRjLUNzga-zJXts2UPics
google-site-verification=YVxAf7gFR4vFk1RkUwiYt3pzl2AVUP6aPdBgV1qtwcw
google-site-verification=a8Lak2UwVjIlmH1xRYU3mJ6nSQ7rJnyf2VKWtH4nKZI
google-site-verification=nCi1QdlMabPJOvtQNCo5KaPyDfwog9pDr3d8IN767YA
h1-domain-verification=AYCqXFtcqVzAhHLWr58GvY2WrbTfkGeMsijza2jPS2E1qcn1
infoblox-domain-mastery=83433630723145c8e700674aa65ad12bf58d7cd22434a5527c383d13...
jamf-site-verification=vqjVdHx1f_q52DK-WclChA
klaviyo-site-verification=UM4UEX
klaviyo-site-verification=WwbqJa
logmein-verification-code=4FVB4FQ17eVMyHCC7RAApS4Zp
logmein-verification-code=905b1ed4-1c2e-466f-b24c-756e6ca39eb5
loom-verification=0004053852
lucidlink-verification=26PKTJ9J3ATM2SWV49QRS442K4
miro-verification=9ac407d6774b2ec4313b004d40204399e37f3b48
notion-domain-verification=MHmHAv2mrRGxVuA3rhIRmz6vwrsAEbsqCR6yRIycSoj
smartsheet-site-validation=zZPtdlBFlbl-n54tmRUUcd6Bd8lllpAR
sso-domain-verification-7wfrk6=LfxRM5a023zTb2jO6QWeDcZ9e
tiktok-domain-verification=e8242b26316716e951678da03b794de5a838482929d5b62ea2e0a...
unity-sso-verification=46eb4cbd-e316-4691-84c2-4f4bce784d84
SPF v=spf1 include:_spf_ipv4.netflix.com include:_spf.google.com include:amazonses.c...
zapier-domain-verification-challenge=d740d03c-47a4-491c-934d-c61bdba6099e
CAALookup not available with standard resolver
Resolved in 111 ms

CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.

Why this matters

Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.

A+
IPv6 Readiness
IPv6 reachable (122 ms)
PASS
IPv6 reachable (122 ms)
Info::
IPv6 is configured and reachable at 2600:1f18:631e:2f85:93a9:f7b0:d18:89a7, 2600:1f18:631e:2f83:49ee:beaa:2dfd:ae8f, 2600:1f18:631e:2f84:4f7a:4092:e2e9:c617
Got: 122 ms connect
IPv6 Ready
AAAA Records 2600:1f18:631e:2f85:93a9:f7b0:d18:89a7, 2600:1f18:631e:2f83:49ee:beaa:2dfd:ae8f, 2600:1f18:631e:2f84:4f7a:4092:e2e9:c617 Connection Reachable (122 ms)
A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Info::
HTTP correctly 301-redirects to HTTPS

www / non-www

302https://www.netflix.com/
200https://netflix.com/

Preferred variant: non-www

HTTP → HTTPS

301http://netflix.com/ https://netflix.com/

Consistent

A+
Domain Intelligence
netflix.com — via MarkMonitor Inc., 28 years, 10 months old
PASS
netflix.com — via MarkMonitor Inc., 28 years, 10 months old
Info::
Domain registered until Nov 10, 2027 (1 years, 7 months remaining)
Info::
DNSSEC is not enabled
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Info::
Registrar: MarkMonitor Inc.
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Domain expiry

512 days

November 10, 2027

SSL certificate

308 days

Issued by DigiCert Inc

Domain age

28 years, 10 months

Registered November 11, 1997

DNSSEC

Not enabled

Protects against DNS spoofing

Hosting

Unknown

2600:1f18:631e:2f84:ceae:e049:1e:6a96

Registrar

MarkMonitor Inc.

Unlocked 4 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Enable DNSSEC to protect visitors from DNS spoofing
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar MarkMonitor Inc.
Created November 11, 1997 (28 years, 10 months ago)
Expires November 10, 2027 (1 years, 7 months)
Last Updated October 9, 2025
Name Servers ns-1372.awsdns-43.org, ns-1984.awsdns-56.co.uk, ns-659.awsdns-18.net, ns-81.awsdns-10.com
DNSSEC Not enabled
Hosting
IP Address 2600:1f18:631e:2f84:ceae:e049:1e:6a96
Data source: rdap (0.4s)

DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.

Why this matters

Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.

Learn more

DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.

Source: ICANN / RFC 4033

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A+
HTTP Probe Timing
Total 385 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
2 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
122 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
125 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
385 ms
Total Time Total request time from DNS lookup through full response.
386 ms

Connection waterfall

DNS Lookup 2 ms TCP Connect 122 ms TLS Handshake 125 ms Server Processing 136 ms Content Transfer 0 ms
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback