Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BHTTP Probe TimingTotal 832 ms — DNS, TCP, TLS, TTFB, content transfer breakdownREVIEW
Connection waterfall
BTLS Certificate Expiry & Recommendations258 days until leaf cert expires — 5 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 54 ms lookupPASS
| A | 13.248.219.127, 76.223.69.48 |
| AAAA | — |
| CNAME | — |
| NS | ns-1262.awsdns-29.org, ns-1942.awsdns-50.co.uk, ns-260.awsdns-32.com, ns-579.awsdns-08.net |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 aspmx3.googlemail.com 10 aspmx2.googlemail.com |
| TXT | -YmejhUkwDLXXeWYbehQAxrf 1password-site-verification=EJWIVHGTDFG7DFTTYJL4LR5FLY MS=ms32056553 _5tvx1gyc2yfoda4lftaahduomcrwf8n _fimewmbhqiw0326uox8jlpdv0ijab64 adobe-idp-site-verification=9268f0bf65e722619f863d4c8e05c94ebf45e50d691a1e6399e8... anthropic-domain-verification-f3zxsq=LPY17h2p8t4lxXbc7smBKywZI apple-domain-verification=csMy6RR7QIjftLlf atlassian-domain-verification=t449HTbEFJ6cig9xRqaeCy4WXYQWjoIGeg/DLWl8G308boa5Db... atlassian-sending-domain-verification=ce00b671-dc0a-433a-bfb7-2358cf3821a8 brevo-code:2f0c4fd9880f9665542e181744f1d9fa canva-site-verification=xWH39TNIIfwwRxL8s2TcvQ cursor-domain-verification-3hpy7a=Y2tu94Khunoulb0vx40QUKMxY docker-verification=56e942dc-af8a-40c7-b671-3b2549fa6836 docusign=17efa275-26e8-4bf5-be57-894111e00bce dropbox-domain-verification=piklqj1g2z36 epoch-domain-verification-xh26fy=luIeDFoDpcOzLQkefqm8go14E gn8g8wj3rxyhhyv4582pj68cs9nkt6zp google-site-verification=KLRkSFXuyWSnycd2CicMYEpYeIj_SXHW6IPRtGPQ648 google-site-verification=N60sstGie9jnCQqr5PUZw7cWpUTggmM4Fuveih7dS2g google-site-verification=Pr7iUx77LxDC34m8Vd_MONpWyLm1lGi5nT9_-b1ifQQ google-site-verification=WgtoYZ5Pimcr7SESFr_1xYW2awtx_DtiHKhjUd0WLm4 google-site-verification=gEGpnxSMW8ironroRwAYm5F0a-ff8zL-j2y2q9tQKL4 google-site-verification=gqPzq2Hsmcae9L3nQxFSRa47pXenhOP30el1-OdfI4s google-site-verification=lBGlKiSVmjZPPLkprHztShC-hquWEuRmXqOzwnUPIS4 google-site-verification=ou3vCVjSCTacNlZ45HWmWC9Bgh3LrhibNjfvdN6NQno google-site-verification=tfC-Q8StbguRHx4bvf6nGl0oO0f1pwtlNZiqPGriCN0 google-site-verification=v8pWhH0M0cY7_gnvUgDWc2hOwqyhaUcXwANwHF6yU8w h1-domain-verification=BnRNcurBY8Ep78My4FHBXmLzhhSJWMWYwkPfHrXDNtA4RrkP hubspot-developer-verification=NDM5ODg2MGItZTQwNy00MDJjLWFhMTktZWMyODhhYjc1NmZi hubspot-developer-verification=Zjc4NjI5M2ItMWUxMy00MzBmLTkwNjItNmZkMWMxYTcwMDM3 hubspot-uv4NW994s5Am miro-verification=93074e8e9166f962d18902efe961e4b1bc4e3234 notion-domain-verification=sMTDrB7KkRlRygoteRG6jE7xiZITKdLXL5lhRk8ZT4F notion_verify_YR#is].+RNfLBfV)6ceu]TL?++3>Q6)F^BeVaw+tTADe#Qu@55#yu=Kj^Q8#cGDnmN... openai-domain-verification=dv-SM9Mstx4xknAgtNhzdzjPX38 ps-cd-verification=15285629-d436-432e-87ca-7e8a850a71d3 reachdesk-verification=YFGnB17NeDVHYp9gESLVqpOQoEVaaCKmM8Ryqpq2SxmahSrZsY3tgrrnk... stripe-verification=e2d645081bdc8fd29f2f4ea6f29337bd5d25a819694fa6cb534a085adec0... v=MCPv1; k=ed25519; p=3zRkqhZH6mDF42JW4AFYFkf0tlDSM2+y2tOcdlSvkIs= SPF v=spf1 include:_spf.google.com ip4:205.201.128.0/20 ip4:198.2.128.0/18 ip4:148.1... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://amplitude.com
811 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://amplitude.com | 200 | 811 ms | HTTP/1.1 | nginx/1.22.0 |
A+Crawlabilityrobots.txt present, sitemap with 9 URLsPASS
User-Agent: *
User-Agent: GPTBot
User-Agent: OAI-SearchBot
User-Agent: ChatGPT-User
User-Agent: ClaudeBot
User-Agent: anthropic-ai
User-Agent: PerplexityBot
User-Agent: Google-Extended
User-Agent: Applebot-Extended
User-Agent: CCBot
User-Agent: Meta-ExternalAgent
User-Agent: cohere-ai
Allow: /
Disallow: /*sanity_test*
Sitemap: https://amplitude.com/sitemap.xml
- https://amplitude.com/sitemap-root.xml
- https://amplitude.com/sitemap-ja-jp.xml
- https://amplitude.com/sitemap-ko-kr.xml
- https://amplitude.com/sitemap-es-es.xml
- https://amplitude.com/sitemap-pt-br.xml
- https://amplitude.com/sitemap-pt-pt.xml
- https://amplitude.com/sitemap-fr-fr.xml
- https://amplitude.com/sitemap-de-de.xml
- https://amplitude.com/docs/sitemap-docs....
A+Domain Intelligenceamplitude.com — via MarkMonitor Inc., 30 years, 4 months old, hosted on AWSPASS
208 days
January 10, 2027
258 days
Issued by Amazon
30 years, 4 months
Registered May 9, 1996
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
76.223.69.48
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice