Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations126 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 12 ms lookupPASS
| A | 108.156.60.34, 108.156.60.24, 108.156.60.119, 108.156.60.76 |
| AAAA | 2600:9000:2394:ce00:e:6c93:2e80:93a1, 2600:9000:2394:7c00:e:6c93:2e80:93a1, 2600:9000:2394:5a00:e:6c93:2e80:93a1, 2600:9000:2394:4600:e:6c93:2e80:93a1, 2600:9000:2394:e000:e:6c93:2e80:93a1, 2600:9000:2394:d800:e:6c93:2e80:93a1, 2600:9000:2394:ba00:e:6c93:2e80:93a1, 2600:9000:2394:9200:e:6c93:2e80:93a1 |
| CNAME | — |
| NS | ns-1091.awsdns-08.org, ns-1809.awsdns-34.co.uk, ns-236.awsdns-29.com, ns-991.awsdns-59.net |
| MX | 1 aspmx.l.google.com 5 alt2.aspmx.l.google.com 5 alt1.aspmx.l.google.com 10 aspmx2.googlemail.com 10 aspmx3.googlemail.com |
| TXT | adobe-idp-site-verification=2a89b891432143ce2403c051e2ba92b042188556f48ed29a21f5... atlassian-domain-verification=cQVPHGxF7xozv8YN7f0YFszavoQXsa4jIyy0YTh1l703iGGjj1... box-domain-verification=b50bb9d4c71875c10b09cd6e310b592b20353cd15bbbefb4fad5b398... bugcrowd-verification=c44172c0849844f8508e7908047a84bf canva-site-verification=5aT9JJUuponuDnyrDMzOpw docker-verification=8e34f3f0-0aa5-4d34-bb94-f54b00bb7e81 docusign=6295a189-1693-4624-bfae-ebdd192e05c1 figma-domain-verification=6b48ca69b772dd85a5eafc93089ccbce085476786d8eaf45e1609b... gc-ai-domain-verification-fyngm9=DmVW9GtGZRxbjMeek7HHZoGyV google-site-verification=A6Wokcxexs3h8RCPep5ikPj_5Ou35JR9zynIBt4_VOs google-site-verification=IT9U2rOS45RPU4SahdQirbmjpGxqlIDq2WZX4NDmwSs google-site-verification=QTcEoV1p6n5Wlr0HAHzEe5RBESSyKsi_fWsLRYGwOPo google-site-verification=QkSu5Qzm3bnrSyy0MRphM8GB8wL3gbISeqrGOwnV0h8 google-site-verification=VYcubAv9DhS-FXW62xNkvua2iyEN-0SfyyY7xP47Zw4 google-site-verification=ZEAcwPyVJrLK8UiyTfLALfAb3RtGeKMm9GHQf62PROk google-site-verification=d-LV6kMUE24jvMMrtDY8uzCXNhljPeWP4pho55cHBuE google-site-verification=mOSvNFm6z5fqbFkSxjQly5TWxPyScSXCEdSXSur_Siw lyb8vwnk417tpq35llqvmnkt5fhgrvtk notion-domain-verification=h4Hv4k0X4eQZsSUGQGXLDeJTULRMzfxchQE9lZEv8df rippling-domain-verification=96f39fac3e0393f3 status-page-domain-verification=l8kq9jjk7nvg uber-domain-verification=ce94fe1c-f3e0-4dc4-8497-0880cb913fa8 SPF v=spf1 include:_spf.google.com include:mg-spf.greenhouse.io include:stspg-custom... zapier-domain-verification-challenge=8cf9e29c-60c9-4452-a2db-9a86307fdbe3 |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 169 ms totalPASS
https://branch.io
18 ms · HTTP/1.1
https://www.branch.io/
151 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://branch.io | 301 | 18 ms | HTTP/1.1 | AmazonS3 |
| 2 | https://www.branch.io/ | 200 | 151 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 8 URLsPASS
# ======================================================
# robots.txt for Branch.io
# ======================================================
# Default policy
User-agent: *
Allow: /
# -----------------------------
# Explicit ALLOW for AI/LLM crawlers
# -----------------------------
User-agent: GPTBot
Allow: /
User-agent: CCBot
Allow: /
User-agent: Google-Extended
Allow: /
User-agent: PerplexityBot
Allow: /
User-agent: ClaudeBot
Allow: /
User-agent: anthropic-ai
Allow: /
User-agent: Applebot-Extended
Allow: /
# -----------------------------
# Crawl hygiene (limit noisy URLs)
# -----------------------------
# Common tracking parameters
Disallow: /*utm_
Disallow: /*gclid=
Disallow: /*fbclid=
Disallow: /*msclkid=
Disallow: /*ref=
# Additional query params / WP patterns
Disallow: /*?currency=
Disallow: /*?page_id=
Disallow: /*?wvideo=
Disallow: /*?p=
Disallow: /*?amp
# WP endpoints - Security: Block REST API discovery
Disallow: /wp-json/
# Deep link/debug parameters that create infinite combinations
Disallow: /*&deeplink_path
Disallow: /*&branch
# Internal assets that don't need indexing
Disallow: /assets/
Disallow: /scripts/
# -----------------------------
# Security: Block sensitive paths
# -----------------------------
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/plugins/
Disallow: /wp-content/themes/*/assets/
Disallow: /*.php$
Disallow: /xmlrpc.php
Disallow: /wp-trackback.php
Disallow: /wp-cron.php
Disallow: /readme.html
Disallow: /license.txt
# Allow specific needed paths
Allow: /wp-admin/admin-ajax.php
Allow: /wp-content/uploads/
# -----------------------------
# Sitemaps (production)
# Yoast sitemap index links to all section sitemaps
# -----------------------------
Sitemap: https://www.branch.io/sitemap_index.xml
- https://www.branch.io/post-sitemap.xml
- https://www.branch.io/post-sitemap2.xml
- https://www.branch.io/page-sitemap.xml
- https://www.branch.io/events-sitemap.xml
- https://www.branch.io/glossary-sitemap.x...
- https://www.branch.io/basic-page-sitemap...
- https://www.branch.io/branch_author-site...
- https://www.branch.io/category-sitemap.x...
A+Domain Intelligencebranch.io — via Gandi SAS, 14 years, 7 months oldPASS
148 days
November 10, 2026
126 days
Issued by Amazon
14 years, 7 months
Registered November 10, 2011
Status unknown
Protects against DNS spoofing
Unknown
2600:9000:2394:c600:e:6c93:2e80:93a1
Gandi SAS
Expiry timeline
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.
Source: ICANN / domain-security best practice