Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FIPv6 ReadinessActionIPv6 records exist but unreachableFIX
Having AAAA records but an unreachable server is worse than no AAAA — clients may experience delays before falling back to IPv4.
Advertising IPv6 (AAAA records) without a reachable server means IPv6-preferring clients silently fail every connection.
Learn more ▾ ▴
Modern browsers prefer IPv6 if AAAA exists (Happy Eyeballs algorithm). If the IPv6 server isn't reachable, browsers fall back to IPv4 — but with seconds of added latency per request. Either fix IPv6 reachability or remove the AAAA records.
Source: RFC 8305 (Happy Eyeballs)
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BRedirect Chain1 redirect(s), 1020 ms totalREVIEW
https://citrix.com
967 ms · HTTP/1.1
https://www.citrix.com/
53 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://citrix.com | 301 | 967 ms | HTTP/1.1 | nginx/1.21.0 |
| 2 | https://www.citrix.com/ | 200 | 53 ms | HTTP/1.1 | Apache |
See the visual redirect chain in the HTTP Probe tab →
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BHTTP Probe TimingTotal 1025 ms — DNS, TCP, TLS, TTFB, content transfer breakdownREVIEW
Connection waterfall
BTLS Certificate Expiry & Recommendations105 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 10 ms lookupPASS
| A | 54.86.126.30 |
| AAAA | 2001:4868:10c:3::15 |
| CNAME | — |
| NS | nick.ns.cloudflare.com, nucum.ns.cloudflare.com |
| MX | 10 citrix-com.mail.protection.outlook.com |
| TXT | 2t6gy0q499y96q28b0z5mnhtlks21rdd 3t5bM076VhqoBQm0/iivRXpZWa6LpjLD8EFZCibjtEkr/dxH+cgwn0DQdbO20cYlWA36lpfLCHuWT/Zn... 6e27d61c798a415a9254eedf47663922 Dynatrace-site-verification=32879264-2121-4161-a859-b13d10bb2502__duiqao3ktk2ins... Dynatrace-site-verification=710e7769-2992-45d3-a823-7e0226503a22__12l0u0ber39sb0... MS=36A460148583A60833119892ABAB4079FDF86E47 MS=ms54920430 MS=ms68893011 _5vjloo5rruthg6a1s7a57tv0zc0c94g _7lgmmwvxfs1icnbx1juhqfzsv71v634 _d6nbs1s3970i4oq5co9s131qoy6sb4k _glr6aa90jm59t3ej0zsk6aso27xgrka _j1mb27jibc18zjp1p1vrhihsiwaoi5g _o3skw3we74rpkyulzn53mwku7o2w56n _thd3wsj9d2fqawbcdgzuuc7o7bi1h2i adobe-idp-site-verification=013ec935de02014472e246efd3805b6d350feb7a6f13449b6be6... adobe-idp-site-verification=b88397f8e98f219f8160f9bdb854fa0695a0c3efab9c22925369... amazonses:E7SQiLGGpJUHZpsneQqzDqmNKue1IEVZdb1rENEi/Dg= apple-domain-verification=ET6dk0ADDepEVntW atlassian-domain-verification=ShopL09th5Q/UhA16zCVT436T8sB4PJ/vvlRxTvwfwYrGAUvBZ... atlassian-domain-verification=k6qJjBktGNUCqv7cL24iXYl3PRAIKerh6bZc8aqVCbAk2eb0ic... atlassian-domain-verification=pM2zMVF3ilinGRzSJaFrifVDwKNfCc8YKepaMnFRG2pL7hZDOf... atlassian-sending-domain-verification=8e4f414f-ebd4-4bb2-8579-7c28a5ae7a66 canva-site-verification=mBJwllbVUompoPhUPgRwwg docker-verification=c8b61426-355f-406c-848d-a9d0185d3948 drift-domain-verification=5edf4923a7503b0a6fac7ebf6bc74428e5188c6ac6005dcaaab5ef... drift-domain-verification=c286c113164c090e2f69012c3e8010164da9e5978fa3a34a5f0258... dtm-domain-verification=UphS5F_eOHcz2Vh0XMWL2vwxZQ_wJZV90sGqbxWX9Ms fastly-domain-delegation-fddelt741634-2-21-24 google-site-verification=3ecYNAuVuxsdnmhq3Ad62yUTjNyu_zVw2Nis0h2qyzI google-site-verification=ETMql6HI7j-2wO1XJTazSA4dUcdaAW-Sj_o-bKOp-dQ google-site-verification=XIIa__E6cYK3Xakkc5hsDrkK5N5mEUUnJx65DOC_7i0 google-site-verification=bSH0MyYgC2I8yW9EHos2RQz-prfZMhWCRowUKu3pgCM google-site-verification=c7rEgrYXVnflD00b7SleDHUN2kjZtD-OlQ4DIIvJdwg google-site-verification=cGG0r71gpLRXk62j29Uiv86YPEKnvVKk8qlHYkRDt-8 google-site-verification=dDdG0qHwFD3ttQ-m4JRgcRHIHi5TXeyZWSABt9-_y-I google-site-verification=jXyXsHF5vk-RhTtsKHf2YiDoNTVmQhneJbrTsfJSBcA google-site-verification=lEvhlUkj6N0fViKKFL3vVrn32UD5QgF6K_ra8o2GfmY google-site-verification=qbd0uPFSUTQ3x_NNe-XCYTEdJcTB6deO3en9M7aLHdY google-site-verification=s3thrxQvgyMbkT53Ccnx8Jkfp8spWJoF9nQ2TfZuLSQ intersight=fbbc4e248c148b5d80a326da53022fdfcded163999ceaec6165a3973462a8afb logmein-verification-code=34ca51fb-c701-459e-b60c-d266aa0b06ef logmein-verification-code=c0b03e33-2d52-49d5-aef5-3a76dc891290 lucid-verification=qe15rgfgj93635Klpky491 miro-verification=b7c7869613661d321b9662b83c6463432f5e9c40 mongodb-site-verification=SamQU8vXenVX25pDkz4E8A71b38JNKqg mongodb-site-verification=asLRxyuY2hcOZHP9AEfjFett97gNq0TW mongodb-site-verification=jBiX7xzjOVLN7kwQfpqZ8kfQjB3MxXFt mpsfzpwyj351cdlsfxq70rqlc1b3881b onetrust-domain-verification=26961e9a8c964a7e8ac78900461bc12c pexip-ms-tenant-domain-verification=e80b8b84-73b5-4b34-9123-c60ecb37a68a t2jcU7Uk003UBKV3zfl0 SPF v=spf1 include:spf.citrix.com include:spf2.citrix.com include:_spf.google.com in... wiz-domain-verification=7c47753d31ab194423d6ca83573012e4140e16cd5539e71a3fa46156... wrike-verification=NDYxMTI0MTo0YWM2ZDkyMjhiNzFjYjVkYTJkNWUyOWZlOGZmNTZmZDFlNzRkZ... wrike-verification=NTAxMzcxNDpjMjRkNzkxNzZkNjFhNzVmZDBlNjczZDhkYTc4MDhjNmM0Y2QzM... xdzkgym5phfnptplvzjm88vym4mhvpp3 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 2 URLsPASS
User-agent: *
Sitemap: https://www.citrix.com/sitemap-index.xml
Sitemap: https://www.citrix.com/blogs/sitemap.xml
Disallow: /go/private
Disallow: /cgi-bin/
Disallow: /account
Disallow: /partnercentral
Disallow: /content/campaigns
Disallow: /404.html
Disallow: /no_access
Disallow: /welcome/embargoed-country.html
Disallow: /toolbox-outage
Disallow: /*.print.html
Disallow: /glossary/akamaitest.html
Disallow: /blogs/category
Disallow: /blogs/product
Disallow: /blogs/author
Disallow: /blogs/tag
Disallow: /static
Disallow: /blogs/2006/
Disallow: /blogs/2007/
Disallow: /blogs/2008/
Disallow: /blogs/2009/
Disallow: /blogs/2010/
Disallow: /blogs/2011/
Disallow: /*/go/private
Disallow: /*/cgi-bin/
Disallow: /*/account
Disallow: /*/partnercentral
Disallow: /*/content/campaigns
Disallow: /*/404.html
Disallow: /*/no_access
Disallow: /*/welcome/embargoed-country.html
Disallow: /*/toolbox-outage
Disallow: /*/*.print.html
Disallow: /*/glossary/akamaitest.html
Disallow: /*/static
A+Domain Intelligencecitrix.com — via MarkMonitor Inc., 32 years, 2 months oldPASS
400 days
July 21, 2027
105 days
Issued by DigiCert Inc
32 years, 2 months
Registered July 22, 1994
Not enabled
Protects against DNS spoofing
Unknown
2001:4868:10c:3::15
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice