Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations78 days until leaf cert expires — 5 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 53 ms lookupPASS
| A | 104.20.38.152, 172.66.144.156 |
| AAAA | 2606:4700:10::6814:2698, 2606:4700:10::ac42:909c |
| CNAME | — |
| NS | nash.ns.cloudflare.com, betty.ns.cloudflare.com |
| MX | 10 mxa-001d3201.gslb.pphosted.com 10 mxb-001d3201.gslb.pphosted.com |
| TXT | _globalsign-domain-verification=16aKJufSrMKbcCAKCXzVC4PbCHEMl2CuparSiVEdN9 4e2dbbba73fe55027e0330d7d0e11c32cf769de55b398733f3 google-site-verification=noGvImnAKJYNq44dR8narezMMwIXKMv__yHaq8QlYLA google-site-verification=1uYlIYoYVlBwqeuYcddzruxf3Icen-qPAWAlHUfEnRU globalsign-domain-verification=GAw3QxpoQCUd6MEBcIrvwmn1548c2kZ_M8jDU57Ho3 _globalsign-domain-verification=MK_ZKmss4D_DdzGOsssHxxBOK6hJc6LGycFvNOESdZ pardot906722=5c76eff2a274026ec8c83cfa971f37eb156ea74548ee8b1186048651ed388798 openai-domain-verification=dv-s2RpqUJSpTcKGhbw4MJ2BTIJ SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all ZOOM_verify_5zbcWYGbTEOz2WwLUjZPKA apple-domain-verification=REp6ZDBwDrlKlw8T anthropic-domain-verification-qp2z1f=of9b9i88OHTGJgf0mVKf4Lzqw MS=ms43762543 google-site-verification=5cJ3pQgo74dImHbM0TRq32lQt7ug_tiW0X60Zi4KRbQ zoho-verification=zb26035150.zmverify.zoho.com linkedin-site-verification=5099e4a8-a389-477f-bd31-fe4da658edf1 bw=yiKhHuBYK+b62QjIBOX9UagU+YTgVDXLuOH8j1LOdsao |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 179 ms totalPASS
https://csis.org
66 ms · HTTP/1.1
https://www.csis.org/
113 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://csis.org | 301 | 66 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.csis.org/ | 200 | 113 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 21 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: *
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /README.md
Disallow: /composer/Metapackage/README.txt
Disallow: /composer/Plugin/ProjectMessage/README.md
Disallow: /composer/Plugin/Scaffold/README.md
Disallow: /composer/Plugin/VendorHardening/README.txt
Disallow: /composer/Template/README.txt
Disallow: /modules/README.txt
Disallow: /sites/README.txt
Disallow: /themes/README.txt
Disallow: /web.config
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /search/
Disallow: /user/register
Disallow: /user/password
Disallow: /user/login
Disallow: /user/logout
Disallow: /media/oembed
Disallow: /*/media/oembed
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password
Disallow: /index.php/user/register
Disallow: /index.php/user/login
Disallow: /index.php/user/logout
Disallow: /index.php/media/oembed
Disallow: /index.php/*/media/oembed
Allow: /*?page=
Disallow: /search
Disallow: /*?
# Bots
User-agent: Bytespider
Disallow: /
- https://www.csis.org/sitemap.xml?page=1
- https://www.csis.org/sitemap.xml?page=2
- https://www.csis.org/sitemap.xml?page=3
- https://www.csis.org/sitemap.xml?page=4
- https://www.csis.org/sitemap.xml?page=5
- https://www.csis.org/sitemap.xml?page=6
- https://www.csis.org/sitemap.xml?page=7
- https://www.csis.org/sitemap.xml?page=8
- https://www.csis.org/sitemap.xml?page=9
- https://www.csis.org/sitemap.xml?page=10
- https://www.csis.org/sitemap.xml?page=11
- https://www.csis.org/sitemap.xml?page=12
- https://www.csis.org/sitemap.xml?page=13
- https://www.csis.org/sitemap.xml?page=14
- https://www.csis.org/sitemap.xml?page=15
- https://www.csis.org/sitemap.xml?page=16
- https://www.csis.org/sitemap.xml?page=17
- https://www.csis.org/sitemap.xml?page=18
- https://www.csis.org/sitemap.xml?page=19
- https://www.csis.org/sitemap.xml?page=20
- https://www.csis.org/sitemap.xml?page=21
A+HTTP Probe TimingTotal 100 ms — DNS, TCP, TLS, TTFB, content transfer breakdownPASS
Connection waterfall
A+CDN & DeliveryCloudflare (HIT)PASS
Domain IntelligenceDomain intelligence data not availableINFO
RDAP and WHOIS lookup both failed