Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations48 days until leaf cert expires — 5 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 15 ms lookupPASS
| A | 104.18.17.245, 104.18.16.245 |
| AAAA | 2606:4700::6812:11f5, 2606:4700::6812:10f5 |
| CNAME | — |
| NS | mark.ns.cloudflare.com, teresa.ns.cloudflare.com |
| MX | 10 us-smtp-inbound-1.mimecast.com 10 us-smtp-inbound-2.mimecast.com |
| TXT | 1password-site-verification=AZOWWSUYOZCWXG6UUG7WAQWA4U a1bkm21a0343ouieme7pbrg2r8 amazon-business-verification=953565c57e806341c014daa53e6fac51ec5d1c29fdb114ad88f... atlassian-domain-verification=zhDn2KozeCnMHrcLEOE/3lG1ty3CpGBP5gyBG0oW5HKsu2C28K... atlassian-sending-domain-verification=1b543096-4bd5-4af7-8ee5-70f29df48256 google-site-verification=20JrKSbXILx_pujtOB7eP_FfSVrylzvsuu3giMC9380 google-site-verification=A2_NoVRNY7GA1ily63C0aTtx-gEBP6NMwsoQxi8SUd4 google-site-verification=Nr0LmdfCeLa6WHsh5HELTAEJH5caavfWKZnZ42leBPY google-site-verification=hrjqf-8rXSNynxTAx-DPtv0ljrcaVIi02Vee-U4nWhw jeMK/22w1ql1SgC/mpYsUKvIql3N7Q2hpdc5isxAkJU= sdc96gonucv2en69kib37cgt39 srvj8psoiniu90qg7rpig71rc9 v0lg2lh3povkbjv93llbmokpu0 SPF v=spf1 ip4:68.233.76.14 ip4:68.233.76.24 ip4:68.233.77.20 ip4:160.34.72.28 ip4:1... xMESo9uRWx9s+apgqwB8yHDOWoyM5ol16dPim8yI0OTawTOV8Le/gzI+Xrr9moXO9eCxatx6B07acQMf... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://diabetes.org
296 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://diabetes.org | 200 | 296 ms | HTTP/1.1 | cloudflare |
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 2 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
# As a condition of accessing this website, you agree to abide by the following
# content signals:
# (a) If a Content-Signal = yes, you may collect content for the corresponding
# use.
# (b) If a Content-Signal = no, you may not collect content for the
# corresponding use.
# (c) If the website operator does not include a Content-Signal for a
# corresponding use, the website operator neither grants nor restricts
# permission via Content-Signal with respect to the corresponding use.
# The content signals and their meanings are:
# search: building a search index and providing search results (e.g., returning
# hyperlinks and short excerpts from your website's contents). Search does not
# include providing AI-generated search summaries.
# ai-input: inputting content into one or more AI models (e.g., retrieval
# augmented generation, grounding, or other real-time taking of content for
# generative AI search answers).
# ai-train: training or fine-tuning AI models.
# ANY RESTRICTIONS EXPRESSED VIA CONTENT SIGNALS ARE EXPRESS RESERVATIONS OF
# RIGHTS UNDER ARTICLE 4 OF THE EUROPEAN UNION DIRECTIVE 2019/790 ON COPYRIGHT
# AND RELATED RIGHTS IN THE DIGITAL SINGLE MARKET.
# BEGIN Cloudflare Managed content
User-agent: *
Content-Signal: search=yes,ai-train=no
Allow: /
User-agent: Amazonbot
Disallow: /
User-agent: Applebot-Extended
Disallow: /
User-agent: Bytespider
Disallow: /
User-agent: CCBot
Disallow: /
User-agent: ClaudeBot
Disallow: /
User-agent: CloudflareBrowserRenderingCrawler
Disallow: /
User-agent: Google-Extended
Disallow: /
User-agent: GPTBot
Disallow: /
User-agent: meta-externalagent
Disallow: /
# END Cloudflare Managed Content
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: *
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /README.md
Disallow: /composer/Metapackage/README.txt
Disallow: /composer/Plugin/ProjectMessage/README.md
Disallow: /composer/Plugin/Scaffold/README.md
Disallow: /composer/Plugin/VendorHardening/README.txt
Disallow: /composer/Template/README.txt
Disallow: /modules/README.txt
Disallow: /sites/README.txt
Disallow: /themes/README.txt
Disallow: /web.config
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /search/
Disallow: /user/register
Disallow: /user/password
Disallow: /user/login
Disallow: /user/logout
Disallow: /media/oembed
Disallow: /*/media/oembed
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password
Disallow: /index.php/user/register
Disallow: /index.php/user/login
Disallow: /index.php/user/logout
Disallow: /index.php/media/oembed
Disallow: /index.php/*/media/oembed
# Paths (query parameter)
Disallow: /*?ada_source=*
Disallow: /?amp;ada_sub_source
Disallow: /?amp;autologin
Disallow: /?amp;field_event_date_and_time_month
Disallow: /?amp;field_event_type_exclude[0]
Disallow: /?amp;field_event_type_target_id
Disallow: /?amp;form
Disallow: /?amp;loc
Disallow: /?amp;page
Disallow: /?amp;recurring
Disallow: /?amp;s_src
Disallow: /?amp;s_subsrc
Disallow: /?autologin
Disallow: /?field_address_administrative_area
Disallow: /?field_event_type_exclude[0]
Disallow: /?field_event_type_target_id
Disallow: /?form
Disallow: /?loc
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
AHTTP Probe TimingTotal 585 ms — DNS, TCP, TLS, TTFB, content transfer breakdownPASS
Connection waterfall
ACDN & DeliveryCloudflare (DYNAMIC)PASS
Domain IntelligenceDomain intelligence data not availableINFO
RDAP and WHOIS lookup both failed