Skip to content
https://emdad365.ir

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
83
GRADE
B
FIX
2
REVIEW
8
PASS
7
INFO
0
Probed from Amsterdam, Netherlands
200 OK
Checks
17
7 PASS 8 REVIEW 2 FIX
D
Multi-Resolver DNS Speed
Action
Mean 368ms across 3 resolvers (spread 1052ms)
FIX
Mean 368ms across 3 resolvers (spread 1052ms)
Info::
Cloudflare: 1ms
Got: 1ms via 1.1.1.1:53
Info::
Quad9: 50ms
Got: 50ms via 9.9.9.9:53
Info::
Google: 1053ms
Got: 1053ms via 8.8.8.8:53
Info::
High latency spread between resolvers: 1052ms (min 1ms / max 1053ms)
Wide gap between the fastest and slowest public resolver suggests a geographic anycast issue or an authoritative-server cache problem. Users in different regions will see materially different DNS times.
D
CDN & Delivery
Action
No CDN detected
FIX
No CDN detected
Warning::
No CDN detected
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN detected

Consider using a CDN to improve global delivery speed and reduce origin load.

B
DNSSEC
Unsigned (DNSSEC not deployed)
REVIEW
Unsigned (DNSSEC not deployed)
Info::
DNSSEC is not deployed
The zone is not DNSSEC-signed. Users on validating resolvers (Cloudflare 1.1.1.1, Quad9 9.9.9.9, growing default in mobile resolvers) get no protection against DNS spoofing for this domain. Most registrars now offer DNSSEC at a single click; consider enabling it for sites where authenticity matters (banking, healthcare, government).
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
C
Reverse DNS
Action
0/2 IPs match cert SAN
REVIEW
0/2 IPs match cert SAN
Info::
PTR lookup failed for 185.143.233.238: lookup 185.143.233.238: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
Info::
PTR lookup failed for 185.143.234.238: lookup 185.143.234.238: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

C
HTTP Probe Timing
Action
Total 1714 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
REVIEW
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
90 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
8 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
22 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
1.63 s
Total Time Total request time from DNS lookup through full response.
1.71 s

Connection waterfall

DNS Lookup 90 ms TCP Connect 8 ms TLS Handshake 22 ms Server Processing 1.51 s Content Transfer 83 ms
B
TLS Certificate Expiry & Recommendations
76 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

76
days left
0d 30d 60d 90d+

Recommended actions

  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: connection error, /health: connection error, /healthz: connection error, /ping: connection error, /status: connection error.
A
DNS Records
2 A records, 2098 ms lookup
PASS
2 A records, 2098 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 185.143.233.238, 185.143.234.238
Info::
No IPv6 (AAAA) records
Info::
2 nameserver(s) configured
Got: e.ns.arvancdn.ir, w.ns.arvancdn.ir
Info::
No MX records — email not configured via DNS
Info::
No SPF record found in TXT records
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Warning::
DNS resolution is slow (2098 ms)
Slow DNS adds latency to every page load. Consider a faster DNS provider.
Got: 2098 ms
A185.143.233.238, 185.143.234.238
AAAA
CNAME
NSe.ns.arvancdn.ir, w.ns.arvancdn.ir
MX
TXT
google-site-verification=EOi0_lTn4Fe2Plfaub0IPit5ZBQgCKKv6AS4UrCanOI
CAALookup not available with standard resolver
Resolved in 2098 ms

SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.

Why this matters

Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.

Learn more

SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.

Source: RFC 7208 (SPF)

Slow DNS adds latency to every page load. Consider a faster DNS provider.

Why this matters

DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.

Source: DNS performance benchmarks

A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://emdad365.ir

https://emdad365.ir

1006 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://emdad365.ir2001006 msHTTP/1.1ArvanCloud
A+
Crawlability
robots.txt present, sitemap with 4 URLs
PASS
robots.txt present, sitemap with 4 URLs
Info::
robots.txt is present
Got: 115 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 4 entries
Info::
Sitemap index with 4 child sitemaps
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 115 B Sitemaps referenced 1 User-agents * Blocking No — crawling allowed
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php

Sitemap: https://emdad365.ir/sitemap_index.xml

A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
HTTP correctly redirects to HTTPS permanently
Got: HTTP 301

www / non-www

https://www.emdad365.ir/
200https://emdad365.ir/

HTTP → HTTPS

301http://emdad365.ir/ https://emdad365.ir/

Consistent

A+
Domain Intelligence
emdad365.ir — hosted on ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
PASS
emdad365.ir — hosted on ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
Info::
Hosting: ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
Got: AS205585
Domain expiry

Unknown

SSL certificate

76 days

Issued by Let's Encrypt

Domain age

Unknown

DNSSEC

Status unknown

Protects against DNS spoofing

Hosting

ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR

ASN AS205585

185.143.234.238

Registrar

Registrar unknown

Lock status unknown 2 NS records
Expiry timeline
Today
+1 year
SSL expiry Danger zone (≤30 days)
Registrar
Name Servers e.ns.arvancdn.ir, w.ns.arvancdn.ir
Hosting
IP Address 185.143.234.238
ASN AS205585 (ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR)
Provider ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
Data source: whois (1.4s)
A+
CDN Cache Observability
Cache state: BYPASS
PASS
Cache state: BYPASS
Info::
CDN cache state observable via 1 header(s)
Got: x-cache=BYPASS
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback