Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BDNSSECUnsigned (DNSSEC not deployed)REVIEW
BCAA RecordsNo CAA records (any CA may issue certificates)REVIEW
CReverse DNSAction0/6 IPs match cert SANREVIEW
BTLS Certificate Expiry & Recommendations82 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BOperational Status PageNo status page link detectedREVIEW
ADNS Records3 A records, 81 ms lookupPASS
| A | 104.26.4.82, 104.26.5.82, 172.67.69.252 |
| AAAA | 2606:4700:20::681a:552, 2606:4700:20::681a:452, 2606:4700:20::ac43:45fc |
| CNAME | — |
| NS | — |
| MX | — |
| TXT | — |
| CAA | Lookup not available with standard resolver |
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.
Learn more ▾ ▴
SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.
Source: RFC 7208 (SPF)
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
A+Multi-Resolver DNS SpeedMean 25ms across 3 resolvers (spread 3ms)PASS
ARedirect Chain1 redirect(s), 226 ms totalPASS
https://app.glaido.com
137 ms · HTTP/1.1
https://app.glaido.com/login?next=%2F
89 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://app.glaido.com | 307 | 137 ms | HTTP/1.1 | cloudflare |
| 2 | https://app.glaido.com/login?next=%2F | 200 | 89 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
ACrawlabilityrobots.txt present, sitemap with 0 URLsPASS
An empty sitemap provides no value. Add <url> entries for your pages.
An empty sitemap signals 'no content to index' to Google — actively harmful versus having no sitemap at all.
Learn more ▾ ▴
Google compares URLs in the sitemap against URLs it has crawled. An empty sitemap on a site with thousands of pages signals abandonment. Either populate it correctly (most CMSes auto-generate) or delete the file and let Google crawl normally.
Source: Google Search Central / sitemaps.org
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
<!DOCTYPE html><!--JZB_M0ULBUq4OAN8WRqlP--><html lang="en"><head><meta charSet="utf-8"/><meta name="viewport" content="width=device-width, initial-scale=1"/><link rel="stylesheet" href="/_next/static/css/653e28f522207d27.css" data-precedence="next"/><link rel="preload" as="script" fetchPriority="low" href="/_next/static/chunks/webpack-2362db2b61322c96.js"/><script src="/_next/static/chunks/4bd1b696-c023c6e3521b1417.js" async=""></script><script src="/_next/static/chunks/493-b04f35346e51d523.js" async=""></script><script src="/_next/static/chunks/main-app-207b798bdc69d2ae.js" async=""></script><script src="/_next/static/chunks/394382b4-b2f938193c4dfaf5.js" async=""></script><script src="/_next/static/chunks/870-3853003e13dc86b3.js" async=""></script><script src="/_next/static/chunks/288-2124b0e1365bdac3.js" async=""></script><script src="/_next/static/chunks/421-bc0264e537527f53.js" async=""></script><script src="/_next/static/chunks/678-5066d3433fcfdd2f.js" async=""></script><script src="/_next/static/chunks/899-53b2e946a219fbd6.js" async=""></script><script src="/_next/static/chunks/app/layout-0cf1b0dce58901cc.js" async=""></script><script src="/_next/static/chunks/app/(auth-callback)/layout-fe69e83e8d7076d9.js" async=""></script><script src="/_next/static/chunks/560-b5ccc073f7dc1175.js" async=""></script><script src="/_next/static/chunks/app/(auth)/login/page-138f24c2f34a4780.js" async=""></script><title>Sign In - Glaido</title><meta name="description" content="Dictation app"/><link rel="icon" href="/images/favicon/favicon.svg"/><script>
(() => {
try {
const stored = localStorage.getItem('glaido:appearance');
const preference = stored === 'light' || stored === 'dark' || stored === 'system'
? stored
: 'dark';
const systemPrefersDark = window.matchMedia('(prefers-color-scheme: dark)').matches;
const theme = preference === 'system'
? (systemPrefersDark ? 'dark' : 'light')
: preference;
document.documentElement.setAttribute('data-theme', theme);
} catch {
document.documentElement.setAttribute('data-theme', 'dark');
}
})();
</script><script src="/_next/static/chunks/polyfills-42372ed130431b0a.js" noModule=""></script></head><body class="min-h-screen font-sans antialiased"><div hidden=""><!--$--><!--/$--></div><script src="/_next/static/chunks/webpack-2362db2b61322c96.js" id="_R_" async=""></script><script>(self.__next_f=self.__next_f||[]).push([0])</script><script>self.__next_f.push([1,"1:\"$Sreact.fragment\"\n2:I[3434,[\"484\",\"static/chunks/394382b4-b2f938193c4dfaf5.js\",\"870\",\"static/chunks/870-3853003e13dc86b3.js\",\"288\",\"static/chunks/288-2124b0e1365bdac3.js\",\"421\",\"static/chunks/421-bc0264e537527f53.js\",\"678\",\"static/chunks/678-5066d3433fcfdd2f.js\",\"899\",\"static/chunks/899-53b2e946a219fbd6.js\",\"177\",\"static/chunks/app/layout-0cf1b0dce58901cc.js\"],\"Providers\",1]\n3:I[1776,[\"484\",\"static/chunks/394382b4-b2f938193c4dfaf5.js\",\"870\",\"static/chunks/870-3853003e13dc86b3.js\",\"288\",\"static/chunks/288-2124b0e1365bdac3.js\",\"421\",\"static/chunks/421-bc0264e537527f53.js\",\"678\",\"static/chunks/678-5066d3433fcfdd2f.js\",\"899\",\"static/chunks/899-53b2e946a219fbd6.js\",\"177\",\"static/chunks/app/layout-0cf1b0dce58901cc.js\"],\"CookieConsentManager\"]\n4:I[9766,[],\"\"]\n5:I[8924,[],\"\"]\n6:I[1061,[\"870\",\"static/chunks/870-3853003e13dc86b3.js\",\"288\",\"static/chunks/288-2124b0e1365bdac3.js\",\"678\",\"static/chunks/678-5066d3433fcfdd2f.js\",\"899\",\"static/chunks/899-53b2e946a219fbd6.js\",\"475\",\"static/chunks/app/(auth-callback)/layout-fe69e83e8d7076d9.js\"],\"PublicRoute\"]\n12:I[7150,[],\"\"]\n:HL[\"/_next/static/css/653e28f522207d27.css\",\"style\"]\n"])</script><script>self.__next_f.push([1,"0:{\"P\":null,\"b\":\"JZB_M0ULBUq4OAN8WRqlP\",\"p\":\"\",\"c\":[\"\",\"login\"],\"i\":false,\"f\":[[[\"\",{\"children\":[\"(auth)\",{\"children\":[\"login\",{\"children\":[\"__PAGE__\",{}]}]}]},\"$undefined\",\"$undefined\",true],[\"\",[\"$\",\"$1\",\"c\",{\"children\":[[[\"$\",\"link\",\"0\",{\"rel\":\"stylesheet\",\"href\":\"/_next/static/css/653e28f522207d27.css\",\"precedence\":\"next\",\"crossOrigin\":\"$undefined\",\"nonce\":\"$undefined\"}]],[\"$\",\"html\",null,{\"lang\":\"en\",\"suppressHydrationWarning\":true,\"children\":[[\"$\",\"head\",null,{\"children\":[\"$\",\"script\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"\\n (() =\u003e {\\n try {\\n const stored = localStorage.getItem('glaido:appearance');\\n const preference = stored === 'light' || stored === 'dark' || stored === 'system'\\n ? stored\\n : 'dark';\\n const systemPrefersDark = window.matchMedia('(prefers-color-scheme: dark)').matches;\\n const theme = preference === 'system'\\n ? (systemPrefersDark ? 'dark' : 'light')\\n : preference;\\n document.documentElement.setAttribute('data-theme', theme);\\n } catch {\\n document.documentElement.setAttribute('data-theme', 'dark');\\n }\\n })();\\n\"}}]}],[\"$\",\"body\",null,{\"className\":\"min-h-screen font-sans antialiased\",\"children\":[\"$\",\"$L2\",null,{\"children\":[[\"$\",\"$L3\",null,{\"dubReferDomain\":\"get.glaido.com\"}],[\"$\",\"$L4\",null,{\"parallelRouterKey\":\"children\",\"error\":\"$undefined\",\"errorStyles\":\"$undefined\",\"errorScripts\":\"$undefined\",\"template\":[\"$\",\"$L5\",null,{}],\"templateStyles\":\"$undefined\",\"templateScripts\":\"$undefined\",\"notFound\":[[[\"$\",\"title\",null,{\"children\":\"404: This page could not be found.\"}],[\"$\",\"div\",null,{\"style\":{\"fontFamily\":\"system-ui,\\\"Segoe UI\\\",Roboto,Helvetica,Arial,sans-serif,\\\"Apple Color Emoji\\\",\\\"Segoe UI Emoji\\\"\",\"height\":\"100vh\",\"textAlign\":\"center\",\"display\":\"flex\",\"flexDirection\":\"column\",\"alignItems\":\"center\",\"justifyContent\":\"center\"},\"children\":[\"$\",\"div\",null,{\"children\":[[\"$\",\"style\",null,{\"dangerouslySetInnerHTML\":{\"__html\":\"body{color:#000;background:#fff;margin:0}.next-error-h1{border-right:1px solid rgba(0,0,0,.3)}@media (prefers-color-scheme:dark){body{color:#fff;background:#000}.next-error-h1{border-right:1px solid rgba(255,255,255,.3)}}\"}}],[\"$\",\"h1\",null,{\"className\":\"next-error-h1\",\"style\":{\"display\":\"inline-block\",\"margin\":\"0 20px 0 0\",\"padding\":\"0 23px 0 0\",\"fontSize\":24,\"fontWeight\":500,\"verticalAlign\":\"top\",\"lineHeight\":\"49px\"},\"children\":404}],[\"$\",\"div\",null,{\"style\":{\"display\":\"inline-block\"},\"children\":[\"$\",\"h2\",null,{\"style\":{\"fontSize\":14,\"fontWeight\":400,\"lineHeight\":\"49px\",\"margin\":0},\"children\":\"This page could not be found.\"}]}]]}]}]],[]],\"forbidden\":\"$undefined\",\"unauthorized\":\"$undefined\"}]]}]}]]}]]}],{\"children\":[\"(auth)\",[\"$\",\"$1\",\"c\",{\"children\":[null,[\"$\",\"$L6\",null,{\"children\":[\"$\",\"div\",null,{\"className\":\"relative flex min-h-screen flex-col items-center bg-background-primary px-4 pt-[clamp(3rem,15vh,240px)] pb-12 overflow-hidden\",\"children\":[[\"$\",\"div\",null,{\"className\":\"pointer-events-none fixed inset-0 opacity-[0.015]\",\"style\":{\"backgroundImage\":\"linear-gradient(var(--color-border-default) 1px, transparent 1px),\\n linear-gradient(90deg, var(--color-border-default) 1px, transparent 1px)\",\"backgroundSize\":\"64px 64px\"}}],[\"$\",\"svg\",null,{\"viewBox\":\"0 0 561.237 598.876\",\"fill\":\"none\",\"xmlns\":\"http://www.w3.org/2000/svg\",\"className\":\"pointer-events-none fixed top-4 left-4 w-[clamp(280px,30vw,492px)] rotate-180 opacity-[0.08] text-text-default hidden lg:block\",\"children\":[[\"$\",\"svg\",\"0\",{\"x\":392.234,\"y\":2.779,\"width\":\"165\",\"height\":\"177\",\"viewBox\":\"0 0 165 177\",\"children\":[[\"$\",\"path\",null,{\"d\":\"M1.72675 61.2898L61.2899 1.72672C63.5783 -0.561687 67.2727 -0.577523 69.5415 1.69134L83.92 16.0699C86.1889 18.3387 86.1731 22.0331 83.8847 24.3215L23.8135 84.3926C21.9082 86.298 21.7785 89.3364 23.5159 91.366L84.223 152.073C86.4919 154.342 86.476 158.036 84.1876 160.325L69.9443 174.568C67.6559 176.857 63.9615 176.872 61.6926 174.604L1.75577 114.667C-0.513092 112.398 -0.497269 108.703 1.79114 106.415L15.7755 92.4307C18.207 89.9992 18.2238 86.0739 15.8131 83.6633L1.69136 69.5415C-0.577515 67.2726 -0.561661 63.5782 1.72675 61.2898Z\",\"fill\":\"currentColor\"}],\"$L7\"]}],\"$L8\",\"$L9\",\"$La\",\"$Lb\",\"$Lc\"]}],\"$Ld\",\"$Le\"]}]}]]}],{\"children\":[\"login\",\"$Lf\",{\"children\":[\"__PAGE__\",\"$L10\",{},null,false]},null,false]},null,false]},null,false],\"$L11\",false]],\"m\":\"$undefined\",\"G\":[\"$12\",[]],\"s\":false,\"S\":true}\n"])</script><script>self.__next_f.push([1,"13:\"$Sreact.suspense\"\n14:I[4340,[\"484\",\"static/chunks/394382b4-b2f938193c4dfaf5.js\",\"870\",\"static/chunks/870-3853003e13dc86b3.js\",\"288\",\"static/chunks/288-2124b0e1365bdac3.js\",\"560\",\"static/chunks/560-b5ccc073f7dc1175.js\",\"678\",\"static/chunks/678-5066d3433fcfdd2f.js\",\"899\",\"static/chunks/899-53b2e946a219fbd6.js\",\"72\",\"static/chunks/app/(auth)/login/page-138f24c2f34a4780.js\"],\"LoginForm\",1]\n15:I[4431,[],\"OutletBoundary\"]\n17:I[5278,[],\"AsyncMetadataOutlet\"]\n19:I[4431,[],\"ViewportBoundary\"]\n1b:I[4431,[],\"MetadataBoundary\"]\n7:[\"$\",\"path\",null,{\"d\":\"M80.7394 61.2898L140.303 1.72672C142.591 -0.561687 146.285 -0.577523 148.554 1.69134L162.933 16.0699C165.202 18.3387 165.186 22.0331 162.897 24.3215L102.826 84.3926C100.921 86.298 100.791 89.3364 102.529 91.366L163.236 152.073C165.505 154.342 165.489 158.036 163.2 160.325L148.957 174.568C146.669 176.857 142.974 176.872 140.705 174.604L80.7684 114.667C78.4995 112.398 78.5154 108.703 80.8038 106.415L94.7882 92.4307C97.2196 89.9992 97.2364 86.0739 94.8258 83.6633L80.704 69.5415C78.4351 67.2726 78.451 63.5782 80.7394 61.2898Z\",\"fill\":\"currentColor\"}]\n8:[\"$\",\"svg\",\"1\",{\"x\":198.155,\"y\":211.291,\"width\":\"165\",\"height\":\"177\",\"viewBox\":\"0 0 165 177\",\"children\":\"$0:f:0:1:2:children:1:props:children:1:props:children:props:children:1:props:children:0:props:children\"}]\n"])</script><script>self.__next_f.push([1,"9:[\"$\",\"svg\",\"2\",{\"x\":388.158,\"y\":208.512,\"width\":\"174\
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Consistent
A+Domain Intelligenceglaido.com — via NameCheap, Inc., 1 years, 1 months old, hosted on HetznerPASS
323 days
July 15, 2027
82 days
Issued by Google Trust Services
1 years, 1 months
Registered July 15, 2025
Not enabled
Protects against DNS spoofing
Hetzner
ASN AS24940
178.104.128.240
NameCheap, Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice