Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BRedirect Chain1 redirect(s), 1286 ms totalREVIEW
https://heart.org
60 ms · HTTP/1.1
https://www.heart.org/
1226 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://heart.org | 301 | 60 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.heart.org/ | 200 | 1226 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations45 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
ADNS Records2 A records, 686 ms lookupPASS
| A | 104.18.26.158, 104.18.27.158 |
| AAAA | — |
| CNAME | — |
| NS | ns2.heart.org, ns3.heart.org, ns1.heart.org |
| MX | 10 mxb-004ad404.gslb.pphosted.com 10 mxa-004ad404.gslb.pphosted.com |
| TXT | 6b6f456fcdd38625028257d3c5da05c99763350aaf335788e25ab55cf19bae1f pardot_367141_*=3282f7e18b8fb276c10484d6e64943069e1bf4b644c5a45ee2a1ac1179563b70 jamf-site-verification=yfDpd5GCAcpA_OGxg69HBA amazonses:oFOXUa/mJPK9o1aHU8UCnGwHrDlsax73n7f1R5Ru1GM= pardot788973=573c3698502c38becff7f68e601b25dde1ae6a5c4e13567f8b61ac1f1114e93f amazonses:3PjxBfH8x2mjt00HCfj3yreBMgunFmcMdITdJHaJMsw= 91304c6a8883069f8782dae2cb90a46df779c79bf757f98f827a4ebdce2dcfac webexdomainverification.GE1Q=8544d856-25e8-4bd6-8970-2022e2d3f624 mandrill_verify.I_7a_CKUZEWq3TynrtyfGQ vz80hm9q9ywvxl3k7cnq1h06h8m6lkn9 adobe-idp-site-verification=dd453e9b4bcc86b56b4c5affdc4d94e35fa825496b96e7e30a16... zapier-domain-verification-challenge=1d357551-81ba-440c-b06d-ba69803b1aa7 amazonses:VfiqZkP9hhG7win/TuoC8MhmBZUJIbafUqyg/Ri35ds= atlassian-domain-verification=wr0ya0BwFQu8Vgwj4IVqknt0BtdsexjgrzOi7uaJV37FhYfaSY... parsec-domain-verification=td_32QkWnktwYA194SKTNtjSNofBT5 apple-domain-verification=8hFrlvXKt6ptWvva amazonses:Gp8t333monR+Z+pkHmLGNMGIAMiCcgiUF2SvGFID21Y= 2013hywoiu9839t543j0s7543uw1 e2a89ae6f616fd2a14ae3e8599f5b04b1aa5cb259dfa63b8247135cb22bd4bac 5d6034cac0b066309d34a1025c09b4bdf7b401b9c7323babeceb08a7cb1b9552 a158651cd971005b4c5ac1be12717c061e9d680c16520bb84e05cca7fac496b7 onetrust-domain-verification=a10e41a3f7374ac8bbd077607bc1d2a8 eT43WZq3lX0x1cYG1yhc7ovUHMMImOHjqLkhYBrBSEJik9/mik/Yh6DZYIRfV2ntkQocksPYXOF5w59/... adobe-idp-site-verification=17906b455a972ccbb50f29326d331a80903ffaaab5b2685dcd39... canva-site-verification=QHd2W3pEO3lwytLa7tHb5g google-site-verification=jg73xTolmPgO4ftTZbkXbWnzn1XkJhaDNREuc0paTKI SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all d0001f06076ee795fd8f6ed8ee335dbf8a0586ce1398f96d22976496af8321b1 ec2664a9a21fe6ec44ced44ffbf71dc01dc571f43137daa67879ca9c4332b171 google-gws-recovery-domain-verification=52951575 smartsheet-site-validation=NBYCJH_FAkfczv0NWHYCz23BupfUqiP1 _gyhvjv05qtvcoxh3w9w6yuc964rkika google-site-verification=ykIr1-mduZQMgbORca6C0S5AJBCv7W2Jl6iQTgD9iFQ 950be6f0-b621-4a6d-b581-b64e7e3451e7 |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
A+Crawlabilityrobots.txt present, sitemap with 5249 URLsPASS
Sitemap: https://www.heart.org/sitemap.xml
User-agent: *
Disallow: /sitecore
Disallow: /Sitecore
Disallow: /sitecore_files/
Disallow: /sitecore modules/
Disallow: /App_Browsers/
Disallow: /App_config/
Disallow: /App_Data/
Disallow: /temp/
Disallow: /upload/
Disallow: /xsl/
Disallow: /es-es/
Disallow: /es/
A+Domain Intelligenceheart.org — via MarkMonitor Inc., 31 years, 8 months old, hosted on CloudflarePASS
2470 days
March 20, 2033
45 days
Issued by Google Trust Services
31 years, 8 months
Registered January 12, 1995
Not enabled
Protects against DNS spoofing
Cloudflare
ASN AS13335
104.18.26.158
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice