Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSFIX
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
HTTP version does not redirect to HTTPS
FHTTP Probe TimingActionTotal 7443 ms — DNS, TCP, TLS, TTFB, content transfer breakdownFIX
Connection waterfall
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BCrawlabilityno robots.txt, no sitemapREVIEW
robots.txt is optional but recommended. It tells search engine crawlers which pages to index.
No robots.txt — crawlers fetch /robots.txt and get 404; not breaking but means default crawl behavior with no directives or sitemap reference.
Learn more ▾ ▴
A minimal robots.txt with `User-agent: * / Allow: / / Sitemap: https://example.com/sitemap.xml` covers the basics. Without it, crawlers behave fine but lose the sitemap signal and can't be selectively blocked from crawl-traps.
Source: robotstxt.org
A sitemap helps search engines discover and index your pages more efficiently.
No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.
Learn more ▾ ▴
A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.
Source: sitemaps.org / Google Search Central
No robots.txt found
This is fine for most sites — a missing robots.txt allows all crawling by default.
No sitemap found
Adding a sitemap helps search engines discover your pages.
BTLS Certificate Expiry & Recommendations284 days until leaf cert expires — 5 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records1 A records, 415 ms lookupPASS
| A | 58.33.222.36 |
| AAAA | 2409:871e:8200:2::18b |
| CNAME | — |
| NS | shuni.icbc.com.cn, cns2.icbc.com.cn, bjtns2.icbc.com.cn, tns1.icbc.com.cn, shtns.icbc.com.cn, ns114.icbc.com.cn |
| MX | 10 mx1.icbc.com.cn 50 mx2.icbc.com.cn |
| TXT | VISA=15F6CD154DCAB785AE838EC20216F869 VISA=BC7F45BC1984466755FB14F9866E85FE VISA=E26A19ABE0FB395CA85F5D281BBAE13A google-site-verification=x-q2H2Ym5gS1_IK9QeM7QXRVerEXADbNJQy6DXu13YE SPF v=spf1 include:spf.icbc.com.cn -all mBIpyNzz0UBhvSJFtxJV0orBOLB8cPOw9f+tJyFDGyg= VISA=75E5C925346A58A64508BCDDFFAFC766 d958cjzqdb271t220g37ygdnj69y2wkx 90yc9cth2h0xz51pkmh35y7cblynyq6l lv7zm833snt467vrj11nzmf3gyy0r84q VISA=4619E80F312F5D2471F5304D3C54D6E4 20251014402777197344ed959913336bd20509b47fbd7eb91bfb110220b169f0e11f3a2a89dbfd04 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
A+Redirect ChainNo redirects — direct accessPASS
https://icbc.com.cn
1483 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://icbc.com.cn | 200 | 1483 ms | HTTP/1.1 |
A+IPv6 ReadinessIPv6 reachable (213 ms)PASS
A+Domain Intelligenceicbc.com.cn — via 北京国科云计算技术有限公司(原北京中科三方网络技术有限公司), 24 years, 10 months oldPASS
1219 days
October 17, 2029
284 days
Issued by China Financial Certification Authority
24 years, 10 months
Registered October 17, 2001
Status unknown
Protects against DNS spoofing
Unknown
2409:871e:8200:2::18b
北京国科云计算技术有限公司(原北京中科三方网络技术有限公司)
Expiry timeline
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.
Source: ICANN / domain-security best practice