Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations52 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Submit your domain to hstspreload.org to be added to the Chrome preload list
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 93 ms lookupPASS
| A | 104.18.16.121, 104.18.17.121 |
| AAAA | 2606:4700::6812:1079, 2606:4700::6812:1179 |
| CNAME | — |
| NS | blue.foundationdns.com, blue.foundationdns.org, blue.foundationdns.net |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt3.aspmx.l.google.com 10 alt4.aspmx.l.google.com |
| TXT | _d8p2p9hgu78wb6fy5stwp2jf40c354n apple-domain-verification=8EoyvQyJIceLglnq _pgk3k2yr97hvbf7w3o9qxus3pj3uxcw 1s42oe9n58ab4ps3tmu2uofkug e50d3481-f9d2-418f-a1b0-84357cfb3821 MS=ms52844045 hm2p68oulrkgak07a9s8shfa1m amazonses:CWGOT7xXPyMAccMHf5UAohZVVsLKcpnMy8FwubU5tTo= google-site-verification=yUBWxOT8T3y3vD7A3AxjO32Q3v9EO_xu3-GqKvezCCQ apple-domain-verification=qehbAcRasawPmxaG SPF v=spf1 include:_spf.google.com ip4:74.209.171.228 ip4:167.102.227.55 ip4:167.102... ap1sfok8ddjvlgq3hsuv8m14hl cisco-ci-domain-verification=157d923f08108c249ab9cb2d1de32beae5e52f2c34c0d23cd42... fsq7vdjvjsn1v09j3h8svv1lum airtable-verification=b849bf00d85c8baabf2b9b0e3655c563 oSR1/kmdm8TR3vpGWzxgEpt8oOFZkPGlC2wjt7Ybw1E== apple-domain-verification=xNlvomDx4dC0dNDI atlassian-domain-verification=i4hEgIkmSVTTaaoptCaJ4keQBOWnkxE8HVeYclacYzAr4Jiiwp... ssndk6q987ggngd3kalgn0ranl dyrwv6t5cpmtzvxll9r7m58cbt985388 atlassian-domain-verification=nGLmLPKyn5LdtV7eBT5u7SwQviNLVpsT75z7arG6e7DEZncEFG... 2ad6cb3dph39b5drtca9cnm90m MS=ms32684192 kgm9vvvlj9cpqd6sf7lrh23r8 globalsign-domain-verification=6E30CB918CD54CAF70EB0D3DAD1F75E1 cisco-ci-domain-verification=120969b94f738685bcd2728bdd9e16994f09f4d8ffef15dbfab... jm6577bftq415t92lgme0dcqr6 RjbxrG0TwsmqzyqmOHbmqs5C66N6m6U google-site-verification=lY08FXmA_zKrp3COIjiThg38LbuK1WeBT_GBs9deM_4 h82honea1tffnk5sim89c5rre5 MS=ms80162997 amazonses:4di2e8L8lnXTZ44TFZ3ofbd7eklIRekz1DcZP03o3Zg= q5vpetdcqofag3jt7pnq0uohhu apple-domain-verification=sZH9-ls4ZFr4UCysr_cmO1NjJZGGtw5BPLeBNSsTkH0 wiz-domain-verification=39cbff0755600ef21b10a93eceb205a7f025ce8dfa31715ea652d7b7... 1lhvo5shit1vji0gjnm6b5m0dg google-site-verification=i6WrFKXFG2a2A49lE_zbAWMauAAURsLvjyUE6F3Esrs Dynatrace-site-verification=e719ee20-de24-4ec1-8190-7c89d0b6b867__t1fhb1s1aav4v6... duo_sso_verification=zv73ztiv9HdXVpph7qtD9S6xGTqLhx8puCzpH8B60XNDAmP7K1ZHha5lQk7... _gax7s8ppaf7cfvu9zmn0ovr09crvssb epfu5gd4i2bu0otqk34oa7kq82 lm9mq09ep938cj2llme52igmut gpmwdejan2q63ik7qdklosx6q67bmkgj._domainkey.maryland.gov MS=ms714B16 bew2vq0bfq8cg5d6rqz8v4g7zp5k5qbqb3 duo_sso_verification=DNoxG9J5Sa1divWb53oRX8uu8O6glVgHm3zd6QqldSqHqogoespNLgk4ZvH... docusign=42a7eaa9-d58f-4277-afed-5358f6bbedd8 i7ep3fu81c66tcvjd65fautveq mu1cgtge26k0qovsglbpohm8oe apple-domain-verification=2ACZ979RxLQOUvfy _7aze2dcrdwsvjiaeguuni8qw6byfk0o |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 523 ms totalPASS
https://maryland.gov
59 ms · HTTP/1.1
https://www.maryland.gov/
464 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://maryland.gov | 301 | 59 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.maryland.gov/ | 200 | 464 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 53 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: *
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /README.md
Disallow: /composer/Metapackage/README.txt
Disallow: /composer/Plugin/ProjectMessage/README.md
Disallow: /composer/Plugin/Scaffold/README.md
Disallow: /composer/Plugin/VendorHardening/README.txt
Disallow: /composer/Template/README.txt
Disallow: /modules/README.txt
Disallow: /sites/README.txt
Disallow: /themes/README.txt
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /search/
Disallow: /user/register
Disallow: /user/password
Disallow: /user/login
Disallow: /user/logout
Disallow: /media/oembed
Disallow: /*/media/oembed
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password
Disallow: /index.php/user/register
Disallow: /index.php/user/login
Disallow: /index.php/user/logout
Disallow: /index.php/media/oembed
Disallow: /index.php/*/media/oembed
A+Domain Intelligencemaryland.gov — via get.gov, 26 years, 10 months oldPASS
63 days
August 18, 2026
52 days
Issued by Let's Encrypt
26 years, 10 months
Registered October 14, 1999
Enabled
Protects against DNS spoofing
Unknown
2606:4700::6812:1179
get.gov
Expiry timeline
Recommended actions
- Renew the domain or enable auto-renewal to prevent accidental expiry
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice