Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BTLS Certificate Expiry & Recommendations85 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 110 ms lookupPASS
| A | 216.239.36.21, 216.239.32.21, 216.239.34.21, 216.239.38.21 |
| AAAA | 2001:4860:4802:34::15, 2001:4860:4802:38::15, 2001:4860:4802:36::15, 2001:4860:4802:32::15 |
| CNAME | — |
| NS | ns3.google.com, ns1.google.com, ns4.google.com, ns2.google.com |
| MX | 0 smtp.google.com |
| TXT | — |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.
Learn more ▾ ▴
SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.
Source: RFC 7208 (SPF)
ARedirect Chain1 redirect(s), 708 ms totalPASS
https://material.io
357 ms · HTTP/1.1
https://m3.material.io/
351 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://material.io | 301 | 357 ms | HTTP/1.1 | Google Frontend |
| 2 | https://m3.material.io/ | 200 | 351 ms | HTTP/1.1 | Google Frontend |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (2 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 372 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
User-agent: * Disallow: /archive Disallow: /search.html
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencematerial.io — via MarkMonitor Inc., 12 years, 8 months oldPASS
110 days
October 4, 2026
85 days
Issued by Google Trust Services
12 years, 8 months
Registered October 4, 2013
Status unknown
Protects against DNS spoofing
Unknown
2001:4860:4802:34::15
MarkMonitor Inc.
Expiry timeline
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.
Source: ICANN / domain-security best practice