Skip to content
https://pa.gov

Infrastructure

· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
80
GRADE
B
FIX
0
REVIEW
5
PASS
4
INFO
0
Probed from Madrid, Spain
308 Permanent Redirect
Checks
9
4 PASS 5 REVIEW
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
Crawlability
robots.txt present, sitemap with 27019 URLs
REVIEW
robots.txt present, sitemap with 27019 URLs
Info::
robots.txt is present
Got: 281 bytes
Info::
sitemap.xml is present
Warning::
sitemap.xml contains invalid XML
Search engines may not be able to parse the sitemap. Fix XML validation errors.
Info::
sitemap.xml contains 27019 entries
Info::
robots.txt references sitemap

Search engines may not be able to parse the sitemap. Fix XML validation errors.

Why this matters

An unparseable sitemap is silently ignored by Google — the URLs it advertises are never queued for crawl.

Learn more

Google's sitemap parser is strict about XML validity. A single unescaped `&` or unclosed tag invalidates the whole file. Run your sitemap through a validator (Search Console's Sitemaps report flags it) and fix the offending entry. Most generators escape correctly; mistakes usually come from manually-written entries.

Source: sitemaps.org / Google Search Central

robots.txt 200 OK
Size 281 B Sitemaps referenced 2 User-agents * Blocking No — crawling allowed
# START YOAST BLOCK

# ---------------------------

User-agent: *

Disallow: /form/ksca-form/ksca.html


Sitemap: https://www.pa.gov/en.sitemap.xml

Sitemap: https://www.pa.gov/content/dam/copapwp-pagov/en/seo/sitemap_images.xml


# ---------------------------

# END YOAST BLOCK
C
URL Variants
Action
www/non-www, trailing slash, HTTP→HTTPS
REVIEW
www/non-www, trailing slash, HTTP→HTTPS
Critical::
Both www and non-www versions serve content
Got: Both variants return 200 Expected: One variant 301-redirects to the other
Warning::
HTTP→HTTPS redirect uses 302 instead of 301
Got: 302 temporary redirect Expected: 301 permanent redirect

www / non-www

200https://www.pa.gov/
200https://pa.gov/

Inconsistent — duplicate content risk

HTTP → HTTPS

307http://pa.gov/ https://pa.gov/

Use 301 (permanent) instead of 302 (temporary)

B
TLS Certificate Expiry & Recommendations
111 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

111
days left
0d 30d 60d 90d+

Recommended actions

  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
CDN & Delivery
Azure CDN (CONFIG_NOCACHE)
REVIEW
Azure CDN (CONFIG_NOCACHE)
Info::
Site is served via Azure CDN CDN
Got: x-azure-ref: 20260421T210249Z-1675fbfb9b4z59hzhC1PARbd7w0000000dzg000000003hvx
Info::
CDN cache status: CONFIG_NOCACHE
CDN Detected: Azure CDN
Provider Azure CDN Cache Status CONFIG_NOCACHE Evidence x-azure-ref: 20260421T210249Z-1675fbfb9b4z59hzhC1PARbd7w0000000dzg000000003hvx
A
DNS Records
6 A records, 801 ms lookup
PASS
6 A records, 801 ms lookup
Info::
Resolves to 6 IPv4 address(es)
Got: 13.107.213.41, 13.107.213.40, 13.107.253.40, 13.107.246.41, 13.107.246.40, 13.107.226.40
Info::
No IPv6 (AAAA) records
Info::
4 nameserver(s) configured
Got: dns5.pa.gov, dns3.pa.gov, dns4.pa.gov, dns2.pa.gov
Info::
1 mail exchanger(s) configured
Info::
CAA records not checked
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Info::
SPF record present in TXT
Warning::
DNS resolution is slow (801 ms)
Slow DNS adds latency to every page load. Consider a faster DNS provider.
Got: 801 ms
A13.107.213.41, 13.107.213.40, 13.107.253.40, 13.107.246.41, 13.107.246.40, 13.107.226.40
AAAA
CNAME
NSdns5.pa.gov, dns3.pa.gov, dns4.pa.gov, dns2.pa.gov
MX
0 PA-GOV.mail.protection.outlook.com
TXT
google-site-verification=mt782B0UsnOl1p54StrUWoja8PEGQFbZZm3C449dLOE
L5/kApjWUWzfKBBT2nVqD1Ow+6+vvVhMPc+gKCvzAAdwr4OkUdqQfYrP4O9LtAKCnXVKyAXbI1ynE8ZC...
brevo-code:e693ae4a17a6c6f32f8d628a279128de
openai-domain-verification=dv-BXKqAr1xdqaLw6l0SPFwbvn1
ZOOM_verify_f7A5SsBo0rPEwEGU8AW4hx
autodesk-domain-verification=jZ0ZjnlmYJZ3ASsmrc08
_globalsign-domain-verification=qtch9G9T0yaNInw5frrrC0_m9P4ZjGFQXBvr_IgeII
SPF v=spf1 ip4:8.20.65.192/26 ip4:8.38.177.192/26 ip4:208.95.153.40 ip4:52.26.166.15...
e2ma-verification=o5hib
google-site-verification=RKOfVkX7srUi7qhv7SzUCW_DwCcfVAj_XsrTqBljA7I
apple-domain-verification=vIW3FwAjRAoeDVlU
e2ma-verification=olncb
google-site-verification=H8NAbVQgBKGeglkjEd4mHXdUUG75FzHOAcXhK5PlxxQ
google-site-verification=glq-y_FWjQkmn-klXvVVW6Ozla9xrmmCOl-mdu3-0uE.
e2ma-verification=zlrgb
_globalsign-domain-verification=zD9EK2LDbQCjyTdTZP0w4poXN2Ej_T5iQKAXJDZm8b
nintex.62f2b9d1fcb5c3cc7d3337c1
e2ma-verification=xiqgb
e2ma-verification=p6chb
google-site-verification=D3pNL6cllS2OkR6xKp_JLloyb3iQhpFFY1hjz98MZRU
apple-domain-verification=He8ObbqEjxymeLUq
e2ma-verification=j51eb
e2ma-verification=haveb
e2ma-verification=54qgb
e2ma-verification=l2ybb
e2ma-verification=hmfib
e2ma-verification=6rchb
figma-domain-verification=788a304f46df28dbc22e37a386c1e0a4c5be11575c268b439744e4...
apple-domain-verification=HBkgahqUKF810TcE
_globalsign-domain-verification=lBEMm9RScJzeLnam2Ijdc_TBuj3RuEF_EuoIHMWb3u
e2ma-verification=iiqgb
e2ma-verification=2jegb
vmware-cloud-verification-d71582f3-fbb1-4852-afOe-e4db5c405775
CAALookup not available with standard resolver
Resolved in 801 ms

CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.

Why this matters

Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.

Slow DNS adds latency to every page load. Consider a faster DNS provider.

Why this matters

DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.

Source: DNS performance benchmarks

A
Redirect Chain
1 redirect(s), 329 ms total
PASS
1 redirect(s), 329 ms total
Info::
Single redirect
Got: https://pa.gov → https://www.pa.gov/ (308)
Info::
WWW normalization redirect

https://pa.gov

79 ms · HTTP/1.1

308

https://www.pa.gov/

250 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://pa.gov30879 msHTTP/1.1
2https://www.pa.gov/200250 msHTTP/1.1

See the visual redirect chain in the HTTP Probe tab →

A+
Domain Intelligence
pa.gov — via get.gov, 25 years, 1 months old, hosted on Microsoft Azure
PASS
pa.gov — via get.gov, 25 years, 1 months old, hosted on Microsoft Azure
Info::
Domain registered until Sep 1, 2026 (4 months remaining)
Info::
DNSSEC is not enabled
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Info::
Registrar: get.gov
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Info::
Hosting: Microsoft Azure
Got: AS8075
Domain expiry

77 days

September 1, 2026

SSL certificate

111 days

Issued by DigiCert Inc

Domain age

25 years, 1 months

Registered July 12, 2001

DNSSEC

Not enabled

Protects against DNS spoofing

Hosting

Microsoft Azure

ASN AS8075

13.107.213.40

Registrar

get.gov

Unlocked 4 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Renew the domain or enable auto-renewal to prevent accidental expiry
  • Enable DNSSEC to protect visitors from DNS spoofing
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar get.gov
Created July 12, 2001 (25 years, 1 months ago)
Expires September 1, 2026 (4 months)
Last Updated October 22, 2025
Name Servers dns2.pa.gov, dns3.pa.gov, dns4.pa.gov, dns5.pa.gov
DNSSEC Not enabled
Registrant REDACTED FOR PRIVACY
Hosting
IP Address 13.107.213.40
ASN AS8075 (MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US)
Provider Microsoft Azure
Data source: rdap (0.5s)

DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.

Why this matters

Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.

Learn more

DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.

Source: ICANN / RFC 4033

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A+
HTTP Probe Timing
Total 179 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
108 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
16 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
36 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
179 ms
Total Time Total request time from DNS lookup through full response.
180 ms

Connection waterfall

DNS Lookup 108 ms TCP Connect 16 ms TLS Handshake 36 ms Server Processing 18 ms Content Transfer 0 ms
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback