Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BCrawlabilityrobots.txt present, sitemap with 3796 URLsREVIEW
Search engines may not be able to parse the sitemap. Fix XML validation errors.
An unparseable sitemap is silently ignored by Google — the URLs it advertises are never queued for crawl.
Learn more ▾ ▴
Google's sitemap parser is strict about XML validity. A single unescaped `&` or unclosed tag invalidates the whole file. Run your sitemap through a validator (Search Console's Sitemaps report flags it) and fix the offending entry. Most generators escape correctly; mistakes usually come from manually-written entries.
Source: sitemaps.org / Google Search Central
User-agent: *
Disallow: /content/dam/
Disallow: /content/dam/pan/en_US/assets/pdf/legal/archive/
Disallow: /content/pan/en_US/content/dam
Disallow: /content/pan/en_US/partners/nextwave-partner-portal/
Disallow: /content/pan/en_US/field/
Disallow: /content/pan/en_US/ignitePromoDemo
Disallow: /content/pan/en_US/legal-notices/privacy/privacy-notice
Disallow: /content/pan/en_US/
Disallow: /content/pan/ja_JP/
Disallow: /content/pan/de_DE/
Disallow: /content/pan/fr_FR/
Disallow: /content/pan/es_ES/
Disallow: /content/pan/pt_BR/
Disallow: /content/pan/en_AU/
Disallow: /content/pan/zh_TW/
Disallow: /content/pan/ko_KR/
Disallow: /content/pan/zh_CN/
Disallow: /content/pan/es_LA/
Disallow: /content/pan/en_US/allsitemap.html
Disallow: /static/
Disallow: /static_260619/
Disallow: /static_perf/
Disallow: /qa/
Disallow: /allsitemap
Disallow: /allsitemap.html
Disallow: /content/pan/en_US/sitemaps/
Disallow: /sitemaps/
Disallow: /content/pan/en_GB/
Disallow: /content/pan/en_CA/
Disallow: /content/pan/en_SG/
Disallow: /content/pan/en_IN/
Disallow: /content/pan/it_IT/
Disallow: /content/pan/es_MX/
Disallow: /content/pan/en_US/topNav/
Disallow: /content/pan/en_US/newTopNav/
Disallow: /content/pan/en_US/expandedTopNav/
Disallow: /apps/
Allow: /apps/pan/public/singlePageReactModel?pageId=
Allow: /apps/pan/public/unit42/bloglist.loadblogresults.json?searchLanguage=en_US
Disallow: /content/pan-dev
Disallow: /content/pan/en_US/healthCheck.html
Disallow: /content/pan/en_US/events/xdr-event
Disallow: /content/pan/en_US/events/xdr-event.html
Disallow: /content/pan/en_US/events/xdr-post-event
Disallow: /content/pan/en_US/events/xdr-post-event.html
Disallow: /content/pan/en_US/atlassian-domain-verification.html
Allow: /sitemap.xml
Disallow: /content/pan/en_US/documentation/
Disallow: /documentation/
Disallow: /company/in-the-news/2019/
Disallow: /company/in-the-news/2018/
Disallow: /company/in-the-news/2017/
Disallow: /company/in-the-news/2016/
Disallow: /company/in-the-news/2015/
Disallow: /company/in-the-news/2014/
Disallow: /company/in-the-news/2013/
Disallow: /company/in-the-news/2012/
Disallow: /company/in-the-news/2011/
Disallow: /company/in-the-news/2010/
Disallow: /company/in-the-news/2009/
Disallow: /company/in-the-news/2008/
Disallow: /company/in-the-news/2007/
Disallow: /company/press/2019/
Disallow: /company/press/2018/
Disallow: /company/press/2017/
Disallow: /company/press/2016/
Disallow: /company/press/2015/
Disallow: /company/press/2014/
Disallow: /company/press/2013/
Disallow: /company/press/2012/
Disallow: /company/press/2011/
Disallow: /company/press/2010/
Disallow: /company/press/2009/
Disallow: /company/press/2008/
Disallow: /company/press/2007/
Disallow: /securityevent/en_US_LV2.html
Disallow: /content/pan/en_US/google992ef19868c7ad5e.html
Disallow: /google992ef19868c7ad5e.html
Disallow: /content/pan/en_US/.well_known/
Disallow: /.well_known/
Disallow: /events/future-of-security-revealed
Disallow: /events/future-of-security-revealed-amer
Disallow: /newbrand
Allow: /content/dam/*.svg$
Allow: /content/dam/*.gif$
Allow: /content/dam/*.png$
Allow: /content/dam/*.jpg$
Allow: /content/dam/*.jpeg$
Allow: /content/dam/*.svg$
Allow: /content/dam/*.gif?imwidth
Allow: /content/dam/*.png?imwidth
Allow: /content/dam/*.jpg?imwidth
Allow: /content/dam/*.jpeg?imwidth
Allow: /content/dam/*.js$
Allow: /content/dam/*.css$
Disallow: /blog/wp-admin/
Allow: /blog/wp-admin/admin-ajax.php
Disallow: /devsectalks/wp-admin/
Allow: /devsectalks/wp-admin/admin-ajax.php
Disallow: /perspectives/wp-admin/
Allow: /perspectives/wp-admin/admin-ajax.php
Sitemap: https://www.paloaltonetworks.com/sitemap.xml
Sitemap: https://www.paloaltonetworks.com/sitemap_home.xml
Sitemap: https://www.paloaltonetworks.com/blog/sitemap_index.xml
Sitemap: https://www.paloaltonetworks.com/devsectalks/sitemap_index.xml
Sitemap: https://www.paloaltonetworks.com/perspectives/sitemap_index.xml
User-agent: Twitterbot
Allow: /*.gif$
Allow: /*.png$
Allow: /*.jpg$
CTLS Certificate Expiry & RecommendationsAction23 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Renew certificate — 23 days remaining
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryGoogle Cloud CDNREVIEW
A+DNS Records1 A records, 88 ms lookupPASS
| A | 34.107.151.202 |
| AAAA | — |
| CNAME | — |
| NS | a1-184.akam.net, a4-64.akam.net, a12-67.akam.net, a13-66.akam.net, a2-65.akam.net, a11-64.akam.net |
| MX | 10 mxb-00169c01.gslb.pphosted.com 10 mxa-00169c01.gslb.pphosted.com |
| TXT | h1vls4tptbk6r1shsnm8efjhbi 1ct0e8iearg3nk0t6bl6npdbl3 85lsukgo072e0kt4rdu4leocm7 google-site-verification=dVdQIgjTBL5flEseOxenNlxNPty1DYkpirmCBAOAjx8 R4WKB79BFYVKQ8DVZPR2JCS5CS2CTXMY 6fe22p5pk34ki6rh7t17tpebfp inf7cd5c1gk18pt59d6e3kl6aa zoom-domain-verification=22a5fdbe-19f4-478a-b0c0-f236be58a2df 9vt91e86j4ko9grm6hbbv98nef efcp23pib3k8t2j4objvldm510 fbr16re8l6ir1b8b8npl2q5neb jamf-site-verification=hJ2s6OV8-f70dmyfxWpMfA _50zigx5mx7pgy87x16829fgdfqa2ov5 jpnf36mq2s92c5c00v14q7a37v 58u3kkdponnm0m6q09l9tv7rnh 4tkjmhj6j50i3dvnd4kfv6jsrq mongodb-site-verification=AaxyA5GqlHGxGgporANUT3ct0vpQeKe4 n3verv80mda9qr440rbk83csuf ah320kfjo9vr2n51e4uvp679lt fn68q5ro1unem66c8oqp6plmu6 google-site-verification=yZTC3zLUAlohH5KdyGFhucj62F6WYFsceaLFqQjj3wM n8n45qiscbhd62kfbu4cfh1nrm 8dsY2aDrNyOKSigWGNtqcmv6DeOmDCP0N0rQzeOVwU CGTGPGXPT3YNYUMKWS4RXNGXQHN5QEY3 airtable-verification=a075552ca822d57705b1dd659256e9c7 n4qkbai0eif60vm0khcd43rk8f 6q8jot3bijmk746uu9nlbh24go 1sgm3vqf8o8ijbok3upjq2a1vk gta24vodmktqbg46m86jocns7s 6rbha37salnckbv9ep380dj2q1 prlc56goe26b2h5nembga82qm5 e7ov2neog15i03o7m8nmnjas0l j8vg973q6brk6f5svj811bukpq ivhv5kprbgklnubnnuk6qjtabg hia3bb4jbcil3ovr30h9hojpqd status-page-domain-verification=gxhgqp5msy2m g4f91blbdh0lhp7opt95r94jk 7qspp33qhf29it14cd7n625cda o8athtmkud74h1jl7jk0t4b3p6 pnnch616iiv6011nq9l624j3c l5b6oaj9gr0mb3muqaeue7qhcr 6X7M4JRV6VHHKF99MHFS5PXH8KKB63ZW fooqm3r8jjn2rovppo3od7c2mp 5ldf3sqj657a1062rh369v3573 hfkbsoa4sc09l53cjpkdjgmob0 SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all 43vq7k80qmd20m3n9mmld6e7qf gga3sqhrcsng1b1bifj24vg0kv tbm34d8bh13j0pc6g25j258r8l qvtit51ea5sim9orhv3vi6ha9t pdmed6j7qorcu1noiscd4jqssr hq2mbpl9hocvnfhctdts151oq4 dsecga64h3uir31eecn4a7175l dnj27ue3j8t6dpv3irdoo5i1ku v8vaboong0f85vf4jmf9mjbohu cursor-domain-verification-vh7tff=UXyGfse9p8T7MhDoMCcuLFRN2 afku51s0btk5bf3d4blift5l4t adobe-idp-site-verification=9b01a9ad-47a1-4d79-a207-25b12d1958a7 veo075dkcta8g6ehishav8qe9f google-site-verification=iITiN6aH67sL0mYGAtCG6TyoZ6xVgT64DRT6IKv9AIU cursor-domain-verification-vfa9w9=J4SCKGYvPEtYsStEsLqTTJJg2 EHJSPTQUZK5WEHK7JD5XWWQAUGW3XMJT atlassian-domain-verification=WeW32v7AwYQEviMzlNjYyXNMUngcnmIMtNZKJ69TuQUoda5T6D... mandrill_verify.PSst9X45ZLorfVHUuJOOog ojocirtnrr6l9nqil9hdeiqr3c amazonses:wD8q9vBgr/tA/9V4Lh4CPADIMQs4LIW/EpqeYxrS5e8= oautm5mhsm5jlv0i6tkhcu5lp4 viaa56ih438657apsv16q04t90 k607lkkdomjv1lfifn7gu1soab va30guv1b5bplubesiot279j8v 9lbrckghad1lbajaei221vag7v nh4uisgc34qmr3650jv5ljs9u3 coda-verification=24ea7eb9-a4cd-4306-a346-a9c4f3fb53b8 u5a40u7bs4rvtve1jfmduof3c2 s6t7d4p6ga3skcjm75difliq9q llfsfhsoosoq2o87t8dahsrns5 8f8urvmme9o3qb8sd92flk0dl0 google-site-verification=YXE-YcmoWUgw4fRT5UnJ7DqfVPrkqWTTpHIwyaoo8yo google-site-verification=PuOqZ-88Dc4Qon0e8UrXPZVLIhAh6Gk_ajqnBIIRl-U 1ko8q8lla6lno7pbceb5e8d5c2 eks3p/qXVt97oL7X1IGBQdP05ev8rOuFOK8LAzqJ8iMkRDfXrKKGEFy3zHyGEAG8IkwimKG83eTQtoWg... dedjakiumqqsvkl5h3ud2s6g1v 2bq4j4pngim79rnrth1thn6n1k 4kh3d97k5qqd6o0fgv1i4g2u83 msos6uc10td74sfn0ohc1q6di1 onetrust-domain-verification=38272c1fe0db433cbce84c5b43a371be anthropic-domain-verification-xyrkyx=xHMqjLbkz0EXPzTkesPAYcrZI hli9bd929s8qh322f5km1kjqgd mongodb-site-verification=iAfodgMVqXWglWqKv3qb4xzIjtZkfBwk atlassian-domain-verification=OLe058dAXDG6kcCutEa7uSYy2iKLT7CvYNxGz2iROYa4NJ8Faz... o831ub1ulm832ugi9qevqcaefm google-site-verification=xAPDc161l_8F3MAhRDzQ52C3yr2F-YoK0vzIcDufRcw pbqm87nb1onkdl4moi3hmthr2f hemc77lfmofd7cm0u3uqptk191 cql9u7mo5but0pguo5a40l7hs2 86ijgbi5k5aju6aleo0oufme00 qh4sv5nodvbq9v9gh7ud7953a8 google-site-verification=8zcmNvhRzBOYw-GN3l86mhO5MTfJjEd8ocEyjdsSLak hbrbe87s49ndjp587q3a8erops cmls5bfa53p3s79ucl3s0rkns docusign=7979590c-2e52-4018-b599-54a429f449d1 njjjurksa7r5ua4q4lm1tb7a80 7g3739d6i2jb30k33m6ueujmt0 ebuie01o1ege38l5jf1ffj8o38 docker-verification=dae53080-28ee-4450-b780-78619cd643d8 3q2j547c2ss9gqblbn7avv85mq vklbb0v8dgrgspo6d7384n70ro oivchnsecr4dq3n2cvh1hnuvhr ka6r91h38s2k55r9ofl0ss8t89 AaxyA5GqlHGxGgporANUT3ct0vpQeKe4 11i5c0ekv25igv3lrihe8rpjr0 parallels-domain-verification=5366262446d24ad4bd780ca3840abec179d72ed4acbf44e594... 7sj8nns9mku4m1vktlppivfbse l4hdr3hgsnhc896jru0u7tued5 837f1128dfc71abb349d6278c0244b12ff1377f1 gihd1g9gcpd7hva1al3qoop7t7 _ju1nifoo3npvax0fea59uu0zhsatxfi google-site-verification=6qPUaVQpEP6Ezu2BOGamqx8Gz2hkS9RrhaAkqh5GV7U vjd7tejrvfgsdl33e57qvpm293 8h0lra2mrvmhel1ehnjsasljvf ccsl433s9cam3jo7bksp32h30t qo1mqncvcq9hd2m8990tbn7vjg google-site-verification=-8dsY2aDrNyOKSigWGNtqcmv6DeOmDCP0N0rQzeOVwU sk4vccrr2nephbhcdics1t33tp o3a1dgpf0ms9ru489pt8e08dur 8qcf0llvbtp0gllc98ocvpkqn5 43lcnpucrrahala0pma17t9ldh 2lc1hj3a5b6sld2clkj3ngkddv zapier-domain-verification-challenge=969a3865-d272-4916-a1b5-55ac1cfba17e 1cttq7kb4knotmj3lt3tvifkgv 6u9q3uttkmtvajb17fa30hlbqj google-site-verification=DJPF4JB4ngTVTLJ7tmB3z_eiSM5GfjZJMefrsF34BGc google-site-verification=-9uP2-iFIdiIubiYWtVQuIoz6YNG5Av2UoWgaZ7KZZI mip6gk3sutvk7m7tgnjvpaai57 8v67o26cmm8cocmjuok9i5pn69 11b87c14-db4f-4b90-b5b1-58b37f18856f1 google-site-verification=IJsdELG7bTVOm_c383MdVZKvWBvhkL3SPijQh4KRYKE m8mdrue0i4l2027jc9o4ank9nv pq6b5tmggne5l7rvht5kd1lb51 6itmsj2v6k9iv9dcjv2qusch45 c9pag47g4m564qf3s8eqvthlu4 ursip6s46blqs253h2dnmeedhv mongodb-site-verification=g1laX7ffTUXFoFUkdp7Mvcmn7dpCqMTg l64rnvbvvsjfdhjusn5jro5jdd CGJAZFH9QTYUPE2A6XJE8VEBUSSB47B5 99sm2jcfqemq06t85qfc993ml1 logmein-verification-code=ccb897d5-1bed-410a-9c45-a6dd6be9b1c so110hdpav9k3sict9heklp1ck qhb84vjgoh7atf2rh81di4ptql 8er4tisqsolco9ccvfju04dsrh MS=ms97043933 84s0rh47rmf2oih7apr3s8m0op d4d9a85a-19b9-432e-9d61-1b98cfbd2ae5 7htalfjfn0qjnm4rgd8hoark5c google-site-verification=Xf-aGYKmAN6AX34i9Nu-KVnysqgvoFkAaW72GG4FDfE chariot=chariot+paloaltonetworks@praetorian.com id9jqtm1fj7ip2vlm37omjrg79 g2um0lap0em6ovd04dvtghha6j onetrust-domain-verification=2c4c9a5ac0854a82866d4d203249d186 3031tesilkvqeo9v9i35gb6f5s ve5ql75cdpn3ak314b9fqlcinc 4bjob0nn7hooms8abdd6fqfrgf 6n7b7pculp76tffnromn7u4ske adobe-idp-site-verification=56c815659a5eb8e0c23229e11b4370227c786e9cb821d48fffb6... asv=41bb9992b7276bdc73abfe2b206c14b0 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 348 ms totalPASS
https://paloaltonetworks.com
165 ms · HTTP/1.1
https://www.paloaltonetworks.com
184 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://paloaltonetworks.com | 301 | 165 ms | HTTP/1.1 | Apache |
| 2 | https://www.paloaltonetworks.com | 200 | 184 ms | HTTP/1.1 | Apache |
See the visual redirect chain in the HTTP Probe tab →
AURL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Use 301 (permanent) instead of 302 (temporary)
A+Domain Intelligencepaloaltonetworks.com — via MarkMonitor Inc., 21 years, 5 months old, hosted on Google CloudPASS
553 days
February 21, 2028
23 days
Issued by DigiCert Inc
21 years, 5 months
Registered February 21, 2005
Enabled
Protects against DNS spoofing
Google Cloud
ASN AS396982
34.107.151.202
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Renew the TLS certificate or verify auto-renewal is working
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice