Skip to content
https://revenuebase.ai

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
90
GRADE
A
FIX
0
REVIEW
6
PASS
11
INFO
0
Probed from Sao Paulo, Brazil
200 OK
Checks
17
11 PASS 6 REVIEW
B
DNSSEC
Unsigned (DNSSEC not deployed)
REVIEW
Unsigned (DNSSEC not deployed)
Info::
DNSSEC is not deployed
The zone is not DNSSEC-signed. Users on validating resolvers (Cloudflare 1.1.1.1, Quad9 9.9.9.9, growing default in mobile resolvers) get no protection against DNS spoofing for this domain. Most registrars now offer DNSSEC at a single click; consider enabling it for sites where authenticity matters (banking, healthcare, government).
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
B
Reverse DNS
0/4 IPs match cert SAN
REVIEW
0/4 IPs match cert SAN
Info::
PTR for 3.166.152.33 does not match any cert SAN: server-3-166-152-33.mia50.r.cloudfront.net
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
Info::
PTR for 3.166.152.96 does not match any cert SAN: server-3-166-152-96.mia50.r.cloudfront.net
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
Info::
PTR for 3.166.152.128 does not match any cert SAN: server-3-166-152-128.mia50.r.cloudfront.net
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
Info::
PTR for 3.166.152.30 does not match any cert SAN: server-3-166-152-30.mia50.r.cloudfront.net
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
TLS Certificate Expiry & Recommendations
162 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

162
days left
0d 30d 60d 90d+

Recommended actions

  • Add includeSubDomains to the HSTS directive
  • Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
  • Enable DNSSEC on your domain for DNS spoofing protection
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: 404, /health: 404, /healthz: 404, /ping: 404, /status: 404.
A+
DNS Records
4 A records, 10 ms lookup
PASS
4 A records, 10 ms lookup
Info::
Resolves to 4 IPv4 address(es)
Got: 3.166.152.33, 3.166.152.96, 3.166.152.128, 3.166.152.30
Info::
No IPv6 (AAAA) records
Info::
4 nameserver(s) configured
Got: ns-1287.awsdns-32.org, ns-1576.awsdns-05.co.uk, ns-390.awsdns-48.com, ns-962.awsdns-56.net
Info::
6 mail exchanger(s) configured
Info::
SPF record present in TXT
Info::
DNS resolution time: 10 ms
Got: 10 ms
A3.166.152.33, 3.166.152.96, 3.166.152.128, 3.166.152.30
AAAA—
CNAME—
NSns-1287.awsdns-32.org, ns-1576.awsdns-05.co.uk, ns-390.awsdns-48.com, ns-962.awsdns-56.net
MX
1 smtp.google.com
5 aspmx.l.google.com
5 alt1.aspmx.l.google.com
5 alt2.aspmx.l.google.com
10 alt3.aspmx.l.google.com
10 alt4.aspmx.l.google.com
TXT
hubspot-developer-verification=ODBhNGM0ODktNjUwNy00YTgwLWIzZDItMDg0ZTJmOWRmZTNi
SPF v=spf1 include:_spf.google.com include:8486714.spf04.hubspotemail.net ~all
CAALookup not available with standard resolver
Resolved in 10 ms
A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
Multi-Resolver DNS Speed
Mean 9ms across 3 resolvers (spread 16ms)
PASS
Mean 9ms across 3 resolvers (spread 16ms)
Info::
Cloudflare: 2ms
Got: 2ms via 1.1.1.1:53
Info::
Google: 8ms
Got: 8ms via 8.8.8.8:53
Info::
Quad9: 18ms
Got: 18ms via 9.9.9.9:53
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://revenuebase.ai

https://revenuebase.ai

336 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://revenuebase.ai200336 msHTTP/1.1cloudflare
A+
Crawlability
robots.txt present, sitemap with 80 URLs
PASS
robots.txt present, sitemap with 80 URLs
Info::
robots.txt is present
Got: 2581 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 80 entries
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 2581 B Sitemaps referenced 2 User-agents PerplexityBot, CCBot, Bingbot, YandexBot, Claude-Web, Perplexity-User, Google-Extended, Google-CloudVertexBot, Applebot-Extended, OAI-SearchBot, ClaudeBot, Bytespider, GPTBot, *, Googlebot, DuckDuckBot, Claude-SearchBot, meta-externalagent, Amazonbot, Applebot, ChatGPT-User, Claude-User Blocking No — crawling allowed
# robots.txt for revenuebase.ai
# Served from S3 through CloudFront. /companies/* is the RevenueBase company
# directory; every other path is proxied to the Webflow marketing site.
# The previous Webflow-generated robots.txt disallowed nothing; this file
# keeps that policy (no disallows, no crawler exclusions) and adds explicit
# allows for the major search and AI crawlers.
#
# The wildcard group below already permits everything, so no group here is
# load-bearing for access. They are here to state intent per crawler, and so
# that a future Disallow added to the wildcard cannot silently take the
# answer-engine crawlers down with it.
#
# The AI vendors run SEPARATE agents for separate purposes, and the one that
# governs whether we appear in an answer is usually NOT the one people think
# of first:
#
#   OpenAI    GPTBot          model training
#             OAI-SearchBot   inclusion in ChatGPT search results  <- this one
#             ChatGPT-User    a user asked ChatGPT to fetch this page
#   Anthropic ClaudeBot       model development
#             Claude-SearchBot  search indexing                    <- this one
#             Claude-User     a user asked Claude to fetch this page
#   Google    Googlebot       search, and AI Overviews follow it
#             Google-Extended Gemini / Vertex model training
#
# Claude-Web is Anthropic's retired agent name. It is kept because removing a
# name from an allow-only file gains nothing and an old crawler may still
# send it.

User-agent: *
Allow: /

# --- Search -----------------------------------------------------------------
User-agent: Googlebot
Allow: /

User-agent: Bingbot
Allow: /

User-agent: DuckDuckBot
Allow: /

User-agent: Applebot
Allow: /

User-agent: YandexBot
Allow: /

# --- Answer engines: retrieval and search indexing --------------------------
User-agent: OAI-SearchBot
Allow: /

User-agent: ChatGPT-User
Allow: /

User-agent: Claude-SearchBot
Allow: /

User-agent: Claude-User
Allow: /

User-agent: Claude-Web
Allow: /

User-agent: PerplexityBot
Allow: /

User-agent: Perplexity-User
Allow: /

# --- Model development ------------------------------------------------------
User-agent: GPTBot
Allow: /

User-agent: ClaudeBot
Allow: /

User-agent: Google-Extended
Allow: /

User-agent: Google-CloudVertexBot
Allow: /

User-agent: Applebot-Extended
Allow: /

User-agent: meta-externalagent
Allow: /

User-agent: Amazonbot
Allow: /

User-agent: CCBot
Allow: /

User-agent: Bytespider
Allow: /

Sitemap: https://revenuebase.ai/sitemap.xml
Sitemap: https://revenuebase.ai/companies/sitemap.xml

A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Info::
HTTP correctly redirects to HTTPS permanently
Got: HTTP 301

www / non-www

301https://www.revenuebase.ai/
200https://revenuebase.ai/

Preferred variant: non-www

HTTP → HTTPS

301http://revenuebase.ai/ → https://revenuebase.ai/

Consistent

A+
Domain Intelligence
revenuebase.ai — via NameCheap, Inc., 5 years, 8 months old, hosted on AWS
PASS
revenuebase.ai — via NameCheap, Inc., 5 years, 8 months old, hosted on AWS
Info::
Domain registered until Feb 14, 2027 (4 months remaining)
Info::
DNSSEC is not enabled
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Info::
Registrar: NameCheap, Inc.
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Info::
Hosting: AWS
Got: AS16509
Domain expiry

132 days

February 14, 2027

SSL certificate

162 days

Issued by Amazon

Domain age

5 years, 8 months

Registered February 14, 2021

DNSSEC

Not enabled

Protects against DNS spoofing

Hosting

AWS

ASN AS16509

3.166.152.33

Registrar

NameCheap, Inc.

Unlocked 4 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Enable DNSSEC to protect visitors from DNS spoofing
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar NameCheap, Inc.
Created February 14, 2021 (5 years, 8 months ago)
Expires February 14, 2027 (4 months)
Last Updated August 12, 2026
Name Servers ns-1576.awsdns-05.co.uk, ns-390.awsdns-48.com, ns-1287.awsdns-32.org, ns-962.awsdns-56.net
DNSSEC Not enabled
Registrant Redacted for Privacy Purposes
Hosting
IP Address 3.166.152.33
ASN AS16509 (AMAZON-02 - Amazon.com, Inc., US)
Provider AWS
Data source: rdap (0.4s)

DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.

Why this matters

Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.

Learn more ▾

DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.

Source: ICANN / RFC 4033

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more ▾

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A
HTTP Probe Timing
Total 514 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
4 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
120 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
123 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
385 ms
Total Time Total request time from DNS lookup through full response.
515 ms

Connection waterfall

DNS Lookup 4 ms TCP Connect 120 ms TLS Handshake 123 ms Server Processing 138 ms Content Transfer 129 ms
A+
CDN & Delivery
Document on Cloudflare; assets also on Fastly
PASS
Document on Cloudflare; assets also on Fastly
Info::
Document is served via Cloudflare CDN (edge: IAD)
Got: cf-ray: a44eb283ba30b712-IAD
Info::
CDN cache status: HIT
Info::
Assets on Cloudflare: cdn.prod.website-files.com (assets: 35), cache HIT
Got: cf-ray: a44eb5304abc2df6-GRU
Info::
Assets on Fastly: cdn.jsdelivr.net (assets: 4), cache HIT, HIT
Got: delegation jsdelivr.map.fastly.net
Document served via CDN: Cloudflare
Provider Cloudflare Cache Status HIT Evidence cf-ray: a44eb283ba30b712-IAD

Asset hosts on a CDN

  • cdn.prod.website-files.com — Cloudflare · assets: 35 · Cache Status: HIT
  • cdn.jsdelivr.net — Fastly · assets: 4 · Cache Status: HIT, HIT

Other asset hosts

  • www.googletagmanager.com — assets: 3 · Google
  • connect.facebook.net — assets: 2 · below probe threshold
  • snap.licdn.com — assets: 2 · below probe threshold
  • cdn.intellimize.co — assets: 1 · below probe threshold
  • d3e54v103j8qbb.cloudfront.net — assets: 1 · below probe threshold
  • ddwl4m2hdecbv.cloudfront.net — assets: 1 · below probe threshold
  • js.hs-analytics.net — assets: 1 · below probe threshold
  • js.hs-banner.com — assets: 1 · below probe threshold
  • js.hs-scripts.com — assets: 1 · below probe threshold
  • js.hsadspixel.net — assets: 1 · below probe threshold
  • js.hscollectedforms.net — assets: 1 · below probe threshold
  • js.hubspot.com — assets: 1 · below probe threshold
  • r2.leadsy.ai — assets: 1 · below probe threshold
  • syntermedia.ai — assets: 1 · below probe threshold
  • visitor-id.prd.coffee.work — assets: 1 · below probe threshold
  • www.redditstatic.com — assets: 1 · below probe threshold
A+
CDN Cache Observability
Cache state: HIT
PASS
Cache state: HIT
Info::
CDN cache state observable via 3 header(s)
Got: age=64004, cf-cache-status=HIT, x-cache=Hit from cloudfront
A+
Operational Status Page
Status page detected via status subdomain
PASS
Status page detected via status subdomain
Info::
Status page link found: https://status.revenuebase.ai/
Got: https://status.revenuebase.ai/
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback