Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BRedirect Chain1 redirect(s), 1064 ms totalREVIEW
https://roche.com
347 ms · HTTP/1.0
https://www.roche.com/
717 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://roche.com | 302 | 347 ms | HTTP/1.0 | BigIP |
| 2 | https://www.roche.com/ | 200 | 717 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
If permanent, use 301 instead.
302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.
Learn more ▾ ▴
Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).
Source: Google Search Central
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
CURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Use 301 (permanent) instead of 302 (temporary)
BTLS Certificate Expiry & Recommendations299 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 19 ms lookupPASS
| A | 198.21.19.135 |
| AAAA | — |
| CNAME | — |
| NS | a4-67.akam.net, a1-178.akam.net, a9-66.akam.net, a7-66.akam.net, a18-66.akam.net, a6-65.akam.net |
| MX | 30 rkamtaext02.roche.com 30 rmumtaext01.roche.com 30 rmumtaext02.roche.com 30 rkamtaext01.roche.com 40 ridesmtaext02.roche.com 40 ridesmtaext01.roche.com 40 sc1esmtaext02.gene.com 40 sc1esmtaext01.gene.com |
| TXT | monday-com-verification=-lb6jW1CALj6G0VoJbrZPxPGFdYEVF-IJCG3H1TxeNY _2lmq1kpj3zl68cjx2zuyf8e69hzmmmc google-site-verification=DI-N7QrNlNT7nPh3xwM5YWOzqNE4nCqwPNNbyXhbESI smartsheet-site-validation=9Kvwnhpbn2lQauH-3mGmNfR1inz1WEQ2 MS=ms69073391 00D3E00000095tV=1TBFT0000001OLG;00DN0000000E2OM=1TBBW00000003sL;00D1k0000008cgn=... _5og63drgk4mg13pwgnmqfw9134p4kbj mentimeter-9b3033f4-b267-4717-af1d-799e8051c051 1password-site-verification=PFMSN2T6SNHOJNIS4GJ3V3FKGE _ch6rqmly8ng0hu52smutphf19wdvy8a cursor-domain-verification-zs3jvn=J1xUOw2sM5ubndmJFPx7zPbjJ 21t1hkt3o3nhegt0v1rsf3k8pq _ids4t6oomcwrz0b6ralwdl0sgkzwv2h _o4k7dfwh7r08p2fxidrzej2uaq5vnar jamf-site-verification=4sWOfQHnKQHZf6Tuu4vO2w _globalsign-domain-verification=M_EiCUlXI38JooJUVD-AeVqgIwlfuFxFEZpfmi6tAa _af6p1j1nftry03nkvfzlwvghmukpbeo google-site-verification=lY4AIJe7ylt3TzC932jXRfNkUfWd-ppP4JODM8ukBBM hvnb6r5ea40ja4msui6c78pde1 docusign=c51aa4f8-4903-4bca-bd95-26a7ce27ee25 _y0aqmsjwq3vdjxf49luz69nsjv4k9s4 atlassian-domain-verification=26PbyyWC0lEqMG83bG1AwfimikzLksRp3Z4ur/WlEbgvj/SeYK... _zkp26b8n5p1owlc8jdsis1ihi1uc9fa 9jkrribf9avju8v91h9f8lgi84 google-site-verification=SJJ805ZcxRDNZfS1u4rSCzdcjx8qFHiUAWHPY5JadM8 _tsihrxdjsu70ovx8gt9a5wastv6iyij k16e239hqdo4m26grru9bq8kc7 _rmuf9uwi4labw0inhn5lz9kcmamvcgm _lh3jyjet7f5i3xy62sl9fpxau2mky1i _algn4l342b4gn6uskoz6e0oaddh7mf2 SPF v=spf1 redirect=roche.com.hosted.spf-report.com MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCRe5lTuuG5kSebxKy844DBqKcUxRK0inNZ316Rg+BC... _pznt234gao172jqgl3yt7mhzo2ivto6 google-site-verification=ZhayQVyWcxKLg2xvYNUjTY26n4iaCD6IlAsJ5V99n9Y ldkl7gf1fsb1jb36i1t2dp726d XrJWdXx6f/99MqLGNRoMf4QtxKv4B1IzuP8QfWdTtFTWlIx6ZrrQRrpKF94fI6sDCDNCcU2mFPd6t0Xv... _h4j0jqptiq82dcnm6lb89v5n5kxb5im _a1b679825zgvfzv6cygten9dfpcwvaw _xr8dg73l5cufqxtfgktyv6xtgd9j69t 00d09000007j3fneas _nw1wjrucvlzezi5yvntbwx3ikufebbr ca3-61da3155bcd94bee89b1efc38cff0b38 atlassian-domain-verification=rK0y5CaSvBVuZlUkhxH8xo2D41XX8a8Sefej1dSclBZGJN6Bmn... _yw5oa7jkd9lb4vh8qvk0ggmirkuqewx brevo-code:9851090db7196df17e6ed5941309c2f7 google-site-verification=wnJ7idjtd96sfhQZmZke0kIET6KCsVh5JjuqIjx9mro _vfjvuxuxhl3cec68j8iynz5yz1hitna _globalsign-domain-verification=rFayBAAZ88UhqW2VDOMQIYGzv1fucNKnl0RbYFe68e 3mvbap8mmj9smuhd83e40hbkrv dclcb9p5ehfti8fo2b100nn9rm zoho-verification=zb70170274.zmverify.zoho.eu ig67vhoh138ibndrmall1vf68k atlassian-domain-verification=AHADYCFXPn9Fp9Gcq3E2la9e34pynWVHFFkF11QG/rmdimKQHQ... _am4baeaepesnotmx15rgr1m7ui9o5vo MS=ms76318237 p12icsp5a7ebghmcj0h8ko5vr1 _re8n27fdbfwxe45tdkhm8h4h4pkw0jb cursor-domain-verification-6hg5sd=OOJioAK7eIr2AMrkKE4HQpJ1Q brevo-code:9f64fa09cc7ff4e066b30cf7c6bb8e80 MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCdCn4YJawlOCOtPxZASgj0QwckjqUI7A88J8X9YtPd... google-site-verification=z7m5ZoiLl92If1w_S4EPqKl-i41g5HZqxCIIEJwSZ1I ca3-740c531fc9d843ca9817693108fa75de geneious.com:domain-verification=lm4PaPLHI8Jfz49GuggxfA _gmzalrhdltl1da3gy1nhxbdkiegyglw _6nq5k1m4ehq6n031uf3r87mwj6lrnv3 atlassian-domain-verification=mkK2hoW3AuZjW0PP/lVlE8ZQsUXsrNN4ZdBcxK568TQfE43FFp... _fgii60v5n2m8ma5iiu93mygoiuhg7e4 ca3-89c3e25382da472d82d59cca45072a60 docusign=0449aba9-9222-44ab-94e4-b54db50856ca 7vq9sk70eksujvjr2ftvc4959n _dr3zqah8l60ydc2m8bvkt23wzudp94w ca3-0b02f89b48c7457b9bdd1356d72b3596 _wawuxn93p8v50zas58wwrj8hv9hi97f _e99v5dl5h9g2ahde71tt8wwah0479ps amazonses:1cIIVg8rf/SdQ1nCzlWdanYKXJa+fzMb1MsekfPPmd4= _idkvqrv71t5mfkf8gza0r7cpglcyefi gitpod-verification=jRTWR5_9e0OIsTSwzas2dIifQSCst2lHukLaT-328dQ= _pl3iltm7c9fmbqwscsl1shqpyar1zdd _09j5969kb1vt5m1g9t74wmq029m7vqr _f970mu96zh0dbcagcgreeuyrbfdg1tm _qrmvj5ka0unio9zm1vtca9ut0z3h4u8 adobe-idp-site-verification=3e9cfc891d1ce0d60c896ee4320d2b2be177ce91630467007851... 9a0ommnpekatlo3uhf8avu05go _57kt1osapqi3kw7fg15x5g0znl0fe2q _al0dai687f2u8ppatotnsiwnxavjrd2 twilio-domain-verification=26693d24b091bc06bc52a652f2d5c5f7 google-site-verification=Bypw9gq-IumI9cXz8g2YC-nBAi2sy4tKDegluVanjr8 openai-domain-verification=dv-qvsqkQn0kLvKB6ZazxAjlqx6 loom-site-verification=6a776599f06941f4b70bf9618427a964 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 1 URLsPASS
# Generated by Sitemap Rewrite
User-agent: *
Allow: /
Disallow: /investors/faq_investors/prospectus-request$
Sitemap: https://www.roche.com/sitemap-index.xml
Host: https://www.roche.com
A+Domain Intelligenceroche.com — via SafeNames Ltd., 34 years, 6 months old, hosted on ASN-ROCHE-BASLE Global corporate IP network, CHPASS
306 days
April 18, 2027
299 days
Issued by DigiCert Inc
34 years, 6 months
Registered April 17, 1992
Not enabled
Protects against DNS spoofing
ASN-ROCHE-BASLE Global corporate IP network, CH
ASN AS2047
198.21.19.135
SafeNames Ltd.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice