Skip to content
https://simpleswap.io/?id=jvw7l9dn7nk6aj4j

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
90
GRADE
A
FIX
1
REVIEW
8
PASS
8
INFO
0
Probed from Santa Clara, United States
200 OK
Checks
17
8 PASS 8 REVIEW 1 FIX
D
CDN & Delivery
Action
No CDN detected
FIX
No CDN detected
Warning::
No CDN detected
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN detected

Consider using a CDN to improve global delivery speed and reduce origin load.

B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
C
Reverse DNS
Action
0/1 IPs match cert SAN
REVIEW
0/1 IPs match cert SAN
Info::
PTR lookup failed for 185.104.209.24: lookup 185.104.209.24: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
HTTP Probe Timing
Total 1245 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
REVIEW
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
6 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
1 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
6 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
1.03 s
Total Time Total request time from DNS lookup through full response.
1.25 s

Connection waterfall

DNS Lookup 6 ms TCP Connect 1 ms TLS Handshake 6 ms Server Processing 1.02 s Content Transfer 214 ms
B
TLS Certificate Expiry & Recommendations
120 days until leaf cert expires — 4 issues to address
REVIEW

Certificate validity

120
days left
0d 30d 60d 90d+

Recommended actions

  • Add includeSubDomains to the HSTS directive
  • Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
CDN Cache Observability
No CDN cache-status headers in the response
REVIEW
No CDN cache-status headers in the response
Info::
No CDN cache-status headers in the response
Without an X-Cache / CF-Cache-Status / X-Vercel-Cache / Age header, you can't tell from outside whether a request hit the cache or went to origin. Operationally important: enables debugging stale-content reports and verifying cache rules. Most managed CDN platforms emit at least one of these by default; absence often means the platform's diagnostic headers are stripped at an upstream proxy.
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: 404, /health: 404, /healthz: 404, /ping: 404, /status: 404.
A+
DNS Records
1 A records, 9 ms lookup
PASS
1 A records, 9 ms lookup
Info::
Resolves to 1 IPv4 address(es)
Got: 185.104.209.24
Info::
Single A record — no DNS redundancy
Multiple A records provide failover if one server goes down.
Info::
No IPv6 (AAAA) records
Info::
2 nameserver(s) configured
Got: elma.ns.cloudflare.com, john.ns.cloudflare.com
Info::
5 mail exchanger(s) configured
Info::
SPF record present in TXT
Info::
DNS resolution time: 9 ms
Got: 9 ms
A185.104.209.24
AAAA
CNAME
NSelma.ns.cloudflare.com, john.ns.cloudflare.com
MX
1 aspmx.l.google.com
5 alt2.aspmx.l.google.com
5 alt1.aspmx.l.google.com
10 alt3.aspmx.l.google.com
10 alt4.aspmx.l.google.com
TXT
yandex-verification=c063347f6cfa2030
zendeskverification=dde00c30d16a212a
google-site-verification=LJqQfNstOGKp8ZybvSxRtxs3z8golzH6BW_czUqi4MA
DirectFedAuthUrl=https://sso.simpleswap.io/realms/simpleswap-sso/protocol/saml
atlassian-domain-verification=VCo1o6vlBJW//0EbQ81rqtL66XWIX5SxFJi2oOY5qqITEMTUtO...
SPF v=spf1 a mx include:_spf.mlsend.com include:_spf.google.com include:mail.zendesk...
CAALookup not available with standard resolver
Resolved in 9 ms

Multiple A records provide failover if one server goes down.

Why this matters

Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.

Learn more

Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.

Source: SRE practice / DNS architecture

A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
DNSSEC
Signed and validating
PASS
Signed and validating
Info::
DNSSEC fully signed and chain validates (ECDSAP256SHA256)
A+
Multi-Resolver DNS Speed
Mean 7ms across 3 resolvers (spread 11ms)
PASS
Mean 7ms across 3 resolvers (spread 11ms)
Info::
Quad9: 2ms
Got: 2ms via 9.9.9.9:53
Info::
Cloudflare: 6ms
Got: 6ms via 1.1.1.1:53
Info::
Google: 13ms
Got: 13ms via 8.8.8.8:53
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://simpleswap.io/?id=jvw7l9dn7nk6aj4j

https://simpleswap.io/?id=jvw7l9dn7nk6aj...

946 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://simpleswap.io/?id=jvw7l9dn7nk6aj...200946 msHTTP/1.1QRATOR
A+
Crawlability
robots.txt present, sitemap with 22 URLs
PASS
robots.txt present, sitemap with 22 URLs
Info::
robots.txt is present
Got: 436 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 22 entries
Info::
Sitemap index with 22 child sitemaps
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 436 B Sitemaps referenced 1 User-agents Bingbot, Slurp, * Blocking No — crawling allowed
User-agent: *
Disallow: */forgot-password*
Disallow: */password-reset*
Disallow: /api/
Disallow: /500.html
Disallow: */?__cf_*

User-agent: Bingbot
Disallow: */forgot-password*
Disallow: */password-reset*
Disallow: /api/
Disallow: /500.html
Disallow: */?__cf_*

User-agent: Slurp
Disallow: */forgot-password*
Disallow: */password-reset*
Disallow: /api/
Disallow: /500.html
Disallow: */?__cf_*

Sitemap: https://simpleswap.io/sitemap.xml
A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Info::
HTTP correctly redirects to HTTPS permanently
Got: HTTP 301

www / non-www

301https://www.simpleswap.io/
200https://simpleswap.io/

Preferred variant: non-www

HTTP → HTTPS

301http://simpleswap.io/ https://simpleswap.io/

Consistent

A+
Domain Intelligence
simpleswap.io — via GoDaddy.com, LLC, 8 years, 6 months old, hosted on QRATOR-SW - Qrator Labs CZ s.r.o., CZ
PASS
simpleswap.io — via GoDaddy.com, LLC, 8 years, 6 months old, hosted on QRATOR-SW - Qrator Labs CZ s.r.o., CZ
Info::
Domain registered until Apr 10, 2029 (2 years, 7 months remaining)
Info::
Registrar: GoDaddy.com, LLC
Info::
Registrar lock is enabled
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Info::
Hosting: QRATOR-SW - Qrator Labs CZ s.r.o., CZ
Got: AS209671
Domain expiry

957 days

April 10, 2029

SSL certificate

120 days

Issued by Sectigo Limited

Domain age

8 years, 6 months

Registered April 10, 2018

DNSSEC

Status unknown

Protects against DNS spoofing

Hosting

QRATOR-SW - Qrator Labs CZ s.r.o., CZ

ASN AS209671

185.104.209.24

Registrar

GoDaddy.com, LLC

Locked 2 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Registrar GoDaddy.com, LLC
Created April 10, 2018 (8 years, 6 months ago)
Expires April 10, 2029 (2 years, 7 months)
Last Updated August 17, 2026
Name Servers john.ns.cloudflare.com, elma.ns.cloudflare.com
Registrant Domains By Proxy, LLC
Hosting
IP Address 185.104.209.24
ASN AS209671 (QRATOR-SW - Qrator Labs CZ s.r.o., CZ)
Provider QRATOR-SW - Qrator Labs CZ s.r.o., CZ
Data source: whois (0.4s)

Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.

Why this matters

Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback