Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations70 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 79 ms lookupPASS
| A | 151.101.66.191, 151.101.194.191, 151.101.130.191, 151.101.2.191 |
| AAAA | — |
| CNAME | — |
| NS | ns-479.awsdns-59.com, ns-1673.awsdns-17.co.uk, ns-696.awsdns-23.net, ns-1053.awsdns-03.org |
| MX | 10 mxb-0099d701.gslb.pphosted.com 10 mxa-0099d701.gslb.pphosted.com |
| TXT | wiz-domain-verification=6878899c8ea6018c7e4d6ae1740a9e20db4f947a31fe1cdeb65a1a6a... duo_sso_verification=MVtLUiHPlIsWBatbAU4xPWoC202mg10xjgxMNiRqH7hDAlOnSJBBhp6bWKT... UX5-KQ8-TF9 apple-domain-verification=CSe6pGKtADzd2u5v facebook-domain-verification=lese4oknsyz8f9fgun8ajob5dv5y8u cursor-domain-verification-wej3xv=3l4ZKWyzVfi8NIZvrgEjVu1eq MS=D967CA80CF07AA2CDC3454F5F9F1ECC9D22FACD53600 docker-verification=a6ddafc0-e200-494c-9d85-bb235bf0aa58 jamf-site-verification=FTxEZ8bdZ-5ecYpJvHQ1kA atlassian-domain-verification=XtjxmKlbTXQpJEa9VinUmGEipF2tFNpFLRTVR9FyUQhR5jsBGo... google-site-verification=rEAr4yCbDBk5Efxyyc9mCZ2MHy_rsb2hCzxKijytBu4 google-site-verification=yMuS2AppRL8mECSmGMPwEBMpxDif0HfOK8vq4q7X8oE elevenlabs=7uxIEF33-QXx87nSOmkblcMqn-AG5StycC6nRRywzgM canva-site-verification=EB9G94gYXhiss659mHO6hg status-page-domain-verification=l31wpt6jtkbt sterling-verification=625723ede396481ab8ab714ab83939bd google-site-verification=QQO4LiOhyx4DUjKw6rV5c9jWqvOltjJx1r3hcKA2w5E MS=ms80059158 google-site-verification=7hlgUJNZxg3BdIxkjudmRixYJaFCkpHDUJw6avlROns smartsheet-gov-site-validation=fJZfH44il11NH3iDKIbGFNSukjo9DFoA bugcrowd-verification=8d4227c2a9b7e590c32cb3990d7e7200 MS=ms45766595 smartsheet-site-validation=fadQyQfN1bzmewr-QseFnmMl3m6oh06d adobe-idp-site-verification=56404acead9fe2b15256656a6bd53b05222f0bc35547b6556fe7... MS=ms68437763 wZEG4m8pElnUjo/C1IOzcI0qp3VNg9+N8Xsyv8D74lA= google-site-verification=VQ-0YEbNBu0bg4z3ocwMtf3g3fHqgxA2gIrAjwQFEuc traction-guest=036fd639-f1b6-4fa2-92eb-824a3f3425a4 anthropic-domain-verification-hxh7sf=oVyTwviNxbjr6AmbAMsL6cJHn google-site-verification=elesh0mmchyHAfw2Vktq4WjRbRhzHixaHbrlTjhdLN8 docusign=b4b97585-7d68-4397-9e07-e8c5ff9754ff cisco-ci-domain-verification=de48ad4c8b27d4819a0ddb36a703fcb74d8662cffc0947ba03c... miro-verification=01fa82b8fe6041ea7112d03669e3209a433a11db google-site-verification=teY7md1VBnLY1rgmXyzDDlBc-KRG0LaZa1TEBUGge7g SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all citrix-verification-code=cfd71eb1-8861-4881-a9f9-618fa3f3f66a stripe-verification=ada0f91d48011e0e4048bad8056de86898ff90a49858db7ab3a2e9a3492d... google-site-verification=l5GyCdkTo8Fv1TwA0yKUsiNiMAmdkVVGZ_GfDlblxkA 063a4dcb-0520-43f1-b0ad-4173a9dbbf3e logmein-verification-code=53ac3fe3-251f-4811-a0a2-5ea3b38f663c drift-domain-verification=f51bed4a8f58f49bf2870396c0092a56d5882e9f4780fd963ec783... google-site-verification=eQ4UCMktgWKYgBkHURiD9gWqgCpTVbtSX4AWzjOfXe0 stripe-verification=3c0afc0e1995abddf0ea11067182afcc073eccfb694eb7ac4b9eeffbad69... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 42 ms totalPASS
https://smartsheet.com
6 ms · HTTP/1.1
https://www.smartsheet.com/
36 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://smartsheet.com | 301 | 6 ms | HTTP/1.1 | |
| 2 | https://www.smartsheet.com/ | 200 | 36 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 5422 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: *
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /README.txt
Disallow: /web.config
# Paths (clean URLs)
Disallow: /admin/
Disallow: /admin
Disallow: /comment/reply/
Disallow: /comment/reply
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /node/add
Disallow: /search/
Disallow: /search
Disallow: /user/register/
Disallow: /user/register
Disallow: /user/password/
Disallow: /user/password
Disallow: /user/login/
Disallow: /user/login
Disallow: /user/logout/
Disallow: /user/logout
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password/
Disallow: /index.php/user/register/
Disallow: /index.php/user/login/
Disallow: /index.php/user/logout/
# Custom
Disallow: /node/
Disallow: /saml/login/
Disallow: /saml/login
Disallow: /saml/logout/
Disallow: /saml/logout
A+Domain Intelligencesmartsheet.com — via MarkMonitor Inc., 25 years, 4 months old, hosted on FastlyPASS
1400 days
April 15, 2030
70 days
Issued by Let's Encrypt
25 years, 4 months
Registered April 15, 2001
Not enabled
Protects against DNS spoofing
Fastly
ASN AS54113
151.101.194.191
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice