Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations62 days until leaf cert expires — 5 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 185 ms lookupPASS
| A | 23.185.0.2 |
| AAAA | 2620:12a:8001::2, 2620:12a:8000::2 |
| CNAME | — |
| NS | ns13e.ucop.edu, ns23e.ucop.edu |
| MX | 10 universityofcalifornia-edu.mail.protection.outlook.com |
| TXT | dtm-domain-verification=hveVvCa5PwcWYIJldB1Rc7XMhWbLnsTnw8o0qZWbcKk MS=ms28421482 fastly-domain-delegation-boasohhek9v7kpwjaxvt-784148-2025-04-12 SPF v=spf1 ip4:44.235.59.76 ip4:54.203.115.92 ip4:69.169.239.14/31 ip4:128.48.73.180... dtm-domain-verification=beiZoAjZdDzobf790_uQDxdwUQLErDhuD6qVxJPI7Nw yahoo-verification-key=qvMDv6IyqVkoZW7eZkqt7/6axGyWvmJxCB30w4TzNzs= google-site-verification=oUy63GM9Oe5_0-j680qkkKk8gLrj0er5ik5cjdZqR1Q |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 305 ms totalPASS
https://universityofcalifornia.edu
9 ms · HTTP/1.1
https://www.universityofcalifornia.edu/
295 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://universityofcalifornia.edu | 301 | 9 ms | HTTP/1.1 | nginx |
| 2 | https://www.universityofcalifornia.edu/ | 200 | 295 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 3061 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
#
# robots.txt
#
# This file is to prevent the crawling and indexing of certain parts
# of your site by web crawlers and spiders run by sites like Yahoo!
# and Google. By telling these "robots" where not to go on your site,
# you save bandwidth and server resources.
#
# This file will be ignored unless it is at the root of your host:
# Used: http://example.com/robots.txt
# Ignored: http://example.com/site/robots.txt
#
# For more information about the robots.txt standard, see:
# http://www.robotstxt.org/robotstxt.html
User-agent: *
# CSS, JS, Images
Allow: /core/*.css$
Allow: /core/*.css?
Allow: /core/*.js$
Allow: /core/*.js?
Allow: /core/*.gif
Allow: /core/*.jpg
Allow: /core/*.jpeg
Allow: /core/*.png
Allow: /core/*.svg
Allow: /profiles/*.css$
Allow: /profiles/*.css?
Allow: /profiles/*.js$
Allow: /profiles/*.js?
Allow: /profiles/*.gif
Allow: /profiles/*.jpg
Allow: /profiles/*.jpeg
Allow: /profiles/*.png
Allow: /profiles/*.svg
# Directories
Disallow: /core/
Disallow: /profiles/
# Files
Disallow: /README.md
Disallow: /composer/Metapackage/README.txt
Disallow: /composer/Plugin/ProjectMessage/README.md
Disallow: /composer/Plugin/Scaffold/README.md
Disallow: /composer/Plugin/VendorHardening/README.txt
Disallow: /composer/Template/README.txt
Disallow: /modules/README.txt
Disallow: /sites/README.txt
Disallow: /themes/README.txt
Disallow: /web.config
# Paths (clean URLs)
Disallow: /admin/
Disallow: /comment/reply/
Disallow: /filter/tips
Disallow: /node/add/
Disallow: /search/
Disallow: /user/register
Disallow: /user/password
Disallow: /user/login
Disallow: /user/logout
Disallow: /media/oembed
Disallow: /*/media/oembed
# Paths (no clean URLs)
Disallow: /index.php/admin/
Disallow: /index.php/comment/reply/
Disallow: /index.php/filter/tips
Disallow: /index.php/node/add/
Disallow: /index.php/search/
Disallow: /index.php/user/password
Disallow: /index.php/user/register
Disallow: /index.php/user/login
Disallow: /index.php/user/logout
Disallow: /index.php/media/oembed
Disallow: /index.php/*/media/oembed
User-agent: Googlebot-News
Disallow: /infocenter
# Disallow: /uc-system
# Disallow: /support-uc
Disallow: /press-room/state-invests-22-million-uc-entrepreneurship-innovation-drive-california-economy
Disallow: /content/historic-architectural-gem-returns-uc
Disallow: /content/historic-architectural-gem-returns-uc-0
User-agent: *
Disallow: /INSTALL.txt
# Disallow: /7872wit3lks3p3s32dci9orvcd1qgf.html
Disallow: /sites/default/files/2.26.2020.At_.A.Glance.FINAL_.pdf
Disallow: /sites/default/files/uc-at-a-glance-sept-2018.pdf
Disallow: /sites/default/files/UC%20at%20a%20Glance%20-%20Feb%20%2718.pdf
Disallow: /sites/default/files/uc-at-a-glance-feb-2018-final.pdf
- https://www.universityofcalifornia.edu/
- https://www.universityofcalifornia.edu/page-not-found
- https://www.universityofcalifornia.edu/news/psychopaths-not-all-psychos
- https://www.universityofcalifornia.edu/news/dna-study-clarifies-relationship-between-polar-bears-and-brown-bears
- https://www.universityofcalifornia.edu/news/ucs-favorite-sea-slug-poised-comeback
A+Domain Intelligenceuniversityofcalifornia.edu — 24 years, 6 months oldPASS
410 days
July 31, 2027
62 days
Issued by Let's Encrypt
24 years, 6 months
Registered February 12, 2002
Status unknown
Protects against DNS spoofing
Unknown
2620:12a:8001::2
Registrar unknown