Skip to content
https://ups.com

Infrastructure

· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
89
GRADE
B
FIX
1
REVIEW
3
PASS
5
INFO
0
Probed from Santa Clara, United States
301 Moved Permanently
Checks
9
5 PASS 3 REVIEW 1 FIX
D
CDN & Delivery
Action
No CDN detected
FIX
No CDN detected
Warning::
No CDN detected
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN detected

Consider using a CDN to improve global delivery speed and reduce origin load.

C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
Crawlability
no robots.txt, no sitemap
REVIEW
no robots.txt, no sitemap
Info::
No robots.txt found
robots.txt is optional but recommended. It tells search engine crawlers which pages to index.
Info::
No sitemap.xml found
A sitemap helps search engines discover and index your pages more efficiently.

robots.txt is optional but recommended. It tells search engine crawlers which pages to index.

Why this matters

No robots.txt — crawlers fetch /robots.txt and get 404; not breaking but means default crawl behavior with no directives or sitemap reference.

Learn more

A minimal robots.txt with `User-agent: * / Allow: / / Sitemap: https://example.com/sitemap.xml` covers the basics. Without it, crawlers behave fine but lose the sitemap signal and can't be selectively blocked from crawl-traps.

Source: robotstxt.org

A sitemap helps search engines discover and index your pages more efficiently.

Why this matters

No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.

Learn more

A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.

Source: sitemaps.org / Google Search Central

robots.txt No robots.txt found

No robots.txt found

This is fine for most sites — a missing robots.txt allows all crawling by default.

sitemap.xml No sitemap found

No sitemap found

Adding a sitemap helps search engines discover your pages.

B
TLS Certificate Expiry & Recommendations
237 days until leaf cert expires — 2 issues to address
REVIEW

Certificate validity

237
days left
0d 30d 60d 90d+

Recommended actions

  • Submit your domain to hstspreload.org to be added to the Chrome preload list
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+
DNS Records
2 A records, 198 ms lookup
PASS
2 A records, 198 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 153.2.228.130, 153.2.224.130
Info::
No IPv6 (AAAA) records
Info::
6 nameserver(s) configured
Got: nsa.ups.com, nsb.ups.com, cbru.br.ns.els-gms.att.net, cmtu.mt.ns.els-gms.att.net, auth1.dns.cogentco.com, auth2.dns.cogentco.com
Info::
2 mail exchanger(s) configured
Info::
CAA records not checked
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Info::
SPF record present in TXT
Info::
DNS resolution time: 198 ms
Got: 198 ms
A153.2.228.130, 153.2.224.130
AAAA
CNAME
NSnsa.ups.com, nsb.ups.com, cbru.br.ns.els-gms.att.net, cmtu.mt.ns.els-gms.att.net, auth1.dns.cogentco.com, auth2.dns.cogentco.com
MX
10 mxb-002b8001.gslb.pphosted.com
10 mxa-002b8001.gslb.pphosted.com
TXT
_p81wgziq3en9j1y08bgl22enp2zxtja
_rydlwrwlr54u9u772rfeonu2s6ptkou
apple-domain-verification=edIJCYjoGulFOG0z
docusign=22f44e31-1d36-4570-85e3-f80bebf73583
docusign=6ba49f2d-39c3-4314-9d71-effdc9bd2256
docusign=c4f64023-709f-42ad-b67a-ef340b6ee64e
docusign=d4cfe06f-650e-4c4c-a946-acaaacb806ab
jamf-site-verification=hw8-VnJi2jXZlB8d_Ycx3A
canva-site-verification=0t2T76468Fz8XdjfppeuCA
ms-domain-verification=80c37544-9962-4dd8-8bf1-06ea029a5e1b
smartsheet-site-validation=3y1yM9Y8zl3Zpj3gXBHCwLmiOaRpheST
unity-sso-verification=bbc1ce19-da05-4eb6-b261-673b0a7d17b3
onetrust-domain-verification=a72ec7481ed44f258ff6a26c7d39ec29
onetrust-domain-verification=ca76068e041d442dabdc2eb32bda9440
globalsign-domain-verification=59f05bd80057c98bf0a778055999d8e2
globalsign-domain-verification=e7f81fe8aa411bfe441765ebffb8b397
adobe-idp-site-verification=eef08e93-4fdf-4906-a2e7-ac21e5d6e7be
omnissa-connect-verification-fe419b26-eeb6-47f5-ba4b-1aff2e77c373
google-site-verification=9463fifxtUPXABeIJw2wUUmoIgqt9HTbadpS54HHuu4
google-site-verification=Ql2LZ5Cjd3SbzB_fnwvH8Aa7ycNDWIMrnDk_fGxqElo
google-site-verification=wjCOQ4ZX-dXduhHgn7A_BORRu-m4uE7UaF-8WrLTDwg
h1-domain-verification=UGPvQeXGCssoY6xN93tCEsSTLLFQAyLnasVUvrr5nnUMpHi6
wPLi4qnnaEKeqRySYuFzWZw8p1H87l3LBJwHQJo+/qiD93TE/IsBr9rO/UI89488KEvWgwXs5j/8vjvX...
wiz-domain-verification=be49a81b664f5e86a985ef6fc12c2f48f155f9ff2b24602666069347...
Dynatrace-site-verification=6804e173-b6f7-434a-9911-d4785de89104__jkn9ikqla8c2cm...
Dynatrace-site-verification=6c7493f5-c875-49a2-b56a-7d444ceabfd5__3mv8veqcrv2adt...
cisco-ci-domain-verification=4cee9d0ed8d9970a23624898d87e2a01b9e48b154d568878bb0...
postman-domain-verification=b3daf24645d4a3a9a800b43265ead7ff38254b1facc357e3e339...
SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:spf-002b8001.pphoste...
CAALookup not available with standard resolver
Resolved in 198 ms

CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.

Why this matters

Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.

A+
Redirect Chain
0 redirect(s), 233 ms total
PASS
0 redirect(s), 233 ms total

https://ups.com

233 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://ups.com301233 msHTTP/1.1Apache
A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
HTTP correctly 301-redirects to HTTPS

www / non-www

https://www.ups.com/
200https://ups.com/

HTTP → HTTPS

301http://ups.com/ https://www.ups.com/

Consistent

A+
Domain Intelligence
ups.com — via CSC Corporate Domains, Inc., 34 years, 6 months old, hosted on UPS - UNITED PARCEL SERVICE, US
PASS
ups.com — via CSC Corporate Domains, Inc., 34 years, 6 months old, hosted on UPS - UNITED PARCEL SERVICE, US
Info::
Domain registered until Apr 8, 2035 (9 years, 1 months remaining)
Info::
DNSSEC is enabled
Info::
Registrar: CSC Corporate Domains, Inc.
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Info::
Hosting: UPS - UNITED PARCEL SERVICE, US
Got: AS12217
Domain expiry

3156 days

April 8, 2035

SSL certificate

237 days

Issued by COMODO CA Limited

Domain age

34 years, 6 months

Registered April 7, 1992

DNSSEC

Enabled

Protects against DNS spoofing

Hosting

UPS - UNITED PARCEL SERVICE, US

ASN AS12217

153.2.224.130

Registrar

CSC Corporate Domains, Inc.

Unlocked 6 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar CSC Corporate Domains, Inc.
Created April 7, 1992 (34 years, 6 months ago)
Expires April 8, 2035 (9 years, 1 months)
Last Updated June 25, 2025
Name Servers auth1.dns.cogentco.com, auth2.dns.cogentco.com, cbru.br.ns.els-gms.att.net, cmtu.mt.ns.els-gms.att.net, nsa.ups.com, nsb.ups.com
DNSSEC Enabled
Hosting
IP Address 153.2.224.130
ASN AS12217 (UPS - UNITED PARCEL SERVICE, US)
Provider UPS - UNITED PARCEL SERVICE, US
Data source: rdap (0.1s)

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A+
HTTP Probe Timing
Total 208 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
4 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
67 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
70 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
209 ms
Total Time Total request time from DNS lookup through full response.
209 ms

Connection waterfall

DNS Lookup 4 ms TCP Connect 67 ms TLS Handshake 70 ms Server Processing 67 ms Content Transfer 0 ms
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback