Redirects to www.google.com

That is the address visitors actually land on, so the certificate, security headers, and public files were checked there. Some sites serve a different certificate on each address.

86 / 100
google.com just checked
Pass 20 Warning 6 Critical 0

Risk signals

Risk signals None found

Nothing stood out. That is not a guarantee of safety — only public information was examined.

Domain age 28 years (1997-09-15 registered)

The domain has been maintained for a long time.

Certificate issued 30 days ago

Certificates are renewed regularly, so a recent date on its own is normal.

Signs of real operation mail configured · SPF present

Mail is properly configured too — not something hastily built sites usually bother with.

Who serves this site

DNS provider Google

DNS records are managed here — this is where you log in to add or change them.

ns3.google.com · ns4.google.com · ns2.google.com
CDN / edge Google

Requests pass through this layer before reaching the real server. It also hides the origin from visitors.

Origin host (estimated) rj-in-f102.1e100.net

Estimated from the IP registration. A CDN in front makes the true origin invisible from outside, which is the safer arrangement.

IP 142.251.24.113 · 142.251.24.102
Mail provider Google

This service handles mail for the domain. Follow its documentation when setting SPF and DMARC.

Certificate & encryption

Certificate expiry 53 days left (2026-09-21)

Plenty of validity left.

Issued by Google Trust Services
Certificate coverage www.google.com

This domain is covered by the certificate.

Legacy TLS TLS 1.0/1.1 disabled

Obsolete protocol versions are switched off.

Email security (anti-spoofing)

SPF Configured · DNS lookups 1/10 max

A sender policy is published and closed off correctly.

v=spf1 include:_spf.google.com ~all
DMARC p=reject

Spoofed mail is quarantined or rejected.

v=DMARC1; p=reject; rua=mailto:[email protected]
DKIM Found: google

Outgoing mail is signed, so recipients can verify it was not forged.

Mail servers (MX) 10 smtp.google.com.

These servers receive mail for the domain.

MTA-STS Enabled

Mail transport encryption is enforced, blocking downgrade attacks in transit.

TLS-RPT Enabled

Reports arrive when mail encryption fails, so problems get noticed.

Mail transport encryption (STARTTLS) Supported (smtp.google.com)

Mail to this domain travels over an encrypted channel. Verified by connecting to the actual server.

DNS configuration

CAA 1 record(s)

Only the listed authorities may issue certificates for this domain.

DNSSEC Not enabled

DNS answers cannot be verified against tampering. Not mandatory, but worth enabling.

How to fix
Most registrars enable DNSSEC with a single switch.
DNS propagation Consistent worldwide

All four resolvers queried return the same address.

Google 142.250.23.100/142.250.23.101/142.250.23.102/142.250.23.113/142.250.23.138 · Cloudflare no answer · Quad9 no answer · KT no answer

HTTP security headers

HSTS Not set

Without HSTS, a first visit over plain HTTP can be intercepted.

How to fix
add_header Strict-Transport-Security "max-age=31536000" always;
CSP Not set

No policy limits which scripts may run, which is the main defence against XSS.

How to fix
add_header Content-Security-Policy "default-src 'self'" always;
MIME sniffing protection Not set

Browsers may guess file types and execute something unintended.

How to fix
add_header X-Content-Type-Options "nosniff" always;
Clickjacking protection Configured

Other sites cannot silently frame your pages.

Referrer policy Not set

Full URLs may leak to other sites when visitors click away.

How to fix
add_header Referrer-Policy "strict-origin-when-cross-origin" always;
Server version disclosure gws

The server version is not advertised.

Response time 298ms

The first byte arrives quickly.

Public files & access

robots.txt information leak 6 suspicious path(s)

robots.txt is a public file. Paths listed here are not hidden — they are advertised to anyone who reads it.

/trends/beta · /urchin_test/ · /accounts/ClientLogin · /compressiontest/ · /maps/reserve/manage
How to fix
Remove those lines. Block access at the web server (403/404) and use a noindex tag on pages you only want kept out of search.
security.txt Present

A public contact is published for reporting security issues.

Sitemap 22

Search engines can find the page list directly.

HTTP → HTTPS redirect No redirect (200)

The site still answers over unencrypted HTTP.

How to fix
Return a 301 redirect from port 80 to the https address.

Domain registration

Domain expiry 2028-09-14 (777 days left)

Registration has time left.

Registered 1997-09-15

Only public information is read (DNS records, certificates, HTTP responses). Nothing is logged in, and no load is placed on the site.

© 2026 WebsiteInfo