~/d/gitlab.com

// gitlab.com

Live audit across 8 checks. Cached 24h · generated less than a minute ago.

domain_grade
B
good
77
/ 100 · across 8 checks
// points lost on:
security headers −12 ssl −8 dnssec −3
[ save & monitor ]
SSL Certificate
[ WARN ]
Expires in 20 days. Schedule renewal.
Issued by Sectigo RSA Domain Validation Secure Server CA · 20 days left · TLSv1.3
→ open SSL Certificate tool
DMARC Policy
[ OK ]
Strict DMARC policy enforced. Spoofed mail is rejected.
v=DMARC1; p=reject; pct=100
→ open DMARC Policy tool
SPF Record
[ OK ]
Strict SPF (-all). Unauthorized senders are rejected.
8 lookups · all=-all
→ open SPF Record tool
MX Records
[ OK ]
MX configured. Detected provider: Google Workspace.
1 aspmx.l.google.com · 5 alt1.aspmx.l.google.com · 5 alt2.aspmx.l.google.com
→ open MX Records tool
Name Servers
[ OK ]
2 authoritative nameservers
diva.ns.cloudflare.com · jermaine.ns.cloudflare.com
WHOIS
[ OK ]
Valid for 269 more days.
Registrar: Gandi SAS · expires 2027-01-15
→ open WHOIS tool
Security Headers
[ CRIT ]
Weak security posture (17/100) — missing: CSP, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Score 17/100
→ open Security Headers tool
DNSSEC
[ WARN ]
No DNSSEC — domain is not signed.
Not signed
→ open DNSSEC tool
[ embed_grade_badge ]
grade badge
Domain grade: B — good
markdown (github readme)
[![DomBrains grade](https://dombrains.com/badge/gitlab.com/grade.svg)](https://dombrains.com/d/gitlab.com)
html (any webpage)
<a href="https://dombrains.com/d/gitlab.com"><img src="https://dombrains.com/badge/gitlab.com/grade.svg" alt="DomBrains grade: B"></a>
// re-queries our scoring engine · cached 1h at the edge · backlinks to this profile page
[ per_check_badges ]
ssl badge <img src="https://dombrains.com/badge/gitlab.com/ssl">
dmarc badge <img src="https://dombrains.com/badge/gitlab.com/dmarc">
spf badge <img src="https://dombrains.com/badge/gitlab.com/spf">
mx badge <img src="https://dombrains.com/badge/gitlab.com/mx">
dnssec badge <img src="https://dombrains.com/badge/gitlab.com/dnssec">
security_headers badge <img src="https://dombrains.com/badge/gitlab.com/security_headers">
// Snapshot freshness: this page is cached 24h. To force a re-scan, run any tool above with the same domain — that always queries live.