{
    "ok": true,
    "domain": "govexec.com",
    "generated_at": "2026-08-09T18:43:52-05:00",
    "cache": {
        "hit": true,
        "ttl": 0
    },
    "score": {
        "total": 75,
        "label": "Good",
        "categories": {
            "dns": 70,
            "mail": 90,
            "security": 69,
            "network": 20,
            "availability": 100
        },
        "category_weights": {
            "dns": 25,
            "mail": 20,
            "security": 25,
            "network": 10,
            "availability": 20
        },
        "items": [
            {
                "category": "dns",
                "title": "IPv4 (A)",
                "max_points": 30,
                "earned_points": 30,
                "lost_points": 0,
                "detail": "1 IPv4 address(es) detected."
            },
            {
                "category": "dns",
                "title": "IPv6 (AAAA)",
                "max_points": 10,
                "earned_points": 0,
                "lost_points": 10,
                "detail": "0 IPv6 address(es) detected."
            },
            {
                "category": "dns",
                "title": "Name server redundancy",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "4 NS record(s); 2 or more required."
            },
            {
                "category": "dns",
                "title": "SOA record",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "Authoritative zone record."
            },
            {
                "category": "dns",
                "title": "DNSSEC chain",
                "max_points": 15,
                "earned_points": 0,
                "lost_points": 15,
                "detail": "Both DS and DNSKEY are required."
            },
            {
                "category": "dns",
                "title": "CAA policy",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5,
                "detail": "Certificate authority restriction."
            },
            {
                "category": "dns",
                "title": "DNS propagation",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "Agreement between public resolvers."
            },
            {
                "category": "mail",
                "title": "MX records",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "1 MX record(s)."
            },
            {
                "category": "mail",
                "title": "SPF",
                "max_points": 25,
                "earned_points": 25,
                "lost_points": 0,
                "detail": "SPF policy published."
            },
            {
                "category": "mail",
                "title": "DMARC",
                "max_points": 25,
                "earned_points": 25,
                "lost_points": 0,
                "detail": "DMARC policy published."
            },
            {
                "category": "mail",
                "title": "DKIM",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "A DKIM selector was verified."
            },
            {
                "category": "mail",
                "title": "MTA-STS",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5,
                "detail": "Mail transport policy."
            },
            {
                "category": "mail",
                "title": "TLS-RPT",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5,
                "detail": "TLS reporting policy."
            },
            {
                "category": "security",
                "title": "Valid TLS certificate",
                "max_points": 55,
                "earned_points": 55,
                "lost_points": 0,
                "detail": "128 day(s) remaining."
            },
            {
                "category": "security",
                "title": "Certificate lifetime",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "Full points require at least 30 days remaining."
            },
            {
                "category": "security",
                "title": "HTTP security headers",
                "max_points": 35,
                "earned_points": 4,
                "lost_points": 31,
                "detail": "1 of 9 evaluated headers detected."
            },
            {
                "category": "network",
                "title": "PTR reverse DNS",
                "max_points": 30,
                "earned_points": 0,
                "lost_points": 30,
                "detail": "PTR not detected."
            },
            {
                "category": "network",
                "title": "IPv4 diversity",
                "max_points": 35,
                "earned_points": 20,
                "lost_points": 15,
                "detail": "Two or more IPv4 addresses receive full points."
            },
            {
                "category": "network",
                "title": "IPv6 connectivity",
                "max_points": 35,
                "earned_points": 0,
                "lost_points": 35,
                "detail": "AAAA availability."
            },
            {
                "category": "availability",
                "title": "DNS resolution",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0,
                "detail": "At least one address family must resolve."
            },
            {
                "category": "availability",
                "title": "HTTP response",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0,
                "detail": "HTTP/2 200 "
            },
            {
                "category": "availability",
                "title": "HTTPS final URL",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "Final URL uses HTTPS."
            }
        ],
        "methodology": "Each category is normalized to 100. The total is the weighted sum: DNS 25%, Email 20%, Security 25%, Network 10%, Availability 20%.",
        "diagnostics": [
            {
                "level": "ok",
                "title": "IPv4 (A)",
                "detail": "1 IPv4 address(es) detected.",
                "category": "dns",
                "max_points": 30,
                "earned_points": 30,
                "lost_points": 0
            },
            {
                "level": "error",
                "title": "IPv6 (AAAA)",
                "detail": "0 IPv6 address(es) detected.",
                "category": "dns",
                "max_points": 10,
                "earned_points": 0,
                "lost_points": 10
            },
            {
                "level": "ok",
                "title": "Name server redundancy",
                "detail": "4 NS record(s); 2 or more required.",
                "category": "dns",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "SOA record",
                "detail": "Authoritative zone record.",
                "category": "dns",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "error",
                "title": "DNSSEC chain",
                "detail": "Both DS and DNSKEY are required.",
                "category": "dns",
                "max_points": 15,
                "earned_points": 0,
                "lost_points": 15
            },
            {
                "level": "error",
                "title": "CAA policy",
                "detail": "Certificate authority restriction.",
                "category": "dns",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5
            },
            {
                "level": "ok",
                "title": "DNS propagation",
                "detail": "Agreement between public resolvers.",
                "category": "dns",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "MX records",
                "detail": "1 MX record(s).",
                "category": "mail",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "SPF",
                "detail": "SPF policy published.",
                "category": "mail",
                "max_points": 25,
                "earned_points": 25,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "DMARC",
                "detail": "DMARC policy published.",
                "category": "mail",
                "max_points": 25,
                "earned_points": 25,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "DKIM",
                "detail": "A DKIM selector was verified.",
                "category": "mail",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            },
            {
                "level": "error",
                "title": "MTA-STS",
                "detail": "Mail transport policy.",
                "category": "mail",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5
            },
            {
                "level": "error",
                "title": "TLS-RPT",
                "detail": "TLS reporting policy.",
                "category": "mail",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5
            },
            {
                "level": "ok",
                "title": "Valid TLS certificate",
                "detail": "128 day(s) remaining.",
                "category": "security",
                "max_points": 55,
                "earned_points": 55,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "Certificate lifetime",
                "detail": "Full points require at least 30 days remaining.",
                "category": "security",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "warning",
                "title": "HTTP security headers",
                "detail": "1 of 9 evaluated headers detected.",
                "category": "security",
                "max_points": 35,
                "earned_points": 4,
                "lost_points": 31
            },
            {
                "level": "error",
                "title": "PTR reverse DNS",
                "detail": "PTR not detected.",
                "category": "network",
                "max_points": 30,
                "earned_points": 0,
                "lost_points": 30
            },
            {
                "level": "warning",
                "title": "IPv4 diversity",
                "detail": "Two or more IPv4 addresses receive full points.",
                "category": "network",
                "max_points": 35,
                "earned_points": 20,
                "lost_points": 15
            },
            {
                "level": "error",
                "title": "IPv6 connectivity",
                "detail": "AAAA availability.",
                "category": "network",
                "max_points": 35,
                "earned_points": 0,
                "lost_points": 35
            },
            {
                "level": "ok",
                "title": "DNS resolution",
                "detail": "At least one address family must resolve.",
                "category": "availability",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "HTTP response",
                "detail": "HTTP/2 200 ",
                "category": "availability",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "HTTPS final URL",
                "detail": "Final URL uses HTTPS.",
                "category": "availability",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            }
        ]
    },
    "dns": {
        "records": {
            "A": [
                "20.119.16.4"
            ],
            "AAAA": [],
            "CNAME": [],
            "MX": [
                "1 smtp.google.com."
            ],
            "TXT": [
                "\"google-site-verification=x5dubrKpk-G76PbHu72-JNINQPs-L4KsfoXD7935PMM\"",
                "\"zvwqpbycdz3vyrc03ntmjmsrtvjbtq0s\"",
                "\"_globalsign-domain-verification=R1bvWDvJUF1gpXlmc7Q3deFwpZciil5dpJR4t-a8XM\"",
                "\"MS=ms78405439\"",
                "\"sending_domain67282=ef3e1c5534dd822e3fe37e8dc8272e92909066af2e0a6546ab43f3f7bee358a9\"",
                "\"asv=684f43fe9e7d03492348f3994a959a21\"",
                "\"yahoo-verification-key=3XfOP1744APFCTjIqlE/cmMuLoo6eNd4uT61/aeAzkU=\"",
                "\"google-site-verification=2vNAttD6fe3iSFZFU_-2tBDmQeMEMurx7OcaNkCmGQQ\"",
                "\"jamf-site-verification=M7nBRP5_hh-Nd1KDL6ON0g\"",
                "\"asv=aa9c9f0001d62fa04e0d30cad29d6cfc\"",
                "\"anthropic-domain-verification-kv37s9=xXahJhZCf7ytfOPlWshZCsIyw\"",
                "\"ZOOM_verify_7QVk1SgzrANVvSaqiwghxJ\"",
                "\"jamf-site-verification=4YurRdRBxorADCQ-wyC7hA\"",
                "\"MS=ms74830737\"",
                "\"adobe-idp-site-verification=ff6c87347fa649443316e546e25404d4a5b16ed4de3350820d8109afd359455d\"",
                "\"google-site-verification=Wk2HF3OsmIGO6szVkbvEc3LeLM6WCPw9ZmpThUfJwOY\"",
                "\"facebook-domain-verification=vwzfzptvdn9aze53xj0liz1n7jopcj\"",
                "\"v=spf1 include:_spf.govexec.com ~all\"",
                "\"apple-domain-verification=GBLzAx9B2hA2OoWS\"",
                "\"kxh03mhgd2xgch4q7q7c14s2pmygsftw\"",
                "\"adobe-idp-site-verification=f7cee942-f8c3-4d10-809d-c8c42d2b6386\"",
                "\"google-site-verification=nczHxlPmadvHhlt15IF0xYyXgi_I9jrBzWtMsaSjUCU\""
            ],
            "NS": [
                "ns3-05.azure-dns.org.",
                "ns1-05.azure-dns.com.",
                "ns2-05.azure-dns.net.",
                "ns4-05.azure-dns.info."
            ],
            "SOA": [
                "ns1-05.azure-dns.com. premiumdns.support.neustar. 2019092097 28800 7200 1209600 86400"
            ],
            "CAA": [],
            "DS": [],
            "DNSKEY": [],
            "RRSIG": [],
            "NSEC": [],
            "NSEC3": [],
            "SRV": [],
            "NAPTR": [],
            "TLSA": [],
            "SSHFP": []
        },
        "ipv4": [
            "20.119.16.4"
        ],
        "ipv6": []
    },
    "mail": {
        "spf": "v=spf1 include:_spf.govexec.com ~all",
        "dmarc": "v=DMARC1; p=quarantine; fo=1; rua=mailto:rua@govexec.com;",
        "dkim_selector": "google",
        "dkim_host": "google._domainkey.govexec.com",
        "dkim": "v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAhAo0/AQOd90WDvushrQgsmNP04tlhfvRuMy9DBBG7SCRDL2hd1u/2Q4qPTWJj7xzSpviQ8vSDfU2FxBH7OH+4IoJnX1OC1v3rYJGoS/q6HlJYf2MndCsKhFd7AvU35zlQHCAb666z+pb2ZBgqYnRNZAie1w0qtrcWg5VPpTZFgyZbPLAa65JTL/u5K6a7XIiaFIyZAwGgFfh/c20GQH5c4jERgG/DjkTQq/vdDdI3lZn8wBP0pd/8H0Qs1xYMzYvyl9BYLmJcnl/0hXHdGFz/lLd9ck894Kw0N9Hswp90ttayzCNwRD7dRSVENEBz9b7GB9m3Vqx3LlCE6705SVoqwIDAQAB",
        "spf_analysis": {
            "valid": true,
            "lookups": 1,
            "final": "~all",
            "message": "Within the estimated limit"
        },
        "dmarc_analysis": {
            "valid": true,
            "policy": "quarantine"
        },
        "bimi": "",
        "mta_sts": "",
        "tls_rpt": ""
    },
    "advanced": {
        "ptr": "",
        "propagation": {
            "consistent": true,
            "results": [
                {
                    "provider": "Google",
                    "server": "8.8.8.8",
                    "result": [
                        "20.119.16.4"
                    ],
                    "time_ms": 51.25
                },
                {
                    "provider": "Cloudflare",
                    "server": "1.1.1.1",
                    "result": [
                        "20.119.16.4"
                    ],
                    "time_ms": 44.76
                },
                {
                    "provider": "Quad9",
                    "server": "9.9.9.9",
                    "result": [
                        "20.119.16.4"
                    ],
                    "time_ms": 39.9
                },
                {
                    "provider": "OpenDNS",
                    "server": "208.67.222.222",
                    "result": [
                        "20.119.16.4"
                    ],
                    "time_ms": 106.38
                },
                {
                    "provider": "AdGuard",
                    "server": "94.140.14.14",
                    "result": [
                        "20.119.16.4"
                    ],
                    "time_ms": 75.28
                }
            ]
        }
    },
    "ssl": {
        "available": true,
        "issuer": "DigiCert Inc",
        "subject": "govexec.com",
        "valid_from": "2026-06-14T19:00:00-05:00",
        "valid_to": "2026-12-15T17:59:59-06:00",
        "days_remaining": 128,
        "san": [
            "govexec.com"
        ],
        "protocol": "TLSv1.3",
        "cipher": "TLS_AES_256_GCM_SHA384"
    },
    "http": {
        "url": "https://www.govexec.com/",
        "status": "HTTP/2 200 ",
        "http_version": "3",
        "headers": {
            "content-length": "233025",
            "content-type": "text/html; charset=utf-8",
            "date": "Sun, 09 Aug 2026 23:43:44 GMT",
            "server": "nginx/1.29.8",
            "location": "https://www.govexec.com/",
            "expires": "Sun, 09 Aug 2026 23:45:27 GMT",
            "vary": "Cookie",
            "last-modified": "Sun, 09 Aug 2026 23:30:27 GMT",
            "cache-control": "max-age=900",
            "xkey": "page-homepage page site-1",
            "x-varnish": "198844742 197276884",
            "age": "121",
            "via": "1.1 varnish-7789d6db5-wcp65 (Varnish/7.6)",
            "strict-transport-security": "max-age=31536000; includeSubDomains",
            "x-azure-ref": "20260809T234344Z-16d9dd57b56k85mrhC1CHIrp1s0000000b8g000000002gzt",
            "x-cache": "CONFIG_NOCACHE",
            "accept-ranges": "bytes"
        },
        "security_checks": {
            "strict-transport-security": true,
            "content-security-policy": false,
            "x-content-type-options": false,
            "x-frame-options": false,
            "referrer-policy": false,
            "permissions-policy": false,
            "cross-origin-opener-policy": false,
            "cross-origin-embedder-policy": false,
            "cross-origin-resource-policy": false
        },
        "server": "nginx/1.29.8",
        "powered_by": ""
    },
    "webpage": {
        "url": "https://www.govexec.com/",
        "title": "Government News, Research and Events for Federal Employees - GovExec.com",
        "description": "Government Executive is the leading source for news, information and analysis about the operations of the executive branch of the federal government.",
        "success": true,
        "error": "",
        "status": 206
    },
    "network": {
        "20.119.16.4": {
            "success": true,
            "country": "United States",
            "country_code": "US",
            "region": "District of Columbia",
            "city": "Washington",
            "latitude": 38.89511,
            "longitude": -77.03637,
            "asn": 8075,
            "organization": "Microsoft Corporation",
            "isp": "Microsoft Corporation",
            "timezone": "America/New_York"
        }
    },
    "smtp": {
        "host": "smtp.google.com",
        "ports": [
            {
                "port": 25,
                "open": false,
                "time_ms": 21.9,
                "banner": "220 mx.google.com ESMTP 46e09a7af769-7f35b86d20dsi6984087a34.128 - gsmtp",
                "error": "No connection"
            },
            {
                "port": 465,
                "open": false,
                "time_ms": 4010.6,
                "banner": "",
                "error": "Connection timed out"
            },
            {
                "port": 587,
                "open": false,
                "time_ms": 4007.1,
                "banner": "",
                "error": "Connection timed out"
            }
        ]
    },
    "visitor": {
        "ip": "216.73.217.62",
        "reverse": "",
        "country": "",
        "country_code": "",
        "region": "",
        "city": "",
        "latitude": null,
        "longitude": null,
        "isp": "",
        "organization": "",
        "asn": "",
        "timezone": "",
        "browser": "Other",
        "os": "Other",
        "language": "",
        "user_agent": "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)",
        "is_bot": true,
        "cloudflare": false
    },
    "analysis_time_ms": 79.84
}