{
    "ok": true,
    "domain": "municode.com",
    "generated_at": "2026-08-09T18:33:32-05:00",
    "cache": {
        "hit": true,
        "ttl": 0
    },
    "score": {
        "total": 81,
        "label": "Good",
        "categories": {
            "dns": 85,
            "mail": 65,
            "security": 81,
            "network": 70,
            "availability": 100
        },
        "category_weights": {
            "dns": 25,
            "mail": 20,
            "security": 25,
            "network": 10,
            "availability": 20
        },
        "items": [
            {
                "category": "dns",
                "title": "IPv4 (A)",
                "max_points": 30,
                "earned_points": 30,
                "lost_points": 0,
                "detail": "2 IPv4 address(es) detected."
            },
            {
                "category": "dns",
                "title": "IPv6 (AAAA)",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "2 IPv6 address(es) detected."
            },
            {
                "category": "dns",
                "title": "Name server redundancy",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "2 NS record(s); 2 or more required."
            },
            {
                "category": "dns",
                "title": "SOA record",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "Authoritative zone record."
            },
            {
                "category": "dns",
                "title": "DNSSEC chain",
                "max_points": 15,
                "earned_points": 0,
                "lost_points": 15,
                "detail": "Both DS and DNSKEY are required."
            },
            {
                "category": "dns",
                "title": "CAA policy",
                "max_points": 5,
                "earned_points": 5,
                "lost_points": 0,
                "detail": "Certificate authority restriction."
            },
            {
                "category": "dns",
                "title": "DNS propagation",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "Agreement between public resolvers."
            },
            {
                "category": "mail",
                "title": "MX records",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "1 MX record(s)."
            },
            {
                "category": "mail",
                "title": "SPF",
                "max_points": 25,
                "earned_points": 25,
                "lost_points": 0,
                "detail": "SPF policy published."
            },
            {
                "category": "mail",
                "title": "DMARC",
                "max_points": 25,
                "earned_points": 0,
                "lost_points": 25,
                "detail": "DMARC policy not found."
            },
            {
                "category": "mail",
                "title": "DKIM",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "A DKIM selector was verified."
            },
            {
                "category": "mail",
                "title": "MTA-STS",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5,
                "detail": "Mail transport policy."
            },
            {
                "category": "mail",
                "title": "TLS-RPT",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5,
                "detail": "TLS reporting policy."
            },
            {
                "category": "security",
                "title": "Valid TLS certificate",
                "max_points": 55,
                "earned_points": 55,
                "lost_points": 0,
                "detail": "66 day(s) remaining."
            },
            {
                "category": "security",
                "title": "Certificate lifetime",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0,
                "detail": "Full points require at least 30 days remaining."
            },
            {
                "category": "security",
                "title": "HTTP security headers",
                "max_points": 35,
                "earned_points": 16,
                "lost_points": 19,
                "detail": "4 of 9 evaluated headers detected."
            },
            {
                "category": "network",
                "title": "PTR reverse DNS",
                "max_points": 30,
                "earned_points": 0,
                "lost_points": 30,
                "detail": "PTR not detected."
            },
            {
                "category": "network",
                "title": "IPv4 diversity",
                "max_points": 35,
                "earned_points": 35,
                "lost_points": 0,
                "detail": "Two or more IPv4 addresses receive full points."
            },
            {
                "category": "network",
                "title": "IPv6 connectivity",
                "max_points": 35,
                "earned_points": 35,
                "lost_points": 0,
                "detail": "AAAA availability."
            },
            {
                "category": "availability",
                "title": "DNS resolution",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0,
                "detail": "At least one address family must resolve."
            },
            {
                "category": "availability",
                "title": "HTTP response",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0,
                "detail": "HTTP/2 200 "
            },
            {
                "category": "availability",
                "title": "HTTPS final URL",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0,
                "detail": "Final URL uses HTTPS."
            }
        ],
        "methodology": "Each category is normalized to 100. The total is the weighted sum: DNS 25%, Email 20%, Security 25%, Network 10%, Availability 20%.",
        "diagnostics": [
            {
                "level": "ok",
                "title": "IPv4 (A)",
                "detail": "2 IPv4 address(es) detected.",
                "category": "dns",
                "max_points": 30,
                "earned_points": 30,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "IPv6 (AAAA)",
                "detail": "2 IPv6 address(es) detected.",
                "category": "dns",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "Name server redundancy",
                "detail": "2 NS record(s); 2 or more required.",
                "category": "dns",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "SOA record",
                "detail": "Authoritative zone record.",
                "category": "dns",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "error",
                "title": "DNSSEC chain",
                "detail": "Both DS and DNSKEY are required.",
                "category": "dns",
                "max_points": 15,
                "earned_points": 0,
                "lost_points": 15
            },
            {
                "level": "ok",
                "title": "CAA policy",
                "detail": "Certificate authority restriction.",
                "category": "dns",
                "max_points": 5,
                "earned_points": 5,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "DNS propagation",
                "detail": "Agreement between public resolvers.",
                "category": "dns",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "MX records",
                "detail": "1 MX record(s).",
                "category": "mail",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "SPF",
                "detail": "SPF policy published.",
                "category": "mail",
                "max_points": 25,
                "earned_points": 25,
                "lost_points": 0
            },
            {
                "level": "error",
                "title": "DMARC",
                "detail": "DMARC policy not found.",
                "category": "mail",
                "max_points": 25,
                "earned_points": 0,
                "lost_points": 25
            },
            {
                "level": "ok",
                "title": "DKIM",
                "detail": "A DKIM selector was verified.",
                "category": "mail",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            },
            {
                "level": "error",
                "title": "MTA-STS",
                "detail": "Mail transport policy.",
                "category": "mail",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5
            },
            {
                "level": "error",
                "title": "TLS-RPT",
                "detail": "TLS reporting policy.",
                "category": "mail",
                "max_points": 5,
                "earned_points": 0,
                "lost_points": 5
            },
            {
                "level": "ok",
                "title": "Valid TLS certificate",
                "detail": "66 day(s) remaining.",
                "category": "security",
                "max_points": 55,
                "earned_points": 55,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "Certificate lifetime",
                "detail": "Full points require at least 30 days remaining.",
                "category": "security",
                "max_points": 10,
                "earned_points": 10,
                "lost_points": 0
            },
            {
                "level": "warning",
                "title": "HTTP security headers",
                "detail": "4 of 9 evaluated headers detected.",
                "category": "security",
                "max_points": 35,
                "earned_points": 16,
                "lost_points": 19
            },
            {
                "level": "error",
                "title": "PTR reverse DNS",
                "detail": "PTR not detected.",
                "category": "network",
                "max_points": 30,
                "earned_points": 0,
                "lost_points": 30
            },
            {
                "level": "ok",
                "title": "IPv4 diversity",
                "detail": "Two or more IPv4 addresses receive full points.",
                "category": "network",
                "max_points": 35,
                "earned_points": 35,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "IPv6 connectivity",
                "detail": "AAAA availability.",
                "category": "network",
                "max_points": 35,
                "earned_points": 35,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "DNS resolution",
                "detail": "At least one address family must resolve.",
                "category": "availability",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "HTTP response",
                "detail": "HTTP/2 200 ",
                "category": "availability",
                "max_points": 40,
                "earned_points": 40,
                "lost_points": 0
            },
            {
                "level": "ok",
                "title": "HTTPS final URL",
                "detail": "Final URL uses HTTPS.",
                "category": "availability",
                "max_points": 20,
                "earned_points": 20,
                "lost_points": 0
            }
        ]
    },
    "dns": {
        "records": {
            "A": [
                "172.64.145.10",
                "104.18.42.246"
            ],
            "AAAA": [
                "2606:4700:4400::ac40:910a",
                "2a06:98c1:3105::6812:2af6"
            ],
            "CNAME": [],
            "MX": [
                "0 municode-com.mail.protection.outlook.com."
            ],
            "TXT": [
                "\"bh7eco2tu1ablh46fl6tl3kf3d\"",
                "\"v=spf1 a mx ip4:198.2.128.232 ip4:40.70.207.119 include:spf.protection.outlook.com include:mail.zendesk.com include:spf.mandrillapp.com include:spf.emailsignatures365.com include:clickbackspf.com include:spf.municodeweb.com -all\"",
                "\"adobe-idp-site-verification=49a0c9fff595e26a7a9a3aefff5e7aeb4c594a6d89be0dbeb03b28bdec84b6ef\"",
                "\"MS=ms50948674\"",
                "\"n3fnslgreat97s4d8bs8eleabu\"",
                "\"MS=ms38674299\"",
                "\"MS=ms60355508\"",
                "\"bHi1BNLoIOLPQuUMn/pPTVPsTvq+5G/ye/ITiiGyx7SJQstIMTJPKmePg6953P/Yq65vGkytnv1ff4l9HjtDDA==\"",
                "\"7o3i08hpa0ct4nmc8r712nqv94\"",
                "\"MS=ms84256387\"",
                "\"rs7o93ubp654djm9ptora942mg\"",
                "\"google-site-verification=bIw6WmuxkN7pt2ujjIntrU-pLmfZlrZ4a4UGiVPngno\"",
                "\"58b44gsm6rt9q85be96ujgd8t3\""
            ],
            "NS": [
                "cortney.ns.cloudflare.com.",
                "simon.ns.cloudflare.com."
            ],
            "SOA": [
                "cortney.ns.cloudflare.com. dns.cloudflare.com. 2410691316 10000 2400 604800 1800"
            ],
            "CAA": [
                "0 issuewild \"letsencrypt.org\"",
                "0 issue \"ssl.com\"",
                "0 issuewild \"godaddy.com\"",
                "0 issue \"comodoca.com\"",
                "0 issuewild \"pki.goog; cansignhttpexchanges=yes\"",
                "0 issue \"letsencrypt.org\"",
                "0 issuewild \"digicert.com; cansignhttpexchanges=yes\"",
                "0 issuewild \"comodoca.com\"",
                "0 iodef \"mailto:sysadmin@municode.com\"",
                "0 issuewild \"ssl.com\"",
                "0 issue \"pki.goog; cansignhttpexchanges=yes\"",
                "0 issue \"digicert.com; cansignhttpexchanges=yes\""
            ],
            "DS": [],
            "DNSKEY": [],
            "RRSIG": [],
            "NSEC": [],
            "NSEC3": [],
            "SRV": [],
            "NAPTR": [],
            "TLSA": [],
            "SSHFP": []
        },
        "ipv4": [
            "172.64.145.10",
            "104.18.42.246"
        ],
        "ipv6": [
            "2606:4700:4400::ac40:910a",
            "2a06:98c1:3105::6812:2af6"
        ]
    },
    "mail": {
        "spf": "v=spf1 a mx ip4:198.2.128.232 ip4:40.70.207.119 include:spf.protection.outlook.com include:mail.zendesk.com include:spf.mandrillapp.com include:spf.emailsignatures365.com include:clickbackspf.com include:spf.municodeweb.com -all",
        "dmarc": "",
        "dkim_selector": "selector2",
        "dkim_host": "selector2._domainkey.municode.com",
        "dkim": "v=DKIM1; k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDMZXqRzzsy3qquXmNrtkqSY6ke/btqdXoFDrHyukMsCy/ok0FUch41w82OXkV3RuSR/cojTc455ua+1oXXhkOPXHbPV6gtSvQFm4ZicARmt2SysxqtXEzwMdc9xigtlEFHrMq/1rdj1C0YTnJIIfXPmu7PWw5Gdy6Q/xNacd2zTQIDAQAB;",
        "spf_analysis": {
            "valid": true,
            "lookups": 8,
            "final": "-all",
            "message": "Within the estimated limit"
        },
        "dmarc_analysis": {
            "valid": false,
            "policy": ""
        },
        "bimi": "",
        "mta_sts": "",
        "tls_rpt": ""
    },
    "advanced": {
        "ptr": "",
        "propagation": {
            "consistent": true,
            "results": [
                {
                    "provider": "Google",
                    "server": "8.8.8.8",
                    "result": [
                        "104.18.42.246",
                        "172.64.145.10"
                    ],
                    "time_ms": 59.45
                },
                {
                    "provider": "Cloudflare",
                    "server": "1.1.1.1",
                    "result": [
                        "104.18.42.246",
                        "172.64.145.10"
                    ],
                    "time_ms": 28.43
                },
                {
                    "provider": "Quad9",
                    "server": "9.9.9.9",
                    "result": [
                        "104.18.42.246",
                        "172.64.145.10"
                    ],
                    "time_ms": 37.75
                },
                {
                    "provider": "OpenDNS",
                    "server": "208.67.222.222",
                    "result": [
                        "104.18.42.246",
                        "172.64.145.10"
                    ],
                    "time_ms": 131.49
                },
                {
                    "provider": "AdGuard",
                    "server": "94.140.14.14",
                    "result": [
                        "104.18.42.246",
                        "172.64.145.10"
                    ],
                    "time_ms": 85.88
                }
            ]
        }
    },
    "ssl": {
        "available": true,
        "issuer": "Let's Encrypt",
        "subject": "municode.com",
        "valid_from": "2026-07-17T01:59:42-05:00",
        "valid_to": "2026-10-15T01:59:41-05:00",
        "days_remaining": 66,
        "san": [
            "*.municode.com",
            "municode.com"
        ],
        "protocol": "TLSv1.3",
        "cipher": "TLS_AES_256_GCM_SHA384"
    },
    "http": {
        "url": "https://www.civicplus.com/municode-codification-software/",
        "status": "HTTP/2 200 ",
        "http_version": "3",
        "headers": {
            "date": "Sun, 09 Aug 2026 23:33:23 GMT",
            "content-type": "text/html; charset=UTF-8",
            "location": "https://www.civicplus.com/municode-codification-software/",
            "cache-control": "max-age=3600",
            "x-cache-original-ttl": "1209600s",
            "x-backend-age": "237234",
            "age": "0",
            "expires": "Sun, 09 Aug 2026 21:10:02 GMT",
            "x-cache": "cached",
            "x-full-url": "municode.com/",
            "x-rpid": "RP3E1A600",
            "cacheid": "2",
            "set-cookie": "__cf_bm=kGDNmCsKYjyMbig46QcMNUIwtcgb2obTTQqYvaykk8c-1786318403.4313934-1.0.1.1-OnXxo33bNkcLCZu7mrVUJZa47K.7pHuHDRK1zHi50ig6vwQCurctH9Q7unAOjtIu5l5ahT6pt1zzJmjB7tTTIPkGKzICC0_ct_v7bAOIvmN0iI3icOQJaRp.GNXg9czS; HttpOnly; SameSite=None; Secure; Path=/; Domain=www.civicplus.com; Expires=Mon, 10 Aug 2026 00:03:23 GMT",
            "cf-cache-status": "DYNAMIC",
            "server": "cloudflare",
            "cf-ray": "a28a90c5786120af-STL",
            "strict-transport-security": "max-age=63072000; includeSubDomains; preload",
            "ki-cf-cache-status": "BYPASS",
            "x-content-type-options": "nosniff",
            "x-edge-location-klb": "1",
            "ki-cache-type": "None",
            "ki-edge": "v=28.4.5;mv=99.9.9",
            "ki-origin": "o1i",
            "x-kinsta-cache": "HIT",
            "x-redirect-by": "redirection",
            "report-to": "{\"group\":\"cf-nel\",\"max_age\":604800,\"endpoints\":[{\"url\":\"https://a.nel.cloudflare.com/report/v4?s=1sXFvnYjLokc662yB8Aghv5zDbH8u9w9tQgtFaR0x6uydyYyi6zV33rybk6lanDkP5sl5EVe%2F5RndVyVn%2FcnYSRI%2FCM0DWVy2ozz7NZy0ovi8b%2B8FieMBpIqvhFp7mXwcv8P\"}]}",
            "nel": "{\"report_to\":\"cf-nel\",\"success_fraction\":0.01,\"max_age\":604800}",
            "alt-svc": "h3=\":443\"; ma=86400",
            "link": "<https://www.civicplus.com/wp-json/>; rel=\"https://api.w.org/\", <https://www.civicplus.com/wp-json/wp/v2/pages/30286>; rel=\"alternate\"; title=\"JSON\"; type=\"application/json\", <https://www.civicplus.com/?p=30286>; rel=shortlink",
            "vary": "Accept-Encoding",
            "referrer-policy": "unsafe-url",
            "x-frame-options": "SAMEORIGIN",
            "x-xss-protection": "1; mode=block"
        },
        "security_checks": {
            "strict-transport-security": true,
            "content-security-policy": false,
            "x-content-type-options": true,
            "x-frame-options": true,
            "referrer-policy": true,
            "permissions-policy": false,
            "cross-origin-opener-policy": false,
            "cross-origin-embedder-policy": false,
            "cross-origin-resource-policy": false
        },
        "server": "cloudflare",
        "powered_by": ""
    },
    "webpage": {
        "url": "https://www.civicplus.com/municode-codification-software/",
        "title": "Municode Municipal Code Management for Governments - CivicPlus",
        "description": "Publish your municipal code online with CivicPlus. Provide your community and staff with a fully searchable, accessible, and mobile-friendly digital code.",
        "success": true,
        "error": "",
        "status": 200
    },
    "network": {
        "172.64.145.10": {
            "success": true,
            "country": "United States",
            "country_code": "US",
            "region": "California",
            "city": "San Francisco",
            "latitude": 37.7749113,
            "longitude": -122.4185412,
            "asn": 13335,
            "organization": "Cloudflare, Inc.",
            "isp": "Cloudflare, Inc.",
            "timezone": "America/Los_Angeles"
        },
        "104.18.42.246": {
            "success": true,
            "country": "United States",
            "country_code": "US",
            "region": "California",
            "city": "San Francisco",
            "latitude": 37.7749113,
            "longitude": -122.4185412,
            "asn": 13335,
            "organization": "Cloudflare, Inc.",
            "isp": "Cloudflare, Inc.",
            "timezone": "America/Los_Angeles"
        }
    },
    "smtp": {
        "host": "municode-com.mail.protection.outlook.com",
        "ports": [
            {
                "port": 25,
                "open": false,
                "time_ms": 25.9,
                "banner": "",
                "error": "Network is unreachable"
            },
            {
                "port": 465,
                "open": false,
                "time_ms": 4020.6,
                "banner": "",
                "error": "Connection timed out"
            },
            {
                "port": 587,
                "open": false,
                "time_ms": 4054,
                "banner": "",
                "error": "Connection timed out"
            }
        ]
    },
    "visitor": {
        "ip": "216.73.217.62",
        "reverse": "",
        "country": "",
        "country_code": "",
        "region": "",
        "city": "",
        "latitude": null,
        "longitude": null,
        "isp": "",
        "organization": "",
        "asn": "",
        "timezone": "",
        "browser": "Other",
        "os": "Other",
        "language": "",
        "user_agent": "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@anthropic.com)",
        "is_bot": true,
        "cloudflare": false
    },
    "analysis_time_ms": 121.8
}