gitlab.com
AI Security Summary
99/100 — trusted. Long-established domain (22.6 years old), clean threat reputation, no impersonation patterns. Verdict driven by: missing Content Security Policy; large response served uncompressed — worth extra caution before trusting.
Restricts which scripts and resources the page can load.
Addressing this signal prevents trust downgrades and potential security risks.
View Glossary Guide- Site responded with 200
- HTTPS is enforced
- Fast response (236ms)
- Served through Cloudflare
- 2 address record(s) resolved
- IPv6 (AAAA) available
- 2 authoritative nameservers
- Domain registered 23+ years ago
- Missing Content Security Policy
- Large response served uncompressed
No critical issues found
Domain passes all high-risk checks
- Registrar Name
- Gandi SAS
- Creation Date
- January 15, 2004 (22.6 years ago)
- Last Updated
- December 11, 2025
- Registry Expiry Date
- January 15, 2027
- WHOIS Privacy Protection
- Publicly Visible
- Domain Status Codes
- client transfer prohibited
- IPv4 Addresses (A)
- 172.65.251.78
- IPv6 Addresses (AAAA)
- 2606:4700:90:0:f22e:fbec:5bed:a9b9
- Mail Servers (MX)
- aspmx.l.google.com (Priority: 1), alt1.aspmx.l.google.com (Priority: 5), alt2.aspmx.l.google.com (Priority: 5), alt3.aspmx.l.google.com (Priority: 10), alt4.aspmx.l.google.com (Priority: 10)
- Authoritative Nameservers (NS)
- diva.ns.cloudflare.com, jermaine.ns.cloudflare.com
- TXT Records Found
- 30 TXT verification records
- Registrable Domain
- gitlab.com
- Registrar Organization
- Gandi SAS
- WHOIS Privacy Status
- Public Registration Data
- Registry Status Codes
- client transfer prohibited
- Delegated Authoritative Nameservers
- diva.ns.cloudflare.com, jermaine.ns.cloudflare.com
- Registration Lifecycle
- Registered: 2004 → Expires: 2027
- SPF Record
- v=spf1 include:mail.zendesk.com include:_spf.google.com include:mktomail.com include:_spf.salesforce.com include:_spf-ip.gitlab.com a:zgateway.zuora.com include:mailgun.org include:_spf.sendergen.com ip4:35.80.141.6/32 ip4:44.229.121.55/32 -all
- DMARC Policy Mode
- Policy: REJECT
- DMARC Raw Record
- v=DMARC1; p=reject; pct=100; rua=mailto:dmarc_agg@vali.email;
- DKIM Selectors Detected
- google, mail
- Root Domain Label
- gitlab
- Top-Level Domain (TLD)
- .com (Standard TLD)
- Punycode Obfuscation
- No (Standard ASCII)
- Homoglyph / Lookalike Script
- No mixed scripts
- Brand Match Analysis
- No recognized brand impersonation
- Typosquatting Risk
- Clean
- HTML Title
- GitLab - Speed with control for agentic software engineering
- Meta Description
- The intelligent orchestration platform for DevSecOps, enabling teams and agents to ship trusted software at enterprise scale.
- Document Language
- en-US
- Character Encoding
- utf-8
- Viewport Setting
- width=device-width, initial-scale=1
- Generator Software
- —
- HTTP Response Time
- 236 ms
- Payload Body Size
- 220.3 KB
- Compression Status
- Uncompressed
- Cache Directives
- public, max-age=0, must-revalidate
99/100 — trusted. Long-established domain (22.6 years old), clean threat reputation, no impersonation patterns. Verdict driven by: missing Content Security Policy; large response served uncompressed — worth extra caution before trusting.
- Payment Red Flags
- None (No suspicious payment requests)
- High-Pressure Language
- None (No artificial urgency detected)
- Disposable Domain Risk
- No (Established infrastructure)
- Text Scanned Depth
- 6,881 characters verified
- Primary Web Server
- cloudflare
- CDN / Cloud Provider
- Cloudflare
- Primary IP Address
- 172.65.251.78
- HTTP Status Code
- 200 OK
- Final Landing Destination
- https://about.gitlab.com/
- Redirect Hop Count
- 1 hop
- 1.https://gitlab.com/ → https://about.gitlab.com/
- Certificate Authority (Issuer)
- C=US, O=Google Trust Services, CN=WR1
- Subject Common Name (CN)
- *.usagestats.gitlab.com
- Validity Period
- 20 days remaining (Expires: 2026-09-26T06:23:11Z)
- Subject Alternative Names (SANs)
- 40 domains protected
- Certificates Logged (CT)
- 100 certs recorded
- Published Phone Numbers
- 18972324098, 1787067438, 1787071042, 8829180 0, 1.5555555556, 1.1666666667
- Robots.txt Directives
- Present & Configured
- Sitemaps Declared
- None in robots.txt
- Disallow Rules Count
- 86 rules
View Raw robots.txt
# See http://www.robotstxt.org/robotstxt.html for documentation on how to use the robots.txt file # # To ban all spiders from the entire site uncomment the next two lines: # User-Agent: * # Disallow: / # Add a 1 second delay between successive requests to the same server, limits resources used by crawler # Only some crawlers respect this setting, e.g. Googlebot does not # Crawl-delay: 1 # Based on details in https://gitlab.com/gitlab-org/gitlab/blob/master/config/routes.rb, # https://gitlab.com/gitlab-org/gitlab/blob/master/spec/routing, and using application # Global routes User-Agent: * Disallow: /autocomplete/users Disallow: /autocomplete/projects Disallow: /search Disallow: /admin Disallow: /profile Disallow: /dashboard Disallow: /users Disallow: /api/v* Disallow: /help Disallow: /s/ Disallow: /-/profile Disallow: /-/profile/ Disallow: /-/user_settings/ Disallow: /-/ide/ Disallow: /-/experiment # Restrict allowed routes to avoid very ugly search results Allow: /users/sign_in Allow: /users/sign_up Allow: /users/*/snippets # Generic resource routes like new, edit, raw # This will block routes like: # - /projects/new # - /gitlab-org/gitlab-foss/issues/123/-/edit User-Agent: * Disallow: /*/new Disallow: /*/edit Disallow: /*/raw Disallow: /*/realtime_changes # Group details User-Agent: * Disallow: /groups/*/-/analytics Disallow: /groups/*/-/analytics/ Disallow: /groups/*/-/insights/ Disallow: /groups/*/-/issues_analytics Disallow: /groups/*/-/contribution_analytics Disallow: /groups/*/-/group_members Disallow: /groups/*/-/saml/ Disallow: /groups/*/-/saml_group_links Disallow: /groups/*/-/settings/ Disallow: /groups/*/-/billings Disallow: /groups/*/-/hooks Disallow: /groups/*/-/projects # Project details User-Agent: * Disallow: /*/*.git$ Disallow: /*/*.git/* Disallow: /*/archive/ Disallow: /*/repository/archive* Disallow: /*/activity Disallow: /*/-/project_members Disallow: /*/-/blame/ Disallow: /*/-/branches Disallow: /*/-/commits/ Disallow: /*/-/commit Disallow: /*/commit/*.patch Disallow: /*/commit/*.diff Disallow: /*/-/compare/ Disallow: /*/-/network/ Disallow: /*/path_locks Disallow: /*/merge_requests/*.patch Disallow: /*/merge_requests/*.diff Disallow: /*/merge_requests/*/diffs Disallow: /*/services Disallow: /*/uploads/ Disallow: /*/-/import Disallow: /*/-/requirements_management/ Disallow: /*/-/pipelines Disallow: /*/-/pipeline_schedules Disallow: /*/-/jobs Disallow: /*/-/ci/ Disallow: /*/-/quality/ Disallow: /*/-/licenses Disallow: /*/-/security/ Disallow: /*/-/dependencies Disallow: /*/-/audit_events Disallow: /*/-/on_demand_scans Disallow: /*/-/feature_flags Disallow: /*/-/ml/ Disallow: /*/-/environments Disallow: /*/-/clusters Disallow: /*/-/terraform Disallow: /*/-/terraform_module_registry Disallow: /*/-/*/configuration Disallow: /*/-/error_tracking Disallow: /*/-/metrics Disallow: /*/-/alert_management Disallow: /*/-/incidents Disallow: /*/-/oncall_schedules Disallow: /*/-/escalation_policies Disallow: /*/-/*/service_desk Disallow: /*/-/analytics Disallow: /*/-/analytics/ Disallow: /*/-/value_stream_analytics Disallow: /*/-/graphs/ Disallow: /*/insights/ Disallow: /*/-/pipelines/ Disallow: /*/-/settings/ Disallow: /*/-/hooks Disallow: /*/-/usage_quotas
Export & Share Intelligence
Download the complete official PDF verification report (all sections and technical signals expanded), or export raw JSON telemetry.
Scan Engine Performance
Automated multi-signal inspection pipeline