twitter.com
AI Security Summary
97/100 — trusted. Long-established domain (26.6 years old), clean threat reputation, no impersonation patterns. Verdict driven by: redirects to a different domain (x.com); no contact page found — worth extra caution before trusting.
Reputable sites usually publish a contact page.
Addressing this signal prevents trust downgrades and potential security risks.
View Glossary Guide- Site responded with 200
- HTTPS is enforced
- Fast response (185ms)
- Served through Cloudflare
- 1 address record(s) resolved
- 8 authoritative nameservers
- Domain registered 27+ years ago
- Owner information disclosed
- No contact page found
- Redirects to a different domain (x.com)
No critical issues found
Domain passes all high-risk checks
- Registrar Name
- CSC Corporate Domains, Inc.
- Creation Date
- January 21, 2000 (26.6 years ago)
- Last Updated
- January 17, 2026
- Registry Expiry Date
- January 21, 2027
- WHOIS Privacy Protection
- Publicly Visible
- Domain Status Codes
- client transfer prohibited, server delete prohibited, server transfer prohibited, server update prohibited
- IPv4 Addresses (A)
- 172.66.0.227
- IPv6 Addresses (AAAA)
- None
- Mail Servers (MX)
- aspmx.l.google.com (Priority: 1), alt1.aspmx.l.google.com (Priority: 5), alt2.aspmx.l.google.com (Priority: 5), alt3.aspmx.l.google.com (Priority: 10), alt4.aspmx.l.google.com (Priority: 10)
- Authoritative Nameservers (NS)
- a.r06.twtrdns.net, a.u06.twtrdns.net, b.r06.twtrdns.net, b.u06.twtrdns.net, c.r06.twtrdns.net, c.u06.twtrdns.net, d.r06.twtrdns.net, d.u06.twtrdns.net
- TXT Records Found
- 24 TXT verification records
- Registrable Domain
- twitter.com
- Registrar Organization
- CSC Corporate Domains, Inc.
- WHOIS Privacy Status
- Public Registration Data
- Registry Status Codes
- client transfer prohibited, server delete prohibited, server transfer prohibited, server update prohibited
- Delegated Authoritative Nameservers
- a.r06.twtrdns.net, a.u06.twtrdns.net, b.r06.twtrdns.net, b.u06.twtrdns.net, c.r06.twtrdns.net, c.u06.twtrdns.net, d.r06.twtrdns.net, d.u06.twtrdns.net
- Registration Lifecycle
- Registered: 2000 → Expires: 2027
- SPF Record
- v=spf1 ip4:199.16.156.0/22 ip4:199.59.148.0/22 ip4:8.25.194.0/23 ip4:8.25.196.0/23 ip4:204.92.114.203 ip4:204.92.114.204/31 include:_spf.google.com include:_thirdparty.twitter.com -all
- DMARC Policy Mode
- Policy: REJECT
- DMARC Raw Record
- v=DMARC1; p=reject; rua=mailto:d3omt-8484@rua.dmarc.emailanalyst.com; ruf=mailto:d3omt-8484@ruf.dmarc.emailanalyst.com; fo=1
- DKIM Selectors Detected
- Root Domain Label
- Top-Level Domain (TLD)
- .com (Standard TLD)
- Punycode Obfuscation
- No (Standard ASCII)
- Homoglyph / Lookalike Script
- No mixed scripts
- Brand Match Analysis
- Official Domain (twitter)
- Typosquatting Risk
- Clean
- HTML Title
- X. It’s what’s happening / X
- Meta Description
- From breaking news and entertainment to sports and politics, get the full story with all the live commentary.
- Document Language
- en
- Character Encoding
- utf-8
- Viewport Setting
- width=device-width,initial-scale=1,maximum-scale=1,user-scalable=0,viewport-fit=cover
- Generator Software
- —
- HTTP Response Time
- 185 ms
- Payload Body Size
- 30.2 KB
- Compression Status
- Uncompressed
- Cache Directives
- no-cache, no-store, max-age=0
97/100 — trusted. Long-established domain (26.6 years old), clean threat reputation, no impersonation patterns. Verdict driven by: redirects to a different domain (x.com); no contact page found — worth extra caution before trusting.
- Payment Red Flags
- None (No suspicious payment requests)
- High-Pressure Language
- None (No artificial urgency detected)
- Disposable Domain Risk
- No (Established infrastructure)
- Text Scanned Depth
- 438 characters verified
- Primary Web Server
- cloudflare envoy
- CDN / Cloud Provider
- Cloudflare
- Primary IP Address
- 172.66.0.227
- HTTP Status Code
- 200 OK
- Final Landing Destination
- https://x.com/
- Redirect Hop Count
- 1 hop
- 1.https://twitter.com/ → https://x.com/
- Certificate Authority (Issuer)
- Standard Trusted CA
- Subject Common Name (CN)
- twitter.com
- Validity Period
- 60 days remaining (Expires: 2026-11-04T10:52:21.923Z)
- Subject Alternative Names (SANs)
- 1 domain protected
- Certificates Logged (CT)
- 1 certs recorded
- Published Phone Numbers
- 2231777543, 333903271, 630673210, 0 0 480 490, 285.38 207.711, 462.954 1.5
- Robots.txt Directives
- Present & Configured
- Sitemaps Declared
- https://x.com/sitemap.xml
- Disallow Rules Count
- 45 rules
View Raw robots.txt
# Google / Bing Search Engine Robots # ================================== # Shared group so Googlebot and Bingbot always get the same rules. User-agent: Googlebot User-agent: Bingbot Allow: /*?s= Allow: /*?t= Allow: /*?ref_src= Allow: /hashtag/*?src= Allow: /search?q=%23 Allow: /i/api/ # Same length as the /*/likes and /*/media rules; RFC 9309 breaks the tie in # favor of Allow, so /i/api/ fetches stay crawlable. Allow: /i/api/* Disallow: /*?lang=en-ss Allow: /*?lang= Disallow: /search/realtime Disallow: /search/users Disallow: /search/*/grid Disallow: /*/analytics Disallow: /*/followers Disallow: /*/following Disallow: /*/verified_followers Disallow: /account/deactivated Disallow: /settings/deactivated # Only `*` and `$` are metacharacters here (RFC 9309); regex classes match # literally. /photo is anchored so /status/*/photo/1 media pages stay open. Disallow: /*/likes Disallow: /*/likes? Disallow: /*/retweets Disallow: /*/retweets? Disallow: /*/media Disallow: /*/media? Disallow: /*/photo$ Disallow: /*/photo? Allow: /*? User-agent: facebookexternalhit Allow: /*?lang= Allow: /*?s= Allow: /*?t= Allow: /*?ref_src= Allow: /hashtag/*?src= Allow: /search?*cashtagRestId= Allow: /i/api/ Allow: /i/api/* Disallow: /search?q= Disallow: /search/realtime Disallow: /search/users Disallow: /search/*/grid Disallow: /*? Disallow: /*/followers Disallow: /*/following Disallow: /*/verified_followers Disallow: /account/deactivated Disallow: /settings/deactivated Disallow: /*/likes Disallow: /*/likes? Disallow: /*/retweets Disallow: /*/retweets? Disallow: /*/media Disallow: /*/media? Disallow: /*/photo$ Disallow: /*/photo? User-Agent: Google-Extended Disallow: * User-Agent: FacebookBot Disallow: * User-agent: Discordbot Disallow: * # Meta AI / product crawlers (product tokens; versions like /1.1 are ignored # under RFC 9309 token matching). User-agent: meta-webindexer Disallow: * User-agent: meta-externalagent Disallow: * User-agent: meta-externalads Disallow: * User-agent: meta-externalfetcher Disallow: * # Every bot that might possibly read and respect this file # ======================================================== User-agent: * Disallow: / # WHAT-4882 - Keep notification-email links (/i/u) out of search results. # Named crawlers stay un-blocked on purpose: they must crawl /i/u to see its # X-Robots-Tag noindex (the robots.txt Noindex directive died in 2019). Disallow: /i/u # Wait 1 second between successive requests. See ONBOARD-2698 for details. Crawl-delay: 1 # Independent of user agent. Links in the sitemap are full URLs using https:// # and need to match the protocol of the sitemap. Sitemap: https://x.com/sitemap.xml
Export & Share Intelligence
Download the complete official PDF verification report (all sections and technical signals expanded), or export raw JSON telemetry.
Scan Engine Performance
Automated multi-signal inspection pipeline