Skip to content
RequestGuard Domain Intelligence
Pricing

Domain intelligence

Security Report for chatgpt.com

A closer look at this domain’s security, infrastructure, and public records. Findings first, with the evidence behind every result.

Explore the report
Website security grade C 74/100

Website Security

HTTPS, browser protections, DNS controls and known threats

Grade C #14 of 57

Some protections need work

The website has a solid base, but missing settings weaken its protection.

C74/100

Secure connection

Strong

40/40

Browser protections

Weak

19/30

Domain protection

Weak

0/15

Known threats

Strong

15/15

Fix these first

  1. 1

    DNSSEC

    0/8

    To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.

  2. 2

    Certificate authority restriction

    0/7

    To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.

  3. 3

    Content security policy

    4/10

    To earn 10/10, add an effective script restriction, for example: Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'. Add only the exact external hosts the site needs.

Strongest results

  • HTTPS response

    15/15

    HTTPS returned status 200.

  • Valid TLS certificate

    10/10

    The TLS certificate is valid for this domain.

  • Known malware reports

    6/6

    No active malware-distribution URL was reported.

All 15 security checks

Every result is shown, with what it means and how to fix it.

Working

HTTPS response

HTTPS returned status 200.

15/15
Working

Valid TLS certificate

The TLS certificate is valid for this domain.

10/10
Working

HTTP redirects to HTTPS

HTTP redirects to HTTPS.

5/5
Working

Modern TLS

TLSv1.3 was negotiated.

5/5
Working

Strict transport security

Strict-Transport-Security covers at least 180 days.

5/5
Could be stronger

Content security policy

Content-Security-Policy is enforced but does not restrict script sources.

To earn 10/10, add an effective script restriction, for example: Content-Security-Policy: default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'self'. Add only the exact external hosts the site needs.

4/10
Working

Frame protection

The response limits which sites may frame it.

5/5
Working

Content type protection

Content type sniffing is disabled.

5/5
Working

Referrer policy

Referrer-Policy uses strict-origin-when-cross-origin.

5/5
Needs attention

Browser permissions policy

Permissions-Policy is missing.

To earn 5/5, disable all three tested capabilities: Permissions-Policy: camera=(), microphone=(), geolocation=(). Add separate directives for capabilities the site intentionally allows.

0/5
Needs attention

DNSSEC

DNSSEC validation data was not found.

To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.

0/8
Needs attention

Certificate authority restriction

No CAA record was found.

To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.

0/7
Working

Known malware reports

No active malware-distribution URL was reported.

6/6
Working

Threat-blocking DNS

3 threat-protection resolvers returned the domain.

5/5
Working

Domain blocklists

The domain did not match the checked domain blocklists.

4/4

This dated automated check does not verify the business, its content, or every page. The score describes the configuration observed during this scan.

Badges and embed code
Embed code
<a href="https://requestguard.com/domain/chatgpt.com/">
  <img src="https://requestguard.com/domain/chatgpt.com/badges/security.svg" alt="Website security grade for chatgpt.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/chatgpt.com/#infrastructure">
  <img src="https://requestguard.com/domain/chatgpt.com/badges/location.svg" alt="Network location for chatgpt.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/chatgpt.com/">
  <img src="https://requestguard.com/domain/chatgpt.com/badges/trust.svg" alt="Trust badge for chatgpt.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/chatgpt.com/#whois">
  <img src="https://requestguard.com/domain/chatgpt.com/badges/domain-rating.svg" alt="Domain Rating for chatgpt.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Use these results through the API

API requests require a workspace key and a plan with Lookups access.

The hosted badge updates after a manual scan. A downloaded badge stays static and avoids contacting RequestGuard on page views.

Search visibility

Homepage signals that can affect crawling and indexing

Needs review

Needs review

Some homepage signals need a closer look. Review the recommendations below.

6 homepage checks · Unscored

Observed request

https://chatgpt.com/

Clear

Automated crawler access

The identified crawler received HTTP 200 for the homepage.

Review

Indexing directives

No noindex directive was found in the captured part of the response, but the HTML exceeded the scan limit.

Keep robots metadata in the document head and confirm the rendered page with Google Search Console URL Inspection.

Clear

robots.txt homepage rule

No robots.txt rule blocking Googlebot from the homepage was found.

Clear

Canonical URL

The canonical URL stays on chatgpt.com and matches the homepage path.

Clear

Search-readable HTML

The initial HTML contains a title and visible page content.

Clear

Sitemap discovery

robots.txt declares 6 sitemaps.

This is not a Google index lookup. RequestGuard tests public signals with an identified automated crawler. Only URL Inspection for a verified Google Search Console property can confirm Google's last crawl, selected canonical, and indexing decision.

Open Google's URL Inspection guide

Cached result

Public exposure

Sensitive files and public administrative interfaces

Unscored

Not checked—run a website scan.

Checks 100 common paths and up to 50 technology-specific paths. Opening this report does not start exposure checks.

These are bounded, unauthenticated crawler observations, not a penetration test. A public login is not automatically a vulnerability. Secret values are discarded. Findings do not affect your security score.

Server Infrastructure

Resolved addresses, networks, and hosting providers

Loading infrastructure evidence

DNS Records

A, AAAA, MX, and resolving certificate hostnames, with other record types on demand

Loading DNS records

Email & DNS Security

MX, SPF, DMARC, DNSSEC, and CAA posture

Loading email and DNS posture

WHOIS & Registrar

Registration details via RDAP

RDAP

Registered 3.8 years ago

Registration history and published ownership records. Domain age and Domain Rating are context, not a security verdict.

Registrar

Markmonitor Inc.

Registration dates

Domain age

3.8 years

Created

Nov 30, 2022

Updated

Sep 12, 2026

Expires

Nov 30, 2026

Registrant

Privacy protected

Identity is hidden by a privacy service — standard practice under GDPR and similar laws, not on its own a sign of anything suspicious.

Name REDACTED REGISTRANT
Organization OpenAI
Email REDACTED FOR PRIVACY
Phone REDACTED FOR PRIVACY
Location US REDACTED FOR PRIVACY, US

Some of the data in this object has been removed.

Domain status

Registry status codes — green means the owner locked out unauthorized changes

Update locked Transfer locked Delete locked Registry update lock Registry transfer lock Registry delete lock

Checked

Reputation & DNS filtering

Resolver behavior, domain datasets, and server-IP evidence

No threat match

Resolver summary

No match found in 3 checked threat-protection resolvers.

Checked . No-match results apply only to the sources that returned comparable evidence.

Resolver filtering records provider behavior. It does not by itself prove that a domain is malicious.

Resolver matrix

Five public filtering policies compared with neutral DNS

5 comparable · 0 unavailable

Threat protection

Malware and phishing policy

Ads & tracking

Mixed privacy and security policy

Family / content

Content and security policy

Reputation datasets

URL and domain-list evidence, separate from resolver policy

0 of 1 active matches
URLhaus No match

Reported malware-distribution URLs

SURBL (via URLhaus) Unavailable

URLhaus metadata; this is not a direct SURBL query

Spamhaus DBL (via URLhaus) Unavailable

URLhaus metadata; this is not a direct Spamhaus DBL query

Server-IP DNSBL checks & threat feeds US 172.64.155.209

DNSBL and network-feed matches do not determine the domain verdict. Shared hosting, reverse proxies, and CDNs can put unrelated domains on the same address.

0 of 4 matched, 6 unavailable

Barracuda

b.barracudacentral.org

No match

SpamCop

bl.spamcop.net

No match

UCEPROTECT L1

dnsbl-1.uceprotect.net

No match

DroneBL

dnsbl.dronebl.org

No match

X4B VPN ranges

raw.githubusercontent.com

Feed file is unavailable

Unavailable

X4B datacenter ranges

raw.githubusercontent.com

Feed file is unavailable

Unavailable

Tor exit nodes

check.torproject.org

Feed file is unavailable

Unavailable

Team Cymru fullbogons IPv4

team-cymru.org

Feed file is unavailable

Unavailable

Spamhaus DROP IPv4

www.spamhaus.org

Feed file is unavailable

Unavailable

Feodo Tracker C2

feodotracker.abuse.ch

Feed file is unavailable

Unavailable

NextDNS and other custom profiles are not tested because their result depends on enabled lists, security settings, and parental controls. Check the provider log for the exact rule.

Cached result