paulgraham.com
28-year-old corporate / B2B site based in United States, served through cloudflare, with email running through custom-or-self-hosted.
Email health18Needs work
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.
DMARC aggregate reporting enabled (rua=)
No DMARC aggregate-reporting address is published — you wouldn't see spoofing attempts.
Mailto: direct contact link present
We couldn't find a tap-to-email link anywhere on your site.
Branded domain email address (vs free Gmail/Yahoo)
You send email from your own domain, not a free Gmail/Yahoo address.
4 additional standards didn't apply to this category
Security37Needs work
Your site isn't sending any of the standard browser-protection headers.
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Sensitive path exposure (.git, .env, /admin, xmlrpc.php, wp-login.php)
Some common admin or developer paths are reachable from the public internet.
15 additional standards didn't apply to this category
SEO51Needs work
Title, meta description, OG, Twitter cards, canonical
Your homepage is missing one or more of the standard social-share and search-preview tags.
Schema.org structured data presence
Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.
Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.
No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.
Internal link depth (clicks from homepage to deepest content)
Important pages are reachable in just a click or two from your homepage.
4 additional standards didn't apply to this category
Privacy60Fair
Cookie banner presence + CMP detection
No cookie banner detected, but trackers are present. If you serve EU or California traffic, this is a compliance gap.
No privacy policy page found. Required by GDPR, CCPA, and most app store listings.
Terms of service page presence
No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.
CCPA "Do Not Sell or Share My Personal Information" link
No CCPA "Do Not Sell or Share My Personal Information" link found. If you have California visitors and sell or share data, this is required.
Your homepage loads a moderate number of third-party trackers. Worth auditing what each one is for.
Cookie scan — actual cookies set on first load
Your homepage sets only essential cookies before consent. Non-essential cookies fire after opt-in.
Accessibility62Fair
Some images on your homepage are missing alt text. Screen reader users hear silence where they should hear a description.
No accessibility statement page found. Required in the EU under the Accessibility Act, and increasingly under US state law.
axe-core / WAVE accessibility scan
Automated accessibility scans flagged issues on your homepage — alt text, contrast, ARIA labels, or heading structure problems that block real users.
Your heading levels are properly nested — H1, then H2s, then H3s — and screen readers can navigate the outline.
Text on your homepage meets WCAG AA contrast minimums — readable by visitors with low vision.
ARIA labels presence and validity
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
1 additional standard didn't apply to this category
Performance85Excellent
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
Mobile PageSpeed score + Core Web Vitals (LCP, FCP, CLS)
Your homepage loads fast on mobile — the metrics Google uses for ranking are in the green.
Image optimization (WebP/AVIF)
Your images use modern formats (WebP / AVIF) — visitors download a fraction of the bytes.
Lazy loading on below-fold images
Below-fold images use loading="lazy" — they download only when the visitor scrolls toward them.
Font loading strategy (FOUT/FOIT/swap)
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
6 additional standards didn't apply to this category
View formal standards verdicts → Composite-spec rollups for press, regulators, and compliance auditors.
Is email from this domain trustworthy?31Needs work
Stops scammers from emailing customers as you
You have DMARC set up, but in monitor-only mode — it's not actually rejecting spoofed mail.
Lists who's allowed to email as your business
No SPF record is published, so nothing tells mail providers who's allowed to send as you.
Keeps your email private in transit
No MTA-STS or TLS-RPT policy is published — incoming mail could be downgraded to plaintext.
You get reports when someone fakes your email
No DMARC aggregate-reporting address is published — you wouldn't see spoofing attempts.
A contact form people can actually find
We couldn't find a visible contact form on your homepage.
A clickable email link on your site
We couldn't find a tap-to-email link anywhere on your site.
You email from your own domain, not Gmail
You send email from your own domain, not a free Gmail/Yahoo address.
4 additional standards didn't apply to this site
Is it safe to visit?35Needs work
Browser-level protections for visitors
Your site isn't sending any of the standard browser-protection headers.
Your domain isn't on a spam blocklist
listed=true, response_code=0, answers=127.255.255.254
Only your approved vendors can issue your padlock
There's no CAA record at your registrar saying which companies are allowed to issue certificates for you.
Private files aren't open to the public
Some common admin or developer paths are reachable from the public internet.
15 additional standards didn't apply to this site
Does it respect visitor privacy?47Needs work
Cookie consent banner for European visitors
No cookie banner detected, but trackers are present. If you serve EU or California traffic, this is a compliance gap.
You have a privacy policy page
No privacy policy page found. Required by GDPR, CCPA, and most app store listings.
You have a terms of service page
No terms of service page found. Without one, you have no contractual basis for the relationship with your visitors.
California privacy opt-out link
No CCPA "Do Not Sell or Share My Personal Information" link found. If you have California visitors and sell or share data, this is required.
How many outside companies you let watch your visitors
Your homepage loads a moderate number of third-party trackers. Worth auditing what each one is for.
What your site actually drops on visitors' phones
Your homepage sets only essential cookies before consent. Non-essential cookies fire after opt-in.
Can people find this site?53Needs work
How your site appears when shared or in search results
Your homepage is missing one or more of the standard social-share and search-preview tags.
Hidden labels that explain your business to Google
Your homepage doesn't publish any Schema.org structured data. Search engines and AI tools fall back to guessing what your site is — and they guess wrong more often than not.
A clear headline on every page
Your homepage doesn't have a visible H1 heading. Without it, search engines and screen readers have no anchor for what the page is about.
A trail showing where visitors are on your site
No breadcrumb schema is published. Search engines can't show breadcrumb trails under your listings, and visitors lose the trail to important pages.
How easy it is to reach your deepest pages
Important pages are reachable in just a click or two from your homepage.
4 additional standards didn't apply to this site
Can everyone use it?68Fair
Your photos have written descriptions
Some images on your homepage are missing alt text. Screen reader users hear silence where they should hear a description.
You have an accessibility statement
No accessibility statement page found. Required in the EU under the Accessibility Act, and increasingly under US state law.
Your site works for visitors with disabilities
Automated accessibility scans flagged issues on your homepage — alt text, contrast, ARIA labels, or heading structure problems that block real users.
Your headings are in a sensible order
Your heading levels are properly nested — H1, then H2s, then H3s — and screen readers can navigate the outline.
Text on your homepage meets WCAG AA contrast minimums — readable by visitors with low vision.
Your buttons and forms are labeled for screen readers
Interactive elements have proper ARIA labels — screen reader users get a clear description of each control.
1 additional standard didn't apply to this site
Is it fast?79Strong
Your site uses the newest connection style
Your server still serves over the older HTTP/2 protocol — not the newer, faster HTTP/3.
Pages get squeezed before they're sent
Your server compresses pages with Brotli or gzip — visitors download a fraction of the raw size.
How fast your site loads on a phone
Your homepage loads fast on mobile — the metrics Google uses for ranking are in the green.
Your photos are saved in modern formats
Your images use modern formats (WebP / AVIF) — visitors download a fraction of the bytes.
Photos lower on the page wait their turn
Below-fold images use loading="lazy" — they download only when the visitor scrolls toward them.
Your text shows up while fonts load
Your fonts swap in cleanly — text is readable in the system font while custom fonts download.
6 additional standards didn't apply to this site
Does this look like a real business?——
Site signals
Context we detected about this site — presence, reputation, and the tools it runs. These are informational and don't affect the score, up or down.