allstate.ca

HTTPS HTTP/2 HSTS Gzip Next.js Crawled in 74,832ms · June 27, 2026 20:08 UTC

allstate.ca Website Overview & Technology Report

🤖 AI Summary
We performed a comprehensive analysis of allstate.ca on 2026-06-27. The website returned an HTTP 200 status code with a server response time of 22990ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 274 KB. Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted. The security headers analysis reveals a score of 50/100 (moderate). The following security headers are properly configured: Strict-Transport-Security (HSTS), X-Content-Type-Options, and Referrer-Policy. However, the site is missing Content-Security-Policy, X-Frame-Options, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks. Our technology detection scan identified 3 technologies across 3 categories powering allstate.ca. The detected stack includes Next.js css, Webpack, and Google Tag Manager. The site uses Next.js as its primary framework (version css). Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, allstate.ca receives an overall trust score of 67/100, classified as "Likely Safe".
67
/ 100
Trust Score
50
/ 100
Security Headers
HTTP Response
Status200 OK
Response Time22990ms
ProtocolHTTP/2
Page Size274 KB
CompressionGzip
Compression Savings~60.0%
CDNNo
Server
Total Requests154
3rd Party Domains8
Redirect1 hop(s)
Detected Technologies (3)
🔧 Next.js 🔨 Webpack 🏷️ Google Tag Manager
Security Headers
Content-Security-Policy
Not set
Strict-Transport-Security (HSTS)
Set ✓
X-Frame-Options
Not set
X-Content-Type-Options
Set ✓
Referrer-Policy
Set ✓
Permissions-Policy
Not set
SSL Certificate
IssuerDigiCert Inc
Issuer FullcountryName=US, organizationName=DigiCert Inc, organizationalUnitName=www.digicert.com, commonName=Thawte TLS RSA CA G1
SubjectcountryName=CA, stateOrProvinceName=Ontario, localityName=Markham, organizationName=Allstate Insurance Company of Canada, commonName=allstate.ca
Type
TLS VersionTLS 1.2
Cipher SuiteECDHE-RSA-AES128-GCM-SHA256
Algorithm
Issued
Expires— (? days)
SANs

allstate.ca Trust Score & Safety Analysis

🤖 AI Summary
After conducting a thorough safety and legitimacy analysis, allstate.ca receives a trust score of 67/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases. The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, HSTS (HTTP Strict Transport Security) enforcement preventing protocol downgrade attacks, SPF (Sender Policy Framework) email authentication preventing email spoofing, and DKIM (DomainKeys Identified Mail) providing cryptographic email verification. Areas of concern include: the absence of a Content-Security-Policy header, which leaves the site more vulnerable to cross-site scripting (XSS) attacks, no X-Frame-Options header, which could allow the site to be embedded in malicious iframes (clickjacking), the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved. We checked allstate.ca against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
67
/ 100
Likely Safe
Trust Signals
Valid HTTPS
HSTS enabled
SPF configured
DKIM configured
⚠️ DNSSEC not enabled
⚠️ Missing Content-Security-Policy
⚠️ Missing X-Frame-Options
Blacklist Checks (8/8 clean)
Google Safe Browsing clean
Phishtank clean
Urlhaus clean
Openphish clean
Dnsfilter clean
Spamhaus Dbl clean
Surbl clean
Virustotal clean

allstate.ca Technology Stack & Detected Technologies

🤖 AI Summary
Our technology detection engine scanned allstate.ca and identified 3 distinct technologies across 3 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records. Framework: Next.js (version css) — provides the application framework and routing for allstate.ca. Build Tool: Webpack — bundles and optimizes the JavaScript and CSS assets for allstate.ca. Tag Manager: Google Tag Manager — manages marketing and analytics tags without code changes for allstate.ca. We also extracted the following tracking identifiers: Google Tag Manager container GTM-5FPLV2X. These IDs can be used to identify other websites operated by the same organization.
Framework
🔧 Next.js css(100%)
Build Tool
🔨 Webpack(95%)
Tag Manager
🏷️ Google Tag Manager(95%)
Tracking IDs
gtm_idGTM-5FPLV2X

allstate.ca Performance, Speed & Core Web Vitals

🤖 AI Summary
allstate.ca delivers its homepage in 22990ms (server response time), which is considered slow by industry standards. The total page weight is 274 KB, and we detected 154 resource requests loading assets from 8 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain. The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections. Asset minification status: 0 out of 2 CSS files and 1 out of 15 JavaScript files are minified. Minifying the remaining 16 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality. From an environmental perspective, each page view of allstate.ca produces approximately 0.13g of CO₂, earning a carbon rating of A. This places the website among the cleanest on the web, demonstrating efficient use of server resources and optimized content delivery. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 274 KB is the primary factor in this calculation. Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for allstate.ca. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Core Web Vitals data not available
Requires CrUX API key configuration
Carbon Footprint
CO₂ per page view0.13g
RatingA
Page Weight & Optimization
HTML Size274 KB
CompressionGzip
Compression Savings~60.0%
CDNNo
Total Requests154
3rd Party Domains8
CSS Minified0/2
JS Minified1/15

allstate.ca DNS Records, Email Authentication & Domain Registration

🤖 AI Summary
allstate.ca resolves to the IPv4 address 167.127.90.4, but does not support IPv6. IPv6 adoption is increasingly important as IPv4 address space becomes exhausted, and some ISPs and regions are transitioning to IPv6-only connectivity. The domain has 1 A record(s) configured. The domain name system is managed by 9 name servers: ADNSZDINFWV01.allstate.ca, ADNSZDINFWV02.allstate.ca, adnsz1infwv01.allstate.ca, adnsz1infwv02.allstate.ca, dns1.allstate.ca, dns2.allstate.ca, dns3.allstate.ca, dns4.allstate.ca, and dns5.allstate.ca. Having 9 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used. Email for allstate.ca is handled by Microsoft 365 with 1 MX records configured: allstate-ca.mail.protection.outlook.com. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server. SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC is not configured, leaving the domain vulnerable to email spoofing and phishing attacks that impersonate this domain. DKIM (DomainKeys Identified Mail) is configured, adding a cryptographic signature to outgoing emails that receiving servers can verify to confirm the email hasn't been tampered with in transit. DNSSEC is not enabled for allstate.ca. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions. Our subdomain enumeration scan discovered 5 active subdomains for allstate.ca: apps.allstate.ca, blog.allstate.ca, ftp.allstate.ca, partners.allstate.ca, and www.allstate.ca. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
DNS Records
A
167.127.90.4
NS
ADNSZDINFWV01.allstate.ca
ADNSZDINFWV02.allstate.ca
adnsz1infwv01.allstate.ca
adnsz1infwv02.allstate.ca
dns1.allstate.ca
dns2.allstate.ca
dns3.allstate.ca
dns4.allstate.ca
dns5.allstate.ca
MX
allstate-ca.mail.protection.outlook.com
Email & Authentication
SPF
DMARC p=—
DKIM
DNSSEC
MX ProviderMicrosoft 365
Registrar
Organisation
Country
Contact
Registered
Expires
Domain Age
IPv6 SupportNo
Subdomains (5 found)
apps.allstate.ca blog.allstate.ca ftp.allstate.ca partners.allstate.ca www.allstate.ca

allstate.ca Page Content, Images & Accessibility

🤖 AI Summary
The homepage of allstate.ca contains 786 words of visible text content. This is a moderate amount of content. The page is structured with 6 H2 headings, 0 H3 headings, 0 H4 headings. The page includes 55 images. 13 images (24%) are missing alt text attributes, which is a significant concern for both accessibility and SEO. Screen readers rely on alt text to describe images to visually impaired users, and search engines use alt text to understand image content. Only 76% of images have proper alt text — we recommend adding descriptive alt attributes to all images. The link structure consists of 46 internal links pointing to other pages on the same domain and 23 external links pointing to third-party websites. There are 15 external JavaScript files, 2 CSS stylesheets, and 0 iframes on the page. Notable missing features: XML Sitemap, robots.txt, and Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility. The website has social media presence across 4 platforms: Facebook (@AllstateCanada",), Twitter (@AllstateCanada",), Instagram (@AllstateCanada",), and Linkedin (@AllstateCanada"],). An active social media presence is a positive trust indicator and helps build brand awareness and customer engagement.
786
Words
55
Images
76%
Alt Text Score
274
Page Size (KB)
Content Structure
H1
H2 Tags6
H3 Tags0
H4 Tags0
H5 Tags0
H6 Tags0
Internal Links46
External Links23
Assets & Features
JavaScript Files15
JS Minified1/15
CSS Files2
CSS Minified0/2
Iframes0
Images55
Missing Alt13
SitemapNo
Robots.txtNo
PWANo
AMPNo
RSS FeedNo
Social Media Presence
Facebook: @AllstateCanada",Twitter: @AllstateCanada",Instagram: @AllstateCanada",Linkedin: @AllstateCanada"],

allstate.ca SEO Analysis, Meta Tags & Open Graph

🤖 AI Summary
The title tag for allstate.ca is well-optimized at 59 characters: "Auto, Property Insurance & More | Allstate Insurance Canada". The length falls within the ideal range for Google search results, ensuring the full title is displayed without truncation. No meta description is configured for allstate.ca. This is a critical SEO oversight — without a meta description, Google will auto-generate a snippet from page content, which may not accurately represent the page or entice users to click. Adding a unique, compelling meta description of 120-155 characters is strongly recommended. The canonical url is correctly set to https://www.allstate.ca/, preventing duplicate content issues and the page language is declared as en-ca. Open Graph meta tags are configured with 3/4 recommended fields: OG title ("Allstate Insurance Canada - Auto, Property Insurance and Mor..."), OG description, OG type (Website). These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol. A Twitter Card of type [object Object] is configured, which controls how links appear when shared on Twitter/X. The "[object Object]" type displays a large image preview, which typically generates higher engagement rates than the basic card type.
Google SERP Preview
Auto, Property Insurance & More | Allstate Insurance Canada
https://allstate.ca
Meta Tags
TitleAuto, Property Insurance & More | Allstate Insurance Canada...
Title Length59 chars
Meta Desc Length0 chars
H1
Languageen-CA
Canonicalhttps://www.allstate.ca/
Meta Robotsnot set
Meta Keywordsnot set
Schema.org & Social
Schema Types
OG TypeWebsite
OG ImageNot set
Twitter Card[object Object]
FaviconNot set