How to pass every isitagentready.com check for a content site

Passing the seven isitagentready.com content checks requires a valid robots.txt, sitemap, Link headers, markdown negotiation, Content Signals, and DNS-AID.

To pass all seven checks in the isitagentready.com Content Site profile, a site needs valid robots.txt and sitemap files, discovery Link headers, markdown negotiation, AI bot rules, Content Signals, and a DNSSEC-validated DNS-AID record. Cloudflare introduced isitagentready.com on 2026-04-17 as a site-readiness scanner for AI agents. The available insidetheloop.dev scan reached Level 5 on 2026-10-05 at 21:55:09 UTC, but its DNS-AID check still failed because the resolver returned AD=false, so Level 5 did not mean all seven checks passed.

Key facts

  • Cloudflare introduced isitagentready.com on 2026-04-17 to score website readiness across 22 checks in five categories, with levels numbered 0 through 5.
  • The Content Site profile scopes evaluation to seven checks: robotsTxt, sitemap, linkHeaders, dnsAid, markdownNegotiation, robotsTxtAiRules, and contentSignals.
  • Level 1 requires passing two of three discoverability checks (robotsTxt, sitemap, linkHeaders).
  • Level 2 gates strictly on passing both robotsTxtAiRules and contentSignals in robots.txt.
  • Level 3 requires passing Level 2 and supporting markdownNegotiation via Accept: text/markdown.
  • In April 2026, Cloudflare Radar measured that 4% of the top 200,000 domains published Content Signals and 3.9% supported markdown negotiation.
  • Automated scans execute via POST https://isitagentready.com/api/scan with a JSON payload specifying target URL and enabled checks.

The isitagentready.com scan API

The isitagentready.com scanner exposes a public HTTP POST endpoint at https://isitagentready.com/api/scan. To execute the Content Site profile without running unneeded application or commerce checks, send the target URL with the seven profile check keys in enabledChecks:

curl -sL -X POST https://isitagentready.com/api/scan \
  -H 'Content-Type: application/json' \
  -d '{
    "url": "https://insidetheloop.dev",
    "enabledChecks": [
      "robotsTxt",
      "sitemap",
      "linkHeaders",
      "dnsAid",
      "markdownNegotiation",
      "robotsTxtAiRules",
      "contentSignals"
    ]
  }'

The response returns a JSON document containing top-level properties level, levelName, and a nested checks object. In checks, every evaluated check provides a status ("pass", "fail", or "neutral"), a human-readable message, and an evidence trace detailing HTTP requests, status codes, and DNS lookups.

The seven isitagentready.com Content Site checks

The live Content Site profile selects seven checks across discoverability, content accessibility, and bot access control. The profile sends these IDs in enabledChecks.

1. robots.txt (robotsTxt)

  • What it tests: The scanner requests /robots.txt and verifies that the server returns HTTP 200, uses a text/plain content type, and contains at least one valid User-agent directive per RFC 9309.
  • The fix: Create a /robots.txt file at the root of the domain that specifies crawler rules and links to the sitemap:
User-agent: *
Allow: /
Sitemap: https://insidetheloop.dev/sitemap.xml

2. Sitemap (sitemap)

  • What it tests: The scanner checks whether /sitemap.xml exists and returns valid XML per the Sitemaps protocol, or whether a Sitemap: directive in /robots.txt points to a reachable sitemap.
  • The fix: Generate an XML sitemap listing canonical URLs and ensure /robots.txt references its absolute address.
  • What it tests: The scanner inspects the HTTP response headers of the homepage for Link headers containing registered relation types under RFC 8288 and RFC 9727, including api-catalog, service-desc, service-doc, describedby, or alternate.
  • The fix: Configure origin server middleware, a Cloudflare Transform Rule, or a Cloudflare Worker to emit discovery Link headers on homepage GET requests:
Link: </llms.txt>; rel="describedby"; type="text/plain", </sitemap.xml>; rel="describedby"; type="application/xml", </rss.xml>; rel="alternate"; type="application/rss+xml"

4. Markdown Negotiation (markdownNegotiation)

  • What it tests: The scanner sends a GET request to the homepage with the header Accept: text/markdown. The check passes when the response returns Content-Type: text/markdown. An x-markdown-tokens header indicating the token count is optional.
  • The fix: Enable "Markdown for Agents" in the Cloudflare dashboard under zone settings, or implement server-side content negotiation that inspects the incoming Accept header and returns a Markdown representation instead of HTML.

5. AI Bot Rules (robotsTxtAiRules)

  • What it tests: The scanner evaluates /robots.txt for explicit User-agent rules targeting known AI bots, including search crawlers (OAI-SearchBot, Claude-SearchBot, PerplexityBot) and model-training crawlers (GPTBot, ClaudeBot, Google-Extended), or a wildcard User-agent: * block that applies uniform permissions.
  • The fix: Add explicit User-agent blocks or maintain a clear wildcard User-agent: * stanza with explicit Allow and Disallow paths.

6. Content Signals (contentSignals)

  • What it tests: The scanner checks /robots.txt for a Content-Signal directive formatted per draft-romm-aipref-contentsignals, declaring publisher preferences for ai-train, search, and ai-input.
  • The fix: Add a Content-Signal header line inside the relevant User-agent group in /robots.txt:
User-agent: *
Content-Signal: search=yes, ai-input=yes, ai-train=yes
Allow: /

This directive acts as the gate to Level 2 ("Bot-Aware"). A site cannot advance past Level 1 without it.

7. DNS for AI Discovery (dnsAid)

  • What it tests: The scanner queries DNS-over-HTTPS for Service Binding (SVCB) or HTTPS records under the _agents namespace (such as _index._agents.<domain> or _a2a._agents.<domain>) per draft-mozleywilliams-dnsop-dnsaid and RFC 9460. The check requires public discovery records to be signed with DNSSEC and return an Authenticated Data flag (AD=true).
  • The fix: Add an RFC 9460 SVCB record at _index._agents.<domain> pointing to the site's agent index or endpoint:
_index._agents.insidetheloop.dev. 3600 IN SVCB 1 insidetheloop.dev. alpn="h2" port=443

To satisfy the DNSSEC requirement, enable DNSSEC in the DNS authoritative zone and establish the DS record delegation at the domain registrar so recursive resolvers return AD=true.

The insidetheloop.dev Content Site scan

The available Content Site scan response for https://insidetheloop.dev was recorded at 2026-10-05T21:55:09.310Z (2026-10-05 21:55:09 UTC). It returned Level 5 ("Agent-Native"). The result did not show seven passing checks:

Check

Result

Evidence

robotsTxt

Pass

HTTP 200, text/plain, valid format

sitemap

Pass

Valid XML sitemap referenced from /robots.txt

linkHeaders

Pass

describedby and alternate relations found

dnsAid

Fail

SVCB found, but DNSSEC was not validated (AD=false)

markdownNegotiation

Pass

Content-Type: text/markdown; charset=utf-8

robotsTxtAiRules

Pass

Wildcard rules covered AI crawlers

contentSignals

Pass

Content-Signal found in /robots.txt

The scanner still awarded Level 5 because checks excluded by the Content Site profile were neutral. That score is not proof that all seven active checks passed. To pass dnsAid, the published _agents record must also produce a DNSSEC-validated response with AD=true.

Sources

Last verified: 2026-10-06.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.