Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations53 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryNetlifyREVIEW
A+DNS Records2 A records, 74 ms lookupPASS
| A | 15.197.167.90, 3.33.186.135 |
| AAAA | — |
| CNAME | — |
| NS | ns4.markmonitor.com, ns7.markmonitor.com, ns2.markmonitor.com, ns3.markmonitor.com, ns6.markmonitor.com, ns1.markmonitor.com, ns5.markmonitor.com |
| MX | 0 mattel-com.mail.protection.outlook.com |
| TXT | facebook-domain-verification=mucmxd3t3t1mxbyt4a68mh84ivrixr openai-domain-verification=dv-ZqQqFYXR01FIcAnd22snMZKM -Pat2r5vHBANb7fvRcrBmKzNzCSXmw stripe-verification=d2c5519112b8ef89651a7247406c9196fc7ceb57cd1b375b4097a8e1fee8... mongodb-site-verification=XXdQ0UFy0qkOQAORsJr17oQNzzcTGtnx globalsign-domain-verification=2_W0PBp-Dke0afh34WuVRGDpSyvVpOD4g4wiEQdKXO flexera-domain-verification-ckzubskqelawyefd globalsign-domain-verification=548DF575A9C0CBE199F23D9F8FF8E343 airtable-verification=d2644d9e1f3a7084f45d75fc4853b158 klaviyo-site-verification=Suh8Ep amazonses:SQ7RzWc0jpZz3WUTq2xvKCmCyZSMyasY5+B5254eNR8= smartsheet-site-validation=Pb2iq_20BFe2PNgJQn7ZT3hdNy8PPZM6 _globalsign-domain-verification=fLypsY3AsraNmCRbUoKUI6qQfYPvA340Y-xZ76b9zG s3STULtuaC+JAYVIErkuu1jxN4b7luXvu+1dGR6UPlJiVsq+mJTx/+uVjFK9aBenktzLyg3YvvIH3U/J... atlassian-domain-verification=ycRYijiDol3imUfriVcX8bIugaELJJIs9WfgjCmZdhERrjfZ7v... klaviyo-site-verification=RbzuTn globalsign-domain-verification=84FA62F3C1C2DD2BC483EC35F181291D globalsign-domain-verification=E99B98582B5CBE501244EC0EF15533ED shopify-verification-code=elce9sYD8cm9qq4K3no1kZ0P1lrGv5 miro-verification=2b083f3c04a86493b94e3cf2fc5abb5d42a1584e globalsign-domain-verification=83592c502ac01718e2183bfc36065346 klaviyo-site-verification=T3Zp3h XXLYSrygdNsjlkqUtPrkoWJmJmGSViHcDEgyKwjfJvE 1739bf69-fd7e-416d-9989-9a5dc27f0d3d facebook-domain-verification=q47c0fpjz5dyktmjv753zh6kebe01u klaviyo-site-verification=SU4YSV ciscocidomainverification=1db3115a9241d383c0dfcf306debfa682494a0323e4f8e91c6d4b7... canva-site-verification=0yPMDPYuL_jlmw8N18UQDg MS=ms32300319 apple-domain-verification=8rHg56dysd6NHEGG SPF v=spf1 ip4:156.20.174.28 ip4:156.20.174.19 ip4:156.20.174.20 ip4:156.20.226.21 i... 363-242-484 globalsign-domain-verification=E38512355C14A9D4ED6449EA485628D5 google-site-verification=loworyG6vj9eIjGPgkCCus46iWRe7_0O764_rfYeEkU flexera-domain-verification-nwxkrsgcsfxtodgn asv=41cba8bd778557cbdabcfec11db817c5 _globalsign-domain-verification=xAIWtgGuWzAqcLFerDYVRMouLLcTceP2q7dRAPd2Kd globalsign-domain-verification=FCE0C06DB86E6C09655A686119DC08F5 globalsign-domain-verification=DF20A01F31EA78F75177B5A9747B8D55 elevenlabs=W_U6ZpEboTG6vEtbAqb-WFIxXVrCt0ggvuziWp8hxHs klaviyo-site-verification=SMfDWk atlassian-domain-verification=CBVSBzX73V8o3dW9vZV50zFaoe4kzJz420mhW8/ZsFzZjLsEWV... globalsign-domain-verification=E33B3B1326158F213DCC67708D116007 globalsign-domain-verification=D7474A3561EC11EF56281A874B076C9B globalsign-domain-verification=92DFE769E9125E199EF6EC9169CA87F7 ZOOM_verify_uG9jncpZikTCqaHsE3U5HM |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 310 ms totalPASS
https://mattel.com
136 ms · HTTP/1.1
https://shopping.mattel.com/fr-fr/
175 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://mattel.com | 301 | 136 ms | HTTP/1.1 | Netlify |
| 2 | https://shopping.mattel.com/fr-fr/ | 200 | 175 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 35 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
User-agent: *
Disallow:
- https://shop.mattel.com/sitemap_products...
- https://shop.mattel.com/sitemap_products...
- https://shop.mattel.com/sitemap_products...
- https://shop.mattel.com/sitemap_products...
- https://shop.mattel.com/sitemap_pages_1....
- https://shop.mattel.com/sitemap_collecti...
- https://shop.mattel.com/sitemap_blogs_1....
- https://shop.mattel.com/en-ca/sitemap_pr...
- https://shop.mattel.com/en-ca/sitemap_pr...
- https://shop.mattel.com/en-ca/sitemap_pr...
- https://shop.mattel.com/en-ca/sitemap_pr...
- https://shop.mattel.com/en-ca/sitemap_pa...
- https://shop.mattel.com/en-ca/sitemap_co...
- https://shop.mattel.com/en-ca/sitemap_bl...
- https://shop.mattel.com/fr-ca/sitemap_pr...
- https://shop.mattel.com/fr-ca/sitemap_pr...
- https://shop.mattel.com/fr-ca/sitemap_pr...
- https://shop.mattel.com/fr-ca/sitemap_pr...
- https://shop.mattel.com/fr-ca/sitemap_pa...
- https://shop.mattel.com/fr-ca/sitemap_co...
- https://shop.mattel.com/fr-ca/sitemap_bl...
- https://shop.mattel.com/es-mx/sitemap_pr...
- https://shop.mattel.com/es-mx/sitemap_pr...
- https://shop.mattel.com/es-mx/sitemap_pr...
- https://shop.mattel.com/es-mx/sitemap_pr...
- https://shop.mattel.com/es-mx/sitemap_pa...
- https://shop.mattel.com/es-mx/sitemap_co...
- https://shop.mattel.com/es-mx/sitemap_bl...
- https://shop.mattel.com/pt-br/sitemap_pr...
- https://shop.mattel.com/pt-br/sitemap_pr...
- https://shop.mattel.com/pt-br/sitemap_pr...
- https://shop.mattel.com/pt-br/sitemap_pr...
- https://shop.mattel.com/pt-br/sitemap_pa...
- https://shop.mattel.com/pt-br/sitemap_co...
- https://shop.mattel.com/pt-br/sitemap_bl...
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
ADomain Intelligencemattel.com — via MarkMonitor Inc., 31 years, 3 months old, hosted on AWSPASS
EXPIRED
June 4, 2026
53 days
Issued by Let's Encrypt
31 years, 3 months
Registered June 5, 1995
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
3.33.186.135
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Domain has EXPIRED — renew immediately to avoid total site outage
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Consider enabling auto-renewal to prevent accidental expiration.
Domain expiry approaching — renew immediately and ensure auto-renew + alerting are configured.
Source: ICANN renewal policy
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice