Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BDNSSECUnsigned (DNSSEC not deployed)REVIEW
BCAA RecordsNo CAA records (any CA may issue certificates)REVIEW
BReverse DNS0/1 IPs match cert SANREVIEW
BRedirect Chain2 redirect(s), 483 ms totalREVIEW
https://eni.com
39 ms · HTTP/1.1
https://www.eni.com/
225 ms · HTTP/1.1
https://www.eni.com/it-IT/home.html
218 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://eni.com | 301 | 39 ms | HTTP/1.1 | |
| 2 | https://www.eni.com/ | 301 | 225 ms | HTTP/1.1 | |
| 3 | https://www.eni.com/it-IT/home.html | 200 | 218 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
Each redirect adds latency. Try to minimize the chain to 1 hop.
Redirect chain — each hop adds latency; combine into one redirect where possible.
Source: Google Search Central / web.dev
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations115 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
BCDN Cache ObservabilityNo CDN cache-status headers in the responseREVIEW
BOperational Status PageNo status page link detectedREVIEW
BHealth Check EndpointNo conventional health endpoint foundREVIEW
A+DNS Records1 A records, 14 ms lookupPASS
| A | 23.55.136.60 |
| AAAA | — |
| CNAME | — |
| NS | asia4.akam.net, asia3.akam.net, ns1-160.akam.net, usw6.akam.net, usc4.akam.net, usw2.akam.net, ns1-177.akam.net, use1.akam.net |
| MX | 10 eni-com.mail.protection.outlook.com |
| TXT | MS=ms33691999 _4j2iwpqm0hh7smv0alwxuxg6pkre149 ms-domain-verification=5a01d4dc-b09b-4d82-ba5e-c691fd1f4a41 _4sidjex428n9xo3dfcup5lkvigdqtpr ms-domain-verification=76fcfc94-9b8b-4e27-9ec6-e3cfe23bf8ef xsjcd1kmbcxn5x2qzjyyz72z74svx5sr google-site-verification=8vbVf3fb-IlIcpZcC4oDKm9gK4xclUR8TERRcpRiZXE 9pbwtslcsbxgjsbbqvqg8qq55f3vjvh8 SPrIC/rvYbbDeh3LLYZ03ae6HlAx1BE8L62vKMgfQkE= globalsign-domain-verification=79249136B02E36298F5671B56343E757 SPF v=spf1 include:spf.eni.com include:spf.protection.outlook.com -all 8vbVf3fb-IlIcpZcC4oDKm9gK4xclUR8TERRcpRiZXE Foxit-domain-verification=bffb212b8730389be26b3f674c585672 ms-domain-verification=23079085-1fe6-4857-8e5e-afa7b63f39cc 87y29q4xbv425bgyx1fn70cm175xwchy onetrust-domain-verification=7e98852d735a447982b648a4adc44f6f Kl/JIvuc9Wce07DUJc98tbQ0CDdWsA+wI2t68yslzqI= 178f1335-7ec7-48b5-8d1b-a456b24591ac _j5nfluh532f3bjbgpnozynbz6tvcb9w y1rdx6kxfcyq4fhbpbg2b66ms9h00xt0 QsYeoCAVz4Cp3x0LV+9EzspxTdHI5DMt3f+uBU53+GdKIbVyjfMKHbqXWr14PMDsbP/vPO47U2TUeyP7... globalsign-domain-verification=DAF2F3475EC260E02A66FB387E6E7901 SzjjdNxqk0TubwubGMMUoHn2nL9e5GIjWM2Jxb6aohP9symsQJFpmXzStCM6lX6x jSA2/TvGVdsEZsIRXhVjdYYxtW0IBJq+jRrPH4IjOI1lmfEEOkjveuFKe2OWMUazE+YCRJ+taRiD8LOi... hgzxl7mycl25fsrcx48xy94wpg05j1zd apple-domain-verification=3vvAClEsGzFzxySJ s4pzw98tqs0lfp91svv79vj99q84qsjz _9hij4o1u5u0jnid9l14fjn03o8vcxt6 adobe-idp-site-verification=896234325d5356b8c0f504f685d5635164c2177280cfbeac4bca... globalsign-domain-verification=8D283AC7516379A183F7FEF135024986 ms-domain-verification=7b340ba3-3635-4f4d-8845-389a369c2d91 5e101c23063f934ca4e8513ec5867c33a916d9cab9f4185d6afa457062adc9ca neat-pulse-domain-verification-3Ml9m6N=abb30655-e883-4253-b376-e8f3b42e0cc7 ms-domain-verification=3004abed-516b-4bff-9503-f6c0fd708054 ms-domain-verification=6ff9aa2e-2ca8-49c6-8674-d54fc8e0d57f zbzrsx4mdxxft2t3bb0x50n242vr1f14 google-site-verification=ooOJOB0jhspBaE6591xm3e2ItGWOYf6f2C5a3f5HkzU mongodb-site-verification=Pf3sT0XQAHwJSWQrMB2idWUrNFGX4rJZ 0K1k16G75w58fxaMDpf9i+KBx221GIdSAp/NsRW4PVc= google-site-verification=GqmBPIsd58v-NV5VI_pI3l427wezhO8xTwSAYBf4sp8 globalsign-domain-verification=6CBE1F6FC408E1AFFDC318178597486A ciscocidomainverification=619913516fd3784ed0f9aae27b30239f7e34aa19b1a47e241146d4... ms-domain-verification=7aa9ac27-db4b-464e-a140-a8c5d2c10797 Kl/JIvuc9Wce07DUJc98tXAofquEdZteIkI9OebQPfo= globalsign-domain-verification=4819f8c3c78d6bf65476779ac5cbccc7 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
A+Multi-Resolver DNS SpeedMean 16ms across 3 resolvers (spread 41ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 3492 URLsPASS
### Sitemaps
Sitemap: https://www.eni.com/it-IT/sitemap.xml
Sitemap: https://www.eni.com/en-IT/sitemap.xml
User-agent: *
Disallow: /it-IT/media/comunicati-stampa/2014/06/eni-firma-accordi-strategici-per-il-giacimento-super-giant-perla-in-venezuela.html
Disallow: /en-IT/media/press-release/2014/06/eni-signs-strategic-agreements-for-perla-super-giant-field-in-venezuela.html
Disallow: /it-IT/2024-piano-azionariato-diffuso/piano-azionariato-diffuso.html
Disallow: /it-IT/trattamento-dati-mobile-badge.html
Disallow: /assets/documents/ita/investor/presentazioni/2021/Eni-Retail-Renewables-a-unique-proposition.pdf
Disallow: /assets/css/style.css
Disallow: /assets/js/vendor.min.js
Disallow: /assets/js/app.min.js
Disallow: /visual-design-test
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligenceeni.com — via Register SPA, 32 years, 1 months old, hosted on AkamaiPASS
125 days
December 29, 2026
115 days
Issued by DigiCert Inc
32 years, 1 months
Registered December 30, 1994
Not enabled
Protects against DNS spoofing
Akamai
ASN AS16625
23.55.136.60
Register SPA
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice