Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FIPv6 ReadinessActionIPv6 records exist but unreachableFIX
Having AAAA records but an unreachable server is worse than no AAAA — clients may experience delays before falling back to IPv4.
Advertising IPv6 (AAAA records) without a reachable server means IPv6-preferring clients silently fail every connection.
Learn more ▾ ▴
Modern browsers prefer IPv6 if AAAA exists (Happy Eyeballs algorithm). If the IPv6 server isn't reachable, browsers fall back to IPv4 — but with seconds of added latency per request. Either fix IPv6 reachability or remove the AAAA records.
Source: RFC 8305 (Happy Eyeballs)
BTLS Certificate Expiry & Recommendations59 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 8 ms lookupPASS
| A | 104.18.39.231, 172.64.148.25 |
| AAAA | 2606:4700:4404::ac40:9419, 2606:4700:4407::6812:27e7 |
| CNAME | — |
| NS | ns1.ubmdns.com, ns2.ubmdns.com |
| MX | 0 smtp.secureserver.net 10 mailstore1.secureserver.net |
| TXT | google-site-verification=Ptswr-5L0wXw4e_OrTe2hmDQ5wj_IqiEYUtHiz4K050 SPF v=spf1 a ip4:35.224.70.159 ip4:67.227.230.43/32 include:_spf.google.com include:... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://contentmarketinginstitute.com
75 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://contentmarketinginstitute.com | 200 | 75 ms | HTTP/1.1 | cloudflare |
A+Crawlabilityrobots.txt present, sitemap with 41 URLsPASS
User-agent: *
Sitemap: https://contentmarketinginstitute.com/sitemap.xml
Sitemap: https://contentmarketinginstitute.com/googlenews.xml
Sitemap: https://contentmarketinginstitute.com/contributors.xml
Sitemap: https://contentmarketinginstitute.com/generic-content.xml
Sitemap: https://contentmarketinginstitute.com/image-archive-index.xml
Sitemap: https://contentmarketinginstitute.com/news-archive-index.xml
Sitemap: https://contentmarketinginstitute.com/document-archive-index.xml
Sitemap: https://contentmarketinginstitute.com/videos-archive-index.xml
Sitemap: https://contentmarketinginstitute.com/articles-archive-index.xml
Sitemap: https://contentmarketinginstitute.com/webinar-archive-index.xml
Sitemap: https://contentmarketinginstitute.com/sitemap-index.xml
Disallow: /search
Disallow: /recipe-portal/search
Disallow: /api/health
Disallow: /cdn-cgi/
Disallow: /live-preview/
Disallow: /my-purchases/
User-agent: Amazonbot
User-agent: Anthropic-ai
User-agent: Applebot-Extended
User-agent: AwarioRssBot
User-agent: AwarioSmartBot
User-agent: Bytespider
User-agent: CCBot
User-agent: ClaudeBot
User-agent: Claude-Web
User-agent: Cohere-ai
User-agent: Diffbot
User-agent: FacebookBot
User-agent: GPTBot
User-agent: ImagesiftBot
User-agent: Magpie-crawler
User-agent: Meta-ExternalAgent
User-agent: Omgili
User-agent: Omgilibot
User-agent: PanguBot
User-agent: Peer39_crawler
User-agent: Peer39_crawler/1.0
User-agent: Timpibot
User-agent: Webzio-Extended
Disallow: /
AURL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Use 301 (permanent) instead of 302 (temporary)
A+Domain Intelligencecontentmarketinginstitute.com — via SafeNames Ltd., 16 years, 7 months old, hosted on CloudflarePASS
164 days
November 24, 2026
59 days
Issued by Google Trust Services
16 years, 7 months
Registered November 24, 2009
Enabled
Protects against DNS spoofing
Cloudflare
ASN AS13335
104.18.39.231
SafeNames Ltd.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice