Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSFIX
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
HTTP version does not redirect to HTTPS
BRedirect Chain2 redirect(s), 355 ms totalREVIEW
https://merkur.de
105 ms · HTTP/1.1
http://www.merkur.de/
113 ms · HTTP/1.1
https://www.merkur.de/
138 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://merkur.de | 301 | 105 ms | HTTP/1.1 | nginx |
| 2 | http://www.merkur.de/ | 301 | 113 ms | HTTP/1.1 | nginx |
| 3 | https://www.merkur.de/ | 200 | 138 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
Each redirect adds latency. Try to minimize the chain to 1 hop.
Redirect chain — each hop adds latency; combine into one redirect where possible.
Source: Google Search Central / web.dev
Redirect directly from https://merkur.de to https://www.merkur.de/
Redirect chain could be flattened to one hop — server config tweak removes intermediate latency.
Source: web.dev
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations59 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 60 ms lookupPASS
| A | 193.218.202.89 |
| AAAA | — |
| CNAME | — |
| NS | anycast.regdns1.de, anycast.regdns2.net |
| MX | 10 merkur-de.mail.protection.outlook.com |
| TXT | google-site-verification=9DDUx7Mh7HdxyQuvrKtq9DmfeTPt3Nj9nQLcwzGRbtQ google-site-verification=1BIP2v4g3CdOn4vkSgv43JZJn6rbOiY_TjcNZV4Nq5E pinterest-site-verification=392ca7bbfa31df8933d750f3df0e5bc9 google-site-verification=XVEVECeJVYBUo2ByPEVV2CoV27XPDPC3Qz55xvNErwo google-site-verification=XbfePUXEXC4woQyFNMqJWkm1yGnuytZOtBPD7I-2ne0 apple-domain-verification=JwIkqvcB5MXV7sXA MS=ms89234765 pinterest-site-verification=736f1ace50fec1a96230e760296afa5a facebook-domain-verification=r1r43akeu36l668an9pos239rox8zi SPF v=spf1 include:spf.protection.outlook.com include:spf.ippen-media.de ~all MS=ms18547019 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 1000 URLsPASS
# robots.txt www.merkur.de
# Legal notice: www.merkur.de expressly reserves the right to use its content for commercial text and data mining (§ 44b UrhG).
# The use of robots or other automated means to access www.merkur.de or collect or mine data without the express permission of www.merkur.de is strictly prohibited.
User-agent: *
Disallow: /sub/paywall/js/
Disallow: /lightweight-ajax
Disallow: /suche/
Disallow: /test/
Disallow: /west/
Disallow: /fdn/bootstrap/
Disallow: /bi/bootstrap/
Disallow: /bi/doop/
Disallow: /bi/dev/
Disallow: /sso/
Disallow: /west/assets/common/js/fallback.js
Sitemap: https://www.merkur.de/news.xml
# AI
User-agent: Amazonbot
User-agent: AlibabaBot
User-agent: Ai2Bot-Dolma
User-agent: Applebot-Extended
User-agent: Bytespider
User-agent: CCBot
User-agent: ChatGLM-Spider
User-agent: ClaudeBot
User-agent: Claude-Web
User-agent: CloudVertexBot
User-agent: cohere-training-data-crawler
User-agent: Cotoyogi
User-agent: Datenbank Crawler
User-agent: Diffbot
User-agent: FacebookBot
User-agent: Google-Extended
User-agent: GoogleOther
User-agent: GPTBot
User-agent: ICC-Crawler
User-agent: imageSpider
User-agent: Kangaroo Bot
User-agent: laion-huggingface-processor
User-agent: LCC
User-agent: meta-externalagent
User-agent: netEstate Imprint Crawler
User-agent: omgili
User-agent: PanguBot
User-agent: PerplexityBot
User-agent: SBIntuitionsBot
User-agent: Spider
User-agent: Timpibot
User-agent: VelenPublicWebCrawler
User-agent: webzio-extended
User-agent: YouBot
Allow: /ueber-uns/
Disallow: /
# scraper
User-agent: 008
User-agent: Dataprovider.com
User-agent: dcrawl
User-agent: HelloworkJobPostingBot
User-agent: HTTrack
User-agent: HTTrack 3.0
User-agent: KrawlerBot
User-agent: MetaInspector
User-agent: MetaJobBot
User-agent: newspaper
User-agent: Nutch
User-agent: Offline Explorer
User-agent: OpenindexSpider
User-agent: Potions
User-agent: Scrapy
User-agent: ServerHunterSpider
User-agent: StatsDroneBot
User-agent: CloudflareBrowserRenderingCrawler
Disallow: /
# seo tools
User-agent: aa
User-agent: AhrefsBot
User-agent: Attracta
User-agent: Barkrowler
User-agent: BrightEdge Crawler
User-agent: BLEXBot
User-agent: CaliberBot
User-agent: Caliperbot
User-agent: ClarityBot
User-agent: Clearscopebot
User-agent: Cloudtrellis
User-agent: cludo.com
User-agent: Cocolyzebot
User-agent: cognitiveSEO Crawler
User-agent: contentking
User-agent: Convermax
User-agent: Cxense
User-agent: DataForSeoBot
User-agent: DataForSEO Bot
User-agent: DomainStatsBot
User-agent: DotBot
User-agent: Dragonbot
User-agent: Huckabot
User-agent: Huckabuy Bot
User-agent: hypestat
User-agent: iaskspider
User-agent: img2dataset
User-agent: James BOT
User-agent: LinkCheck by Siteimprove
User-agent: LinkChecker Bot
User-agent: linkchecker.pro
User-agent: linkdexbot
User-agent: LinksIndexerBot
User-agent: MarketGoo
User-agent: MBCrawler
User-agent: MegaIndex.ru
User-agent: MJ12bot
User-agent: Moz dotbot
User-agent: Moz rogerbot
User-agent: Nitro-
User-agent: NitroBot
User-agent: online-webceo-bot
User-agent: Prerender
User-agent: Pro Sitemaps
User-agent: Readable
User-agent: RevvimGort
User-agent: rogerbot-crawler
User-agent: RSiteAuditor
User-agent: SearchAtlas Bot
User-agent: SEBot-WA
User-agent: SearchmetricsBot
User-agent: SemrushBot-BA
User-agent: SemrushBot-CT
User-agent: SemrushBot-OCOB
User-agent: SemrushBot-SA
User-agent: SemrushBot-SI
User-agent: SemrushBotBacklinks
User-agent: Senutobot
User-agent: Sidetrade indexer bot
User-agent: seo-audit-check-bot
User-agent: seo4ajax
User-agent: seo4ajax.com
User-agent: SeobilityBot
User-agent: SEOkicks
User-agent: SEOlizer
User-agent: SERankingBacklinksBot
User-agent: serpstatbot
User-agent: SiteAuditBot
User-agent: Sitebulb
User-agent: SiteCheck-sitecrawl
User-agent: SiteCheckerBotCrawler
User-agent: Siteimprove Crawl
User-agent: StatusNestBacklinkSpider
User-agent: Seekport
User-agent: SeekportBot
User-agent: sistrix
User-agent: woorankreview
User-agent: xovi
User-agent: XoviOnpageCrawler
User-agent: Zoombot
Disallow: /
# Intelligence Gatherer
User-agent: A360-Search
User-agent: ActiveComply
User-agent: aiHitBot
User-agent: AndersPinkBot
User-agent: ArchiveBot
User-agent: Automattic Analytics Crawler
User-agent: Awario
User-agent: AwarioBot
User-agent: AwarioSmartBot
User-agent: BigUpDataBot
User-agent: BitSightBot
User-agent: Blackboard
User-agent: BomboraBot
User-agent: BrightEdge Bot
User-agent: Buck
User-agent: channable
User-agent: CheckMarkNetwork
User-agent: Cincraw
User-agent: Clickagy Intelligence Bot v2
User-agent: ContextualBot
User-agent: contxbot
User-agent: cXensebot
User-agent: ds9
User-agent: EcoVadisSustainabilityBot
User-agent: EpivozCrawler
User-agent: ev-crawler
User-agent: EzoicBot-Nicheiq
User-agent: factset_spyderbot
User-agent: FDL Stats Bot
User-agent: HubSpot
User-agent: Innguma
User-agent: LightspeedSystemsCrawler
User-agent: linkfluence
User-agent: LinkWalker
User-agent: Macrobondbot
User-agent: Magpie-crawler
User-agent: MedialogiaBot
User-agent: MediaMonitoringBot
User-agent: Mediatoolkitbot
User-agent: Mediavine Medatada Parser
User-agent: Missinglettr Bot
User-agent: MixrankBot
User-agent: MuckRack
User-agent: Netcraft
User-agent: netEstate NE Crawler
User-agent: NetSeer crawler
User-agent: Netvibes
User-agent: Owler
User-agent: page-preview-tool
User-agent: Pandalytics
User-agent: panscient.com
User-agent: parse.ly scraper
User-agent: SentiBot
User-agent: SlickBot
User-agent: slickstream
User-agent: SMTBot
User-agent: TrendsmapResolver
User-agent: TTD-Content
User-agent: TurnitinBot
User-agent: TweetmemeBot
User-agent: Twingly
User-agent: Twingly Recon-Sjostrom
User-agent: um-FC
User-agent: um-IC
User-agent: um-LN
User-agent: webspidermount
User-agent: webzio
User-agent: YaDirectFetcher
User-agent: YaK
User-agent: Yext Inc
User-agent: YextBot
User-agent: ZoominfoBot
User-agent: ImagesiftBot
Allow: /ueber-uns/
Disallow: /
# Archiver
User-agent: archive.org_bot
User-agent: Arquivo-web-crawler
User-agent: Authory
User-agent: bl.uk_lddc_bot
User-agent: bne.es_bot
User-agent: bnf.fr_bot
User-agent: heritrix
User-agent: ia_archiver
User-agent: ia_archiver-web.archive.org
User-agent: IABot
User-agent: Internet Archive
User-agent: mirrorweb
User-agent: netarkivindsamling
User-agent: Nicecrawler
User-agent: special_archiver
User-agent: Turnitin
User-agent: XY-Archive-Compliance
Allow: /ueber-uns/
Disallow: /
# undocumented / uncategorized
User-agent: Anthropic-ai
User-agent: AwarioRssBot
User-agent: AwarioSmartBot
User-agent: Baidu-YunGuanCe
User-agent: Claude-Web
User-agent: Cohere-ai
User-agent: EtaoSpider
User-agent: Omgilibot
User-agent: Opebot-v
User-agent: Peer39_crawler
User-agent: Peer39_crawler/1.0
User-agent: Keydrop.io
User-agent: CensysInspect
User-agent: xAI
User-agent: Grok
User-agent: GrokBot
User-agent: GrokAI
User-agent: websauger
User-agent: webwhacker
User-agent: webzip
User-agent: webcapture
User-agent: WebCapture 2.0
User-agent: Teleport
User-agent: TeleportPro
User-agent: sitesnagger
User-agent: vorebot
User-agent: WinHTTrack
Disallow: /
- https://www.merkur.de/bayern/regensburg/schwerer-unfall-in-nabburg-zweijaehrige-geraet-in-lebensgefahr-94274418.html
- https://www.merkur.de/deutschland/hessen/isenburg-zentrum-geschaefte-verweigern-jaehrigem-toilettengang-im-94266443.html
- https://www.merkur.de/sport/fc-bayern/bayer-leverkusen-gegen-fc-bayern-heute-im-liveticker-dfb-pokal-halbfinale-kompany-zr-94274147.html
- https://www.merkur.de/deutschland/hessen/spickzettel-war-gestern-wie-hessens-fahrschueler-bei-der-theoriepruefung-betruegen-94266423.html
- https://www.merkur.de/boulevard/das-faellt-prinzessin-kate-bei-grossen-royal-events-schwer-zr-94274487.html
A+Domain Intelligencemerkur.de — hosted on NMM-AS D - 02742 Friedersdorf Hauptstrasse 68, DEPASS
Unknown
59 days
Issued by Let's Encrypt
Unknown
Status unknown
Protects against DNS spoofing
NMM-AS D - 02742 Friedersdorf Hauptstrasse 68, DE
ASN AS34788
193.218.202.89
Registrar unknown
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice