Skip to content
https://derstandard.at

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
80
GRADE
B
FIX
2
REVIEW
9
PASS
6
INFO
0
Probed from Santa Clara, United States
301 Moved Permanently
Checks
17
6 PASS 9 REVIEW 2 FIX
D
Multi-Resolver DNS Speed
Action
Mean 620ms across 3 resolvers (spread 1659ms)
FIX
Mean 620ms across 3 resolvers (spread 1659ms)
Info::
Google: 11ms
Got: 11ms via 8.8.8.8:53
Info::
Cloudflare: 180ms
Got: 180ms via 1.1.1.1:53
Info::
Quad9: 1670ms
Got: 1670ms via 9.9.9.9:53
Info::
High latency spread between resolvers: 1659ms (min 11ms / max 1670ms)
Wide gap between the fastest and slowest public resolver suggests a geographic anycast issue or an authoritative-server cache problem. Users in different regions will see materially different DNS times.
D
CDN & Delivery
Action
No CDN detected
FIX
No CDN detected
Warning::
No CDN detected
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN detected

Consider using a CDN to improve global delivery speed and reduce origin load.

B
DNSSEC
Unsigned (DNSSEC not deployed)
REVIEW
Unsigned (DNSSEC not deployed)
Info::
DNSSEC is not deployed
The zone is not DNSSEC-signed. Users on validating resolvers (Cloudflare 1.1.1.1, Quad9 9.9.9.9, growing default in mobile resolvers) get no protection against DNS spoofing for this domain. Most registrars now offer DNSSEC at a single click; consider enabling it for sites where authenticity matters (banking, healthcare, government).
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
C
Reverse DNS
Action
0/1 IPs match cert SAN
REVIEW
0/1 IPs match cert SAN
Info::
PTR lookup failed for 194.116.243.40: lookup 194.116.243.40: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
B
Redirect Chain
2 redirect(s), 932 ms total
REVIEW
2 redirect(s), 932 ms total
Warning::
2 redirects before reaching final URL
Each redirect adds latency. Try to minimize the chain to 1 hop.
Info::
WWW normalization redirect
Info::
Uses 302 (temporary) redirect
If permanent, use 301 instead.
Got: https://www.derstandard.at/
Info::
Redirect overhead: 932 ms total
Got: 932 ms

https://derstandard.at

893 ms · HTTP/1.1

301

https://www.derstandard.at/

36 ms · HTTP/1.1

302

https://www.derstandard.at/consent/tcf/

4 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://derstandard.at301893 msHTTP/1.1LoadbalancerMMXX
2https://www.derstandard.at/30236 msHTTP/1.1AkamaiGHost
3https://www.derstandard.at/consent/tcf/2004 msHTTP/1.1nginx

See the visual redirect chain in the HTTP Probe tab →

Each redirect adds latency. Try to minimize the chain to 1 hop.

Why this matters

Redirect chain — each hop adds latency; combine into one redirect where possible.

Source: Google Search Central / web.dev

If permanent, use 301 instead.

Why this matters

302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.

Learn more

Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).

Source: Google Search Central

C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
HTTP Probe Timing
Total 908 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
REVIEW
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
180 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
181 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
366 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
909 ms
Total Time Total request time from DNS lookup through full response.
909 ms

Connection waterfall

DNS Lookup 180 ms TCP Connect 181 ms TLS Handshake 366 ms Server Processing 181 ms Content Transfer 0 ms
B
TLS Certificate Expiry & Recommendations
224 days until leaf cert expires — 4 issues to address
REVIEW

Certificate validity

224
days left
0d 30d 60d 90d+

Recommended actions

  • Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
CDN Cache Observability
No CDN cache-status headers in the response
REVIEW
No CDN cache-status headers in the response
Info::
No CDN cache-status headers in the response
Without an X-Cache / CF-Cache-Status / X-Vercel-Cache / Age header, you can't tell from outside whether a request hit the cache or went to origin. Operationally important: enables debugging stale-content reports and verifying cache rules. Most managed CDN platforms emit at least one of these by default; absence often means the platform's diagnostic headers are stripped at an upstream proxy.
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
A
DNS Records
1 A records, 532 ms lookup
PASS
1 A records, 532 ms lookup
Info::
Resolves to 1 IPv4 address(es)
Got: 194.116.243.40
Info::
Single A record — no DNS redundancy
Multiple A records provide failover if one server goes down.
Info::
No IPv6 (AAAA) records
Info::
4 nameserver(s) configured
Got: sec1.rcode0.net, ns.mail.at, balancer1.derstandard.at, sec2.rcode0.net
Info::
1 mail exchanger(s) configured
Info::
SPF record present in TXT
Warning::
DNS resolution is slow (532 ms)
Slow DNS adds latency to every page load. Consider a faster DNS provider.
Got: 532 ms
A194.116.243.40
AAAA
CNAME
NSsec1.rcode0.net, ns.mail.at, balancer1.derstandard.at, sec2.rcode0.net
MX
0 derstandard-at.mail.protection.outlook.com
TXT
MS=ms47139657
463hqfkfn7pp4qco7q3hbe72nr
8j70uh0alffcqo4ulhefqn4cu9
lrrkvjvug814au5trqa565mkf3
n1ukfh61knh8v9iemfi3msci9o
o6eros8k88k00i4hacqtphplph
ra2jkotslrt599p7tlc7reu55a
_dsnvnz8y7zjffjpoe7rpjqp8hk2n5i2
asv=5c83174f60a55f42ed4f4ec797367efd
apple-domain-verification=ilXaxDxHZsG8vMdZ
google-gws-recovery-domain-verification=38576565
facebook-domain-verification=5ag8hyc6wqzfwxqg41p72uesc5mvxj
anthropic-domain-verification-bt1fwj=t14ENGDlUL8QCuBELCvRD0M2g
extensis-domain-verification=059c0e13-ec6a-4618-88c5-15eaa7800b02
google-site-verification=3RcJbxU0JMk9FMSCk8-qEeEX7pi6BRuJQfrW6DZKecs
google-site-verification=CUTFvpQOKxH-wVJFImIpj5WJoQKJCPsv0ZdxQ6G80Ok
_globalsign-domain-verification=R2fidElKRz9PyZrETeA608Kwr__kYKcDBYrJXSlyCM
3pdAynlPoFTwwe8s998I/fnKmP0SbUzz+4OtAdpkHiUDJw4o2vuVvf4AnV5WSu/gBjGi+Wm2VtL3xCqG...
sophos-domain-verification=cd89786b74bca992610b7763c16c27a056cfe3ad76da5cc443d26...
adobe-idp-site-verification=95754749636675a21e252ba5473acb7579df7f766b2a18ad0162...
atlassian-domain-verification=6u2jZzBuzIVC0Cfhoq9YqnRo8PZmlw/dVDI3b6ip/rxO3D7A38...
SPF v=spf1 ip4:194.116.242.0/23 ip4:193.154.214.0/24 ip4:193.228.122.163 ip4:54.77.1...
CAALookup not available with standard resolver
Resolved in 532 ms

Multiple A records provide failover if one server goes down.

Why this matters

Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.

Learn more

Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.

Source: SRE practice / DNS architecture

Slow DNS adds latency to every page load. Consider a faster DNS provider.

Why this matters

DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.

Source: DNS performance benchmarks

A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
Crawlability
robots.txt present, sitemap with 191 URLs
PASS
robots.txt present, sitemap with 191 URLs
Info::
robots.txt is present
Got: 1241 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 191 entries
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 1241 B Sitemaps referenced 2 User-agents Perplexity-User, anthropic-ai, CCBot, ChatGPT-User, ClaudeBot, omgilibot, DeepSeekBot, Bytespider, Claude-Web, Google-Extended, GPTBot, ia_archiver, Kangaroo Bot, PanguBot, Spider, Ai2Bot-Dolma, Applebot-Extended, omgili, PerplexityBot, ChatGLM-Spider, Google-CloudVertexBot, Cotoyogi, cohere-training-data-crawler, FacebookBot, CloudVertexBot, meta-externalagent Blocking No — crawling allowed
User-agent: Applebot-Extended

Disallow: /


User-agent: anthropic-ai

Disallow: /


User-agent: CCBot

Disallow: /


User-agent: ChatGPT-User

Disallow: /


User-agent: ClaudeBot

Disallow: /


User-agent: Claude-Web

Disallow: /


User-agent: FacebookBot

Disallow: /


User-agent: Google-Extended

Disallow: /


User-agent: GPTBot

Disallow: /


User-agent: ia_archiver

Disallow: /


User-agent: omgili

Disallow: /


User-agent: omgilibot

Disallow: /


User-agent: PerplexityBot

Disallow: /


User-agent: Perplexity-User

Disallow: /


User-agent: DeepSeekBot

Disallow: /


User-agent: Bytespider

Disallow: /


User-agent: CloudVertexBot

Disallow: /


User-agent: Kangaroo Bot

Disallow: /


User-agent: PanguBot

Disallow: /


User-agent: Spider

Disallow: /


User-agent: Ai2Bot-Dolma

Disallow: /


User-agent: Bytespider

Disallow: /


User-agent: ChatGLM-Spider

Disallow: /


User-agent: Google-CloudVertexBot

Disallow: /


User-agent: Cotoyogi

Disallow: /


User-agent: cohere-training-data-crawler

Disallow: /


User-agent: meta-externalagent

Disallow: /



Sitemap: https://www.derstandard.at/sitemaps/news.xml

Sitemap: https://www.derstandard.at/sitemaps/sitemap.xml



Crawl-delay: 1

A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Info::
HTTP correctly 301-redirects to HTTPS

www / non-www

302https://www.derstandard.at/
200https://derstandard.at/

Preferred variant: non-www

HTTP → HTTPS

301http://derstandard.at/ https://derstandard.at/

Consistent

A+
Domain Intelligence
derstandard.at — hosted on DERSTANDARD-AS - STANDARD Verlagsgesellschaft m.b.H., AT
PASS
derstandard.at — hosted on DERSTANDARD-AS - STANDARD Verlagsgesellschaft m.b.H., AT
Info::
Hosting: DERSTANDARD-AS - STANDARD Verlagsgesellschaft m.b.H., AT
Got: AS44865
Domain expiry

Unknown

SSL certificate

224 days

Issued by GoDaddy.com, Inc.

Domain age

Unknown

DNSSEC

Status unknown

Protects against DNS spoofing

Hosting

DERSTANDARD-AS - STANDARD Verlagsgesellschaft m.b.H., AT

ASN AS44865

194.116.243.40

Registrar

Registrar unknown

Lock status unknown 4 NS records
Expiry timeline
Today
+1 year
SSL expiry Danger zone (≤30 days)
Registrar
Name Servers balancer1.derstandard.at, ns.mail.at, sec1.rcode0.net, sec2.rcode0.net
Registrant Standard Verlagsgesellschaft m.b.H.
Hosting
IP Address 194.116.243.40
ASN AS44865 (DERSTANDARD-AS - STANDARD Verlagsgesellschaft m.b.H., AT)
Provider DERSTANDARD-AS - STANDARD Verlagsgesellschaft m.b.H., AT
Data source: whois (0.6s)
A+
Health Check Endpoint
Health endpoint at https://derstandard.at/health (HTTP 200)
PASS
Health endpoint at https://derstandard.at/health (HTTP 200)
Info::
Public health endpoint at https://derstandard.at/health
Got: https://derstandard.at/health
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback