Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BCrawlabilityno robots.txt, no sitemapREVIEW
robots.txt is optional but recommended. It tells search engine crawlers which pages to index.
No robots.txt — crawlers fetch /robots.txt and get 404; not breaking but means default crawl behavior with no directives or sitemap reference.
Learn more ▾ ▴
A minimal robots.txt with `User-agent: * / Allow: / / Sitemap: https://example.com/sitemap.xml` covers the basics. Without it, crawlers behave fine but lose the sitemap signal and can't be selectively blocked from crawl-traps.
Source: robotstxt.org
A sitemap helps search engines discover and index your pages more efficiently.
No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.
Learn more ▾ ▴
A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.
Source: sitemaps.org / Google Search Central
No robots.txt found
This is fine for most sites — a missing robots.txt allows all crawling by default.
No sitemap found
Adding a sitemap helps search engines discover your pages.
BTLS Certificate Expiry & Recommendations82 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records1 A records, 12 ms lookupPASS
| A | 23.227.38.32 |
| AAAA | — |
| CNAME | — |
| NS | udns1.cscdns.net, udns2.cscdns.uk |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 aspmx3.googlemail.com 10 aspmx2.googlemail.com |
| TXT | 380DA2D1C2 KJ3-HA9-NC4 MS=ms33437132 MS=ms93986860 EJVrSUZZtWLERUuM0+rqgBNxQc0= klaviyo-site-verification=TEJqNp asv=4da557c4c26bb8c22262c030574786a9 dQxOOTut=abafbd99dd5da746efdc407e80223d74 apple-domain-verification=3VuTGOyZglvaXOhz apple-domain-verification=6DBs5wc8WFIsHxWz F5xuicXR-m1IJuZCG82AzvkW0a9fg8pejP9c6ildlgM brevo-code:0d82261692bd5f43cdfc86ec68c03edc brevo-code:161f5c688beb6d36333ac2b42e6cd5c7 brevo-code:273e0d26a7f3f2c9918851555d1b0a7c brevo-code:66f2ecfcb2208adc081ba002ca2e4d5e brevo-code:c14e4e64506313e21c0f8cfbd641e8a8 brevo-code:d52359a375b0260eeafcbc951bcc6611 brevo-code:f8047eb7f810e5ed7e9766fb02175b92 18eUC5zeu8nuVYnTL1rYJ5WEz1eEhWMUI6robLvjH1c= FlLVP3UW7cXWHSF5XtdzNaGfeT4oBh6OkHf9QoX3974= TDZBIfP6JJoXZgdX12szWzJg7clFMUi+UXvkq+f+KYA= r6tfdz+dS8JjPERBNyQNVdH8faloZhRBh+Rkeovj11w= docusign=441689db-404c-4a76-8284-83bb74494304 docusign=7c5f7f6f-429c-42ec-ac25-1153975552e1 zoho-verification=zb76100411.zmverify.zoho.eu canva-site-verification=jP6Ok282wwmRcD6sm3bPeg Sendinblue-code:dd32b820b6cc6838849527492fb1cd64 gradle-verification=VC14IJ7RRO0I5TJC8GPLL28S0IA0E astro-domain-verification=cmmkd1hyu4h1501p8h16ta9qz amazonses:G5FAlZD41+GFNbWKZNlro6Z3TgM3ANo2Xzj+9B8R6Bg= amazonses:JNwEjQXlsA9H9sLGplqIreScGtt/XEG+2d3ciAPwb2Q= amazonses:X0rgROZY0YpHD55hLoZ28QfaMlnLSxRsPJ1DbMOsaY4= amazonses:b1egfY+o3NncTGY1cLUhFxwOqCrqKy3B7jsQUfsoia8= amazonses:i6bV2UWOPaXNqitgPzJIi4MAhLSznMOGhr659LVVFj4= amazonses:iJ8hckxSTDkkSDwusFkiatQi05KKog7B3xAl8AEmIn0= amazonses:sa9efIoIgAWpZeCr5zI/3RA0urKBSwQIY8y6ZHRCwSQ= amazonses:ukVeHgab65HgOEEeDnZbSDtDBTPj5MLRHp3kmr9xlaw= amazonses:w22FoTSBJ2LjQLwkJE2PqZf+WMS8NN+iQY/2BWIEJ7s= elevenlabs=Tvy_c0kP4ndGgClZlnOA12u9Ev4jbBYNcTqPAueQrzA shopify-verification-code=OZHrIWN3uwfRDFWTNi5KnOD3k5GZBo SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com -all Validity-Domain-Verification=M7kFhXLn7XqF+K9N+JPfu+AH6YU= miro-verification=37acd7e2c96cf70579346dced3ae2e3dd9f29928 mongodb-site-verification=tnO3kEkG9XNVvm7uwFNAVrgPIm1X1akD twilio-domain-verification=3e81df968610d6d7ddb3d7dadc063544 digicert-domain-verification=_imlyj9n557elo27q4897uvcmueetylr globalsign-domain-verification=3c2d41532e2a883189469e6ca48284ee globalsign-domain-verification=74c62f877594976014e07882dc47c927 globalsign-domain-verification=7f3df866d79a5c0d5d7c705ac65dfaa1 adobe-idp-site-verification=a4a2d4e3-b724-4920-a3b9-98a6c217cadc globalsign-domain-verificationz57d18de11d504de6783330e11f30f013
google-site-verification=1meGXSv1cxSXTrSHUS0-XKrnMvMw26IP0kf5I4CAKuE google-site-verification=2jUV6XnXObfL3El0uyROUJaUw_A3BTqb4qk1f3GKvds google-site-verification=9_UeFpKNZEwj5qeLfmc1j6hDRH2GT6cnfbXTm6vZ4uc google-site-verification=B7wftePYWk09fxSQuOWbGRQkBoaJm5Zmeh8xM4Gy3YY google-site-verification=SPuUVLb-kEgbFw-gyCjBKwGoNvg6zmBRb3R3dEypLgg google-site-verification=UPtYPv64e0eUusO6Ez-CpxyBLSJk6JpFQbP-broDcxA google-site-verification=alkRsKofA3B6s529a-uPcvqJTmf2AAtVCXOs6hltJbQ google-site-verification=dkibJRJ4yKYUCo7lvZ1n64ZhwPu3whO_Tln5pBEQ06M google-site-verification=huyPsIlh9YD9nPy06zhRm0OnVNRIsdRmggCN6YORuQM google-site-verification=rfs5-49SqYm-eYbnFLXkej1yessgLSaGUcsJGAjSshE google-site-verification=vWCBTqycOkcpwruepoK4jqIzIcLkBoFesEpw8XLjGEg google-site-verification=yqYhcvj-ZPJCrUWXE9fyfzi5RVnPlxeO7DnzVYJx4fI heroku-domain-verification=lgpmv0z1waimvedgnbjr1vq0x2dtjel/lfyeuxgdxa safetyculture-domain-verification=4cdb8109-b334-4c93-8fc1-fba4f8d304a5 _globalsign-domain-verification=BdBlLDD3Gx_qEoSHwcWZR571ulky5_-OnJXtJSaJyT _globalsign-domain-verification=CPsXBCmywifW4Xlk5UHVWfTFAa2FwgJbvu8IdT9O08 _globalsign-domain-verification=L-ZlaZKBNszvVAdNkF0ECmv_xgEZVVLR_5ByAeHfs8 _globalsign-domain-verification=o3V8aVrMp_ZcIUdAl0iicAqdOZmRl4KDHOqN9tqDlK _globalsign-domain-verification=uIstEgiSI8Gyg1xIW80gVoJ3Ox48FPPIj5EbPsE9Dt Dynatrace-site-verification=a19022e8-1978-46a5-92cb-00baebe51999__tvlm72pes1c4s6... cisco-ci-domain-verification=a8a7396864d1922546b26e0cfdc0fbf4daedf3ccfee1bd568ab... cisco-ci-domain-verification=55b37a7f40e88f7f4995bfb6610108880f7d20e16aff691c674... cisco-ci-domain-verification=7fbfe7a77752c5f7ef5c80abf833704e1e0639c87814b34ef99... webexdomainverification.4F40C8799A6C5713E0536B15FE0A7FEF=b9c22632-eae4-4552-a476... webexdomainverification.550bc28ddf397aabe0536b15fe0a0072=b3663283-46ec-43cb-8ed2... atlassian-domain-verification=C4QiHXUIxRecUgThTaHYwusxspyubM2Ym3HlzJLxF1qeY7UK9T... |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect Chain0 redirect(s), 23 ms totalPASS
https://decathlon.com
23 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://decathlon.com | 429 | 23 ms | HTTP/1.1 | cloudflare |
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Consistent
ADomain Intelligencedecathlon.com — via CSC Corporate Domains, Inc., 31 years, 3 months old, hosted on CloudflarePASS
2 days
May 30, 2026
82 days
Issued by Let's Encrypt
31 years, 3 months
Registered May 31, 1995
Not enabled
Protects against DNS spoofing
Cloudflare
ASN AS13335
23.227.38.32
CSC Corporate Domains, Inc.
Expiry timeline
Recommended actions
- Renew the domain or enable auto-renewal to prevent accidental expiry
- Enable DNSSEC to protect visitors from DNS spoofing
Consider enabling auto-renewal to prevent accidental expiration.
Domain expiry approaching — renew immediately and ensure auto-renew + alerting are configured.
Source: ICANN renewal policy
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033