Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations63 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Submit your domain to hstspreload.org to be added to the Chrome preload list
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records3 A records, 176 ms lookupPASS
| A | 3.226.73.193, 35.153.85.206, 34.233.4.33 |
| AAAA | — |
| CNAME | — |
| NS | ns-1251.awsdns-28.org, ns-1898.awsdns-45.co.uk, ns-270.awsdns-33.com, ns-930.awsdns-52.net |
| MX | 10 icims-com.mail.protection.outlook.com |
| TXT | 00df4000001tvhieag 0ed1fe018a7a393b8449cb4d8c8d535174e62df415 ZOOM_verify_wntwTFoaTsCWj5CIx4onlA adobe-idp-site-verification=3d95910192754d6c5af1539747bd30c43829437acb64c557a0a6... apple-domain-verification=Zdf51f04TNmx2YZo atlassian-domain-verification=//OumnkQO3fq1IlhB76DB0IjCeFESIf6C5D/u7hSAX/TDZdWZi... atlassian-domain-verification=3hvmzoEN24TUZ/HanjniijKMwaYmAnhT0/VBWdEaPdqaf18S29... atlassian-domain-verification=YnjkCUVmtdXzDbC6LtYA7SF3VZLsNQzHy5CJTjhtqMlQa/RU7c... cursor-domain-verification-0wchjq=7ZP4exGsT1w0xa62vj0LcQYaG docusign=2eb3265a-f5b8-40a1-ab8a-c13f35a86a2b docusign=60c577f3-f7ed-400d-a425-28f88c7e553c dropbox-domain-verification=k5e4bza4h9zw google-site-verification=1d2tZBgV3XNEFdg6Q07ZuK4hUGxpiIT9iyhrsIdgSIg google-site-verification=9Vyd8OYQSi0IoihR923g6ZlFdqmWz6EpbNh_R8sbouk google-site-verification=b5JLTdlR7ro0ihjTYN22dOGapap3Ztrl_7tDLNpX3os google-site-verification=lQAYu78xtMsmR4sHiHC71Gy58n5qNmRBSseIaocx3lM google-site-verification=yNk-6miQlH-93YvTWmoYPt1rQOV7Skg3q8UuIkQhxTI miro-verification=69b7bb55b72052459714e472e54d8e3530ad4d63 mongodb-site-verification=fCpK1LZZeU1xk6A5ZihURvhzTUVVG5yw onetrust-domain-verification=2431c9ba4af345cfacab43c43b09e5e7 pardot427042=74384a2aa7d95cc966dc7b1f6740aa517c5e900cf31401fb0cd65ab237ab01a7 pardot427042=cbc9dc127f4391f2542143fd2e106be320171efbb38c78c4b47bdb772feb0504 pardot_5122_*=52446f5ccb1f73a70914a001200447aa913f9d0a1e9a7d44f223dd4e1acdbc0f smartsheet-site-validation=JFve6VE-swqIWAVlU_HtZEza6-Fq-Xfl status-page-domain-verification=s6d2h86nr01p stripe-verification=11674f832ae5dcb19089b6dc65ff3f49bbf86b40b1fb925a88047f4c3746... stripe-verification=6d3fa38f2accbf84ed761cf46dca2d345a37f5f848a3ab461e78610daa9b... stripe-verification=ddce19dbb3fc5ad734587e06fa14425111ba3642f9a3d82f2971a91e829a... SPF v=spf1 include:spf.protection.outlook.com include:icims.com._nspf.vali.email inc... wrike-verification=Mjc3OTkwOTo3NWZjYjI1OTNmNWI0NThhNjM1YzE3NGU4Y2I4Njg0Y2RlOWNhN... zoom-domain-verification=82532805-a35b-4953-b30f-65e111891c9e |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 609 ms totalPASS
https://icims.com
549 ms · HTTP/1.1
https://www.icims.com/
60 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://icims.com | 301 | 549 ms | HTTP/1.1 | nginx |
| 2 | https://www.icims.com/ | 200 | 60 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 10 URLsPASS
User-Agent: *
Disallow: /feed
Disallow: /*?*vendor=
Disallow: /*?*targeting-method=
Disallow: /*?*Targeting-Method=
Disallow: /*?*redis=
Disallow: /*?*product_interest=
Disallow: /*?*press=
Disallow: /*?*num=
Disallow: /*?*industry=
Disallow: /*?*cat=
Disallow: /*?*asset_type=
Sitemap: https://www.icims.com/sitemap_index.xml
- https://www.icims.com/post-sitemap.xml
- https://www.icims.com/page-sitemap.xml
- https://www.icims.com/leadership-sitemap...
- https://www.icims.com/news-sitemap.xml
- https://www.icims.com/news-sitemap2.xml
- https://www.icims.com/customers-sitemap....
- https://www.icims.com/glossary-sitemap.x...
- https://www.icims.com/resources-sitemap....
- https://www.icims.com/resource-category-...
- https://www.icims.com/int-sitemap
A+Domain Intelligenceicims.com — via MarkMonitor Inc., 26 years, 10 months old, hosted on AWSPASS
304 days
April 15, 2027
63 days
Issued by Let's Encrypt
26 years, 10 months
Registered October 13, 1999
Not enabled
Protects against DNS spoofing
AWS
ASN AS14618
34.233.4.33
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice