Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations280 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryAkamaiREVIEW
A+DNS Records1 A records, 9 ms lookupPASS
| A | 184.24.166.61 |
| AAAA | 2a02:26f0:1180:183::e96, 2a02:26f0:1180:19a::e96 |
| CNAME | — |
| NS | dns1.p01.nsone.net, dns2.p01.nsone.net, dns3.p01.nsone.net, dns4.p01.nsone.net |
| MX | 0 overstock-com.mail.protection.outlook.com |
| TXT | f9ZtNknHxHL5abJ6sP4n 794a5440-2f7e-4290-a111-d760825bfeed docker-verification=00f612b4-15a8-46ae-bf21-393a993c1b43 globalsign-domain-verification=51930d36897f77a8aa763ef9b730fc90 google-site-verification=-R3F1JCZ-YdCBGCgpU8QnTO3UdaWpmgb78lbMuXeqro google-site-verification=PLPmk5cozL_pVgYYV90K1_-sVH_QeS5NOQbJhdgQlH4 google-site-verification=UUPHMXa2WH-c7Ys9XL_GPwPAkxNv30jPjL-9RIeUuQc google-site-verification=VrzafT6KoHLIM-B7JiT4dh2C-fGBTObm_Zo_X3WMYdk google-site-verification=hMfR3Z6ihuxLHC8UHB8dsH7_71t2r4SPrw3o1Qnpeho google-site-verification=k5byGCYNNnSKN5QdbOmnB4QHHCzrw5qGrDvjpfZPjc8 google-site-verification=lwFhdI9C5N47saoU82L1IMs6aKWf2pcWgsVkFhMYJU8 google-site-verification=sAwY-6V5arQLrN2vY7sPrzNHK5A5G9d9sY9Jgy7LrLU _globalsign-domain-verification=EGXYWFCTQynvOf5IBle5NjMEbKo9PBQaeH9mnr_Faj _globalsign-domain-verification=NIyArddHtOpe5kb_pCFH5D_yiT5xVzEqeORSeRee0e +bcd9BHkZzHoTMOHkZirO2Z0FzBmBxCVNUMvJL0oTEtOkQL2kGPDmmozPsq5PCWLs3ichMIz4+Zgn1W/... ahrefs-site-verification_cea064a893366cd43a3c4062df9c8f11662ee73530c0c6f325d10aa... atlassian-domain-verification=RlWBXVhdSBLcKksNQLCSI0icckuVo55zfKultsMlgfj9lWcAID... SPF v=spf1 ip4:65.116.112.0/21 ip4:173.241.144.0/20 ip4:52.8.140.255 ip4:54.164.132.... |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 475 ms totalPASS
https://overstock.com
23 ms · HTTP/1.1
https://www.overstock.com/
452 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://overstock.com | 301 | 23 ms | HTTP/1.1 | AkamaiGHost |
| 2 | https://www.overstock.com/ | 200 | 452 ms | HTTP/1.1 | Vercel |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 59 URLsPASS
User-agent: GPTBot
Disallow: /*~*/results.html
User-agent: Sogou web spider
Disallow: */results.html
User-agent: Amazonbot
Disallow: /*~*/results.html
User-agent: meta-externalagent
Disallow: /*~*/results.html
User-agent: Mediapartners-Google
Disallow: /
User-Agent: Pinterestbot
Crawl-delay: 0.2
User-Agent: GoogleOther
Disallow: /c/*
Disallow: */results.html
User-Agent: PetalBot
Disallow: */results.html
User-Agent: *
Disallow: /api/
Disallow: /cart
Disallow: /checkout
Disallow: /order-confirmation
Disallow: /paypal-checkout
Disallow: /paypal-processing
Disallow: *~*/*.html
Disallow: /*/*/*/*,*,*,*,*/*/*.html
Disallow: /*/*/*,*,*,*,/*,*,*,*,/*/*.html
Disallow: /*,*,/*,/results.html
Disallow: *shipping,*
Disallow: /*,/k,*
Disallow: /c/*?*&*&*&*&*&*
Disallow: /c/*?*a*=*-*-*
Disallow: /*?*brand=*~*
Disallow: /*?*senttime=*
Disallow: /*?*send_id=*
Disallow: /*?*dispatch_id=*
Disallow: /*?*token=*
Disallow: /*?*price=*
Disallow: /*?*products=*
Disallow: /*~*~*
Disallow: /octs/track/onecall/*
Disallow: /onecalltracking/*
Disallow: /*?*featuredproduct=
Sitemap: https://api.overstock.com/sitemaps/overstock-v3/us/sitemap.xml
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
- https://api.overstock.com/sitemaps/overs...
A+Domain Intelligenceoverstock.com — via MarkMonitor Inc., 27 years, 7 months oldPASS
240 days
February 11, 2027
280 days
Issued by DigiCert Inc
27 years, 7 months
Registered February 11, 1999
Enabled
Protects against DNS spoofing
Unknown
2a02:26f0:1180:183::e96
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice