Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BDNSSECUnsigned (DNSSEC not deployed)REVIEW
BCAA RecordsNo CAA records (any CA may issue certificates)REVIEW
BReverse DNS0/2 IPs match cert SANREVIEW
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations68 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryAkamaiREVIEW
BCDN Cache ObservabilityNo CDN cache-status headers in the responseREVIEW
BOperational Status PageNo status page link detectedREVIEW
BHealth Check EndpointNo conventional health endpoint foundREVIEW
A+DNS Records2 A records, 85 ms lookupPASS
| A | 95.101.239.176, 95.101.239.178 |
| AAAA | — |
| CNAME | — |
| NS | a18-65.akam.net, a1-148.akam.net, a7-67.akam.net, a5-65.akam.net, a16-64.akam.net, a12-65.akam.net |
| MX | 5 mx0a-001bf601.pphosted.com 5 mx0b-001bf601.pphosted.com 10 mxa-001bf601.gslb.pphosted.com 10 mxb-001bf601.gslb.pphosted.com |
| TXT | SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ip4:192.28.146.104/32 ip4:19... mongodb-site-verification=zXIY4xiw9vi8xOfOumgTLDfyZ3ofk2kw _globalsign-domain-verification=wjJQ2UYQWEucub5NGv5OMV6P-bfXLvizwll_LtWtX3 docusign=6e2b1ec8-2f66-4b8a-bff9-cc3105fa5bb8 browserstack-domain-verification=e7301008-4155-48e6-96d1-f7fa80e52fd6 _q88qawgh3excaogrbf7cvdo28sdj8ia _gf5mv6eyzlltwqrtgaf9igb20s9pfog wiz-domain-verification=ebdf2f09c916f026894642180ace4049ad64e78d1685ab758f06d22c... docusign=f2d64448-94de-44d3-8ce5-353d05819274 MS=ms15146138 facebook-domain-verification=79esg7n82tq8cwyisaodmgi937dpc9 google-site-verification=WnK3OGXPzf93OkYzb0r4cFg0BMyZXVj0Izffi_B1gx0 bw=he4iBLkEPDGY87gvTNe9FHBeuNSH6ycXVm7DixE38g4e _sfjr2erc8z2p0k2t78gs5ezf9ccayry extensis-domain-verification=8cbb3e08-38d3-43e5-a26c-ecbe23bc6b5b _xfzrbmhxie7kv8g3796d6o5h3xx5kg3 _vkmqqqs37b6mzfk4hbi9xz53iyw9m43 _ucivhm2v0cbs1lur7t629qv8azj2mf8 ZOOM_verify_EypkM8mdTIGAzMaaU6FQqQ d365mktkey=5jwvpf0sq2hnxck74g4j2bvir _y699lsz03iab1tidvv19skei417xune _globalsign-domain-verification=XFIuRTkNngLrU5i-shLulkoMIEi0_Zt4oDrwX2jY6T _3hb2t5m95tt3eb8mhf47xt41hl20hj7 google-site-verification=yVm1w9n5ppFWW3VguLK2txdxf5G0Jy4inZuFGe2G-Oo google-site-verification=t5bbskbdu89hkxsTpiKebrHAWx6daS4aOCcSNag8TyQ h1-domain-verification=ZvkpV1LBViSQioUYXwTUPE5Efvg9GbjXXn5TKr5QTVB9squv _3o72s6atk7aox491xy3thti3vvwyx2d _oq8p6bx93yr2obusb9ucoq6cj8fpe33 rippling-domain-verification=7a21d43ff76aea4b google-site-verification=QO2VI3zct25yarL1DpqNjlaXu85xM_SldDK_B8vXrYQ postman-domain-verification=8df76a5aff38310f28818da78362c52a5ae8b28874667992a7b1... _lnh6yg507z9v15gsg348kxzxc26fa03 _q5usuh8st474h63wztleo9evs7e7cf4 google-site-verification=HM17UgtbrZ6Zj5TMrNWhRuscZQ5ByOg9NQK6IGHorhQ _5ercgvne3pdr2pwj0rw7bp86g8fgkt3 apple-domain-verification=TtT64EdjSevURGEI anthropic-domain-verification-t6ndh1=dvjNyyxSoWPut1Euo0MpD8E3c google-site-verification=jkSkqzvPieJqcUz4s0tlezRavxOr3jlbQTL93p-zTdA google-site-verification=BmxV-t4S6PTeVBMe_L6oSllTHr9YKtwYs1pH1fLme_c liveramp-site-verification=4gxlliUYuCXNFLAHLVJLaLVWcysaewjXAd3qz0Imo04 did=did:plc:7sfnardo5xxznxc6esxc5ooe openai-domain-verification=dv-qBVN4qs3x0CUYU935au48PmR 37bdunamo2qbcgr5smugofj2pa docusign=a21b54f1-d564-4fb1-b30f-fc3a33bc6519 y+Yve/Gk3nXCvgVrzwtWkswd/e4v0vQZ5bwsriDDYRc7ScOg7STUzGWRMy7K+uRyEYDLV/LldJkS9OYn... _w4zc8ibxdst0qws82ezoutw94jzbuhg wpe-verification=nbaaccelerator google-site-verification=ET0wYvr0MMjgkvlL61hNMqL3Is9yMehxcBhLtCkKxSs _pqzcv8wc733sjkec0b2wws2he1w3kt7 new-relic-domain-verification=c8379c584c494cd39c6b8a73068d3079 logmein-verification-code=799098fd-6adc-4005-8cdc-7f11b30487b2 _bi3gm13looc07er007iuf571t5bmwov _w8mjjv2sy3hl9lhrd23sienu5tdakie _vz13cnfglsht3078nlafmkb9rimnnzk onetrust-domain-verification=a2a9ae99fd3049ffa7dee0ffa51157a9 atlassian-domain-verification=OUp7pnDpAcubpaWPL5SIaUTg9EvN71CFiy8BGLJgWZgrWjMG9h... |
| CAA | Lookup not available with standard resolver |
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
A+Multi-Resolver DNS SpeedMean 11ms across 3 resolvers (spread 19ms)PASS
ARedirect Chain1 redirect(s), 895 ms totalPASS
https://nba.com
105 ms · HTTP/1.1
https://www.nba.com/
790 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://nba.com | 301 | 105 ms | HTTP/1.1 | AkamaiGHost |
| 2 | https://www.nba.com/ | 200 | 790 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 25 URLsPASS
Sitemap: https://www.nba.com/sitemap_index.xml
User-Agent: *
Disallow: /amp/
Disallow: /api/*
Disallow: /mediacentral/*
Disallow: /search
Disallow: /video/partners/
Disallow: /stats/events/
Disallow: /suns/tickets/vervelounge_requests.html
Disallow: /blazers/node/
Disallow: /bobcats/node/
Disallow: /bucks/node/
Disallow: /bulls/node/
Disallow: /cavaliers/node/
Disallow: /celtics/node/
Disallow: /clippers/node/
Disallow: /grizzlies/node/
Disallow: /hawks/node/
Disallow: /heat/node/
Disallow: /jazz/node/
Disallow: /kings/node/
Disallow: /knicks/node/
Disallow: /lakers/node/
Disallow: /magic/node/
Disallow: /mavericks/node/
Disallow: /nets/node/
Disallow: /nuggets/node/
Disallow: /pacers/node/
Disallow: /pelicans/node/
Disallow: /pistons/node/
Disallow: /raptors/node/
Disallow: /rockets/node/
Disallow: /sixers/node/
Disallow: /spurs/node/
Disallow: /suns/node/
Disallow: /thunder/node/
Disallow: /timberwolves/node/
Disallow: /warriors/node/
Disallow: /wizards/node/
Disallow: /blazers/users/
Disallow: /bobcats/users/
Disallow: /bucks/users/
Disallow: /bulls/users/
Disallow: /cavaliers/users/
Disallow: /celtics/users/
Disallow: /clippers/users/
Disallow: /grizzlies/users/
Disallow: /hawks/users/
Disallow: /heat/users/
Disallow: /jazz/users/
Disallow: /kings/users/
Disallow: /knicks/users/
Disallow: /lakers/users/
Disallow: /magic/users/
Disallow: /mavericks/users/
Disallow: /nets/users/
Disallow: /nuggets/users/
Disallow: /pacers/users/
Disallow: /pelicans/users/
Disallow: /pistons/users/
Disallow: /raptors/users/
Disallow: /rockets/users/
Disallow: /sixers/users/
Disallow: /spurs/users/
Disallow: /suns/users/
Disallow: /thunder/users/
Disallow: /timberwolves/users/
Disallow: /warriors/users/
Disallow: /wizards/users/
User-agent: GPTBot
Disallow: /
Allow: /standings
Allow: /schedule
Allow: /stats/help/glossary
Allow: /stats/draft/history
Allow: /stats/help/statminimums
Allow: /stats/history
Allow: /players
Allow: /player/*profile$
Allow: /team/*
Disallow: /team/*/schedule$
User-agent: Google-Extended
Disallow: /
Allow: /standings
Allow: /schedule
Allow: /stats/help/glossary
Allow: /stats/draft/history
Allow: /stats/help/statminimums
Allow: /stats/history
Allow: /players
Allow: /player/*profile$
Allow: /team/*
Disallow: /team/*/schedule$
User-agent: Amazonbot
Disallow: /
User-agent: anthropic-ai
Disallow: /
User-agent: Applebot-Extended
Disallow: /
User-agent: CCBot
Disallow: /
User-agent: ChatGPT-User
Disallow: /
User-agent: ClaudeBot
Disallow: /
User-agent: Claude-Web
Disallow: /
User-agent: Google-Extended
Disallow: /
User-agent: GPTBot
Disallow: /
User-agent: OAI-SearchBot
Allow: /
User-agent: Quora-Bot
Disallow: /
User-agent: PerplexityBot
Disallow: /
- https://nba.com/sitemap_base.xml
- https://nba.com/sitemap_games_1.xml,site...
- https://nba.com/sitemap_players.xml
- https://nba.com/sitemap_teams.xml
- https://nba.com/sitemap_podcast_series.x...
- https://nba.com/
- https://nba.com/sitemap_nba_tv_list.xml
- https://nba.com/sitemap_stats_base.xml
- https://nba.com/sitemap_stats_players.xm...
- https://nba.com/sitemap_stats_teams.xml
- https://nba.com/sitemap_stats_help.xml
- https://nba.com/sitemap_stats_draft.xml
- https://nba.com/sitemap_stats_tools.xml
- https://nba.com/sitemap_stats_lineups.xm...
- https://nba.com/sitemap_static_watch_sec...
- https://nba.com/sitemap_team_schedule.xm...
- https://nba.com/sitemap_videos_2026_1.xm...
- https://nba.com/sitemap_news.xml
- https://nba.com/sitemap_hubs.xml
- https://nba.com/sitemap_fantasy.xml
- https://nba.com/sitemap_vr.xml
- https://nba.com/sitemap_nbabet.xml
- https://nba.com/sitemap_events.xml
- https://nba.com/sitemaps/sitemap_videos_...
- https://nba.com/sitemap_team_index.xml
A+Domain Intelligencenba.com — via GoDaddy Corporate Domains, LLC, 32 years, 2 months old, hosted on AkamaiPASS
101 days
November 27, 2026
68 days
Issued by Let's Encrypt
32 years, 2 months
Registered November 28, 1994
Not enabled
Protects against DNS spoofing
Akamai
ASN AS20940
95.101.239.178
GoDaddy Corporate Domains, LLC
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice