Skip to content
https://nba.com

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
87
GRADE
B
FIX
0
REVIEW
10
PASS
7
INFO
0
Probed from Madrid, Spain
301 Moved Permanently
Checks
17
7 PASS 10 REVIEW
B
DNSSEC
Unsigned (DNSSEC not deployed)
REVIEW
Unsigned (DNSSEC not deployed)
Info::
DNSSEC is not deployed
The zone is not DNSSEC-signed. Users on validating resolvers (Cloudflare 1.1.1.1, Quad9 9.9.9.9, growing default in mobile resolvers) get no protection against DNS spoofing for this domain. Most registrars now offer DNSSEC at a single click; consider enabling it for sites where authenticity matters (banking, healthcare, government).
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
B
Reverse DNS
0/2 IPs match cert SAN
REVIEW
0/2 IPs match cert SAN
Info::
PTR for 95.101.239.176 does not match any cert SAN: a95-101-239-176.deploy.static.akamaitechnologies.com
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
Info::
PTR for 95.101.239.178 does not match any cert SAN: a95-101-239-178.deploy.static.akamaitechnologies.com
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
REVIEW
www/non-www, trailing slash, HTTP→HTTPS
Critical::
Both www and non-www versions serve content
Got: Both variants return 200 Expected: One variant 301-redirects to the other
Info::
HTTP correctly 301-redirects to HTTPS

www / non-www

200https://www.nba.com/
200https://nba.com/

Inconsistent — duplicate content risk

HTTP → HTTPS

301http://nba.com/ https://www.nba.com/

Consistent

B
TLS Certificate Expiry & Recommendations
68 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

68
days left
0d 30d 60d 90d+

Recommended actions

  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
CDN & Delivery
Akamai
REVIEW
Akamai
Info::
Site is served via Akamai CDN
Got: server header
CDN Detected: Akamai
Provider Akamai Evidence server header
B
CDN Cache Observability
No CDN cache-status headers in the response
REVIEW
No CDN cache-status headers in the response
Info::
No CDN cache-status headers in the response
Without an X-Cache / CF-Cache-Status / X-Vercel-Cache / Age header, you can't tell from outside whether a request hit the cache or went to origin. Operationally important: enables debugging stale-content reports and verifying cache rules. Most managed CDN platforms emit at least one of these by default; absence often means the platform's diagnostic headers are stripped at an upstream proxy.
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: 404, /health: 404, /healthz: 404, /ping: 404, /status: 404.
A+
DNS Records
2 A records, 85 ms lookup
PASS
2 A records, 85 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 95.101.239.176, 95.101.239.178
Info::
No IPv6 (AAAA) records
Info::
6 nameserver(s) configured
Got: a18-65.akam.net, a1-148.akam.net, a7-67.akam.net, a5-65.akam.net, a16-64.akam.net, a12-65.akam.net
Info::
4 mail exchanger(s) configured
Info::
SPF record present in TXT
Info::
DNS resolution time: 85 ms
Got: 85 ms
A95.101.239.176, 95.101.239.178
AAAA
CNAME
NSa18-65.akam.net, a1-148.akam.net, a7-67.akam.net, a5-65.akam.net, a16-64.akam.net, a12-65.akam.net
MX
5 mx0a-001bf601.pphosted.com
5 mx0b-001bf601.pphosted.com
10 mxa-001bf601.gslb.pphosted.com
10 mxb-001bf601.gslb.pphosted.com
TXT
SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ip4:192.28.146.104/32 ip4:19...
mongodb-site-verification=zXIY4xiw9vi8xOfOumgTLDfyZ3ofk2kw
_globalsign-domain-verification=wjJQ2UYQWEucub5NGv5OMV6P-bfXLvizwll_LtWtX3
docusign=6e2b1ec8-2f66-4b8a-bff9-cc3105fa5bb8
browserstack-domain-verification=e7301008-4155-48e6-96d1-f7fa80e52fd6
_q88qawgh3excaogrbf7cvdo28sdj8ia
_gf5mv6eyzlltwqrtgaf9igb20s9pfog
wiz-domain-verification=ebdf2f09c916f026894642180ace4049ad64e78d1685ab758f06d22c...
docusign=f2d64448-94de-44d3-8ce5-353d05819274
MS=ms15146138
facebook-domain-verification=79esg7n82tq8cwyisaodmgi937dpc9
google-site-verification=WnK3OGXPzf93OkYzb0r4cFg0BMyZXVj0Izffi_B1gx0
bw=he4iBLkEPDGY87gvTNe9FHBeuNSH6ycXVm7DixE38g4e
_sfjr2erc8z2p0k2t78gs5ezf9ccayry
extensis-domain-verification=8cbb3e08-38d3-43e5-a26c-ecbe23bc6b5b
_xfzrbmhxie7kv8g3796d6o5h3xx5kg3
_vkmqqqs37b6mzfk4hbi9xz53iyw9m43
_ucivhm2v0cbs1lur7t629qv8azj2mf8
ZOOM_verify_EypkM8mdTIGAzMaaU6FQqQ
d365mktkey=5jwvpf0sq2hnxck74g4j2bvir
_y699lsz03iab1tidvv19skei417xune
_globalsign-domain-verification=XFIuRTkNngLrU5i-shLulkoMIEi0_Zt4oDrwX2jY6T
_3hb2t5m95tt3eb8mhf47xt41hl20hj7
google-site-verification=yVm1w9n5ppFWW3VguLK2txdxf5G0Jy4inZuFGe2G-Oo
google-site-verification=t5bbskbdu89hkxsTpiKebrHAWx6daS4aOCcSNag8TyQ
h1-domain-verification=ZvkpV1LBViSQioUYXwTUPE5Efvg9GbjXXn5TKr5QTVB9squv
_3o72s6atk7aox491xy3thti3vvwyx2d
_oq8p6bx93yr2obusb9ucoq6cj8fpe33
rippling-domain-verification=7a21d43ff76aea4b
google-site-verification=QO2VI3zct25yarL1DpqNjlaXu85xM_SldDK_B8vXrYQ
postman-domain-verification=8df76a5aff38310f28818da78362c52a5ae8b28874667992a7b1...
_lnh6yg507z9v15gsg348kxzxc26fa03
_q5usuh8st474h63wztleo9evs7e7cf4
google-site-verification=HM17UgtbrZ6Zj5TMrNWhRuscZQ5ByOg9NQK6IGHorhQ
_5ercgvne3pdr2pwj0rw7bp86g8fgkt3
apple-domain-verification=TtT64EdjSevURGEI
anthropic-domain-verification-t6ndh1=dvjNyyxSoWPut1Euo0MpD8E3c
google-site-verification=jkSkqzvPieJqcUz4s0tlezRavxOr3jlbQTL93p-zTdA
google-site-verification=BmxV-t4S6PTeVBMe_L6oSllTHr9YKtwYs1pH1fLme_c
liveramp-site-verification=4gxlliUYuCXNFLAHLVJLaLVWcysaewjXAd3qz0Imo04
did=did:plc:7sfnardo5xxznxc6esxc5ooe
openai-domain-verification=dv-qBVN4qs3x0CUYU935au48PmR
37bdunamo2qbcgr5smugofj2pa
docusign=a21b54f1-d564-4fb1-b30f-fc3a33bc6519
y+Yve/Gk3nXCvgVrzwtWkswd/e4v0vQZ5bwsriDDYRc7ScOg7STUzGWRMy7K+uRyEYDLV/LldJkS9OYn...
_w4zc8ibxdst0qws82ezoutw94jzbuhg
wpe-verification=nbaaccelerator
google-site-verification=ET0wYvr0MMjgkvlL61hNMqL3Is9yMehxcBhLtCkKxSs
_pqzcv8wc733sjkec0b2wws2he1w3kt7
new-relic-domain-verification=c8379c584c494cd39c6b8a73068d3079
logmein-verification-code=799098fd-6adc-4005-8cdc-7f11b30487b2
_bi3gm13looc07er007iuf571t5bmwov
_w8mjjv2sy3hl9lhrd23sienu5tdakie
_vz13cnfglsht3078nlafmkb9rimnnzk
onetrust-domain-verification=a2a9ae99fd3049ffa7dee0ffa51157a9
atlassian-domain-verification=OUp7pnDpAcubpaWPL5SIaUTg9EvN71CFiy8BGLJgWZgrWjMG9h...
CAALookup not available with standard resolver
Resolved in 85 ms
A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
Multi-Resolver DNS Speed
Mean 11ms across 3 resolvers (spread 19ms)
PASS
Mean 11ms across 3 resolvers (spread 19ms)
Info::
Quad9: 0ms
Got: 0ms via 9.9.9.9:53
Info::
Google: 16ms
Got: 16ms via 8.8.8.8:53
Info::
Cloudflare: 19ms
Got: 19ms via 1.1.1.1:53
A
Redirect Chain
1 redirect(s), 895 ms total
PASS
1 redirect(s), 895 ms total
Info::
Single redirect
Got: https://nba.com → https://www.nba.com/ (301)
Info::
WWW normalization redirect
Info::
Redirect overhead: 895 ms total
Got: 895 ms

https://nba.com

105 ms · HTTP/1.1

301

https://www.nba.com/

790 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://nba.com301105 msHTTP/1.1AkamaiGHost
2https://www.nba.com/200790 msHTTP/1.1

See the visual redirect chain in the HTTP Probe tab →

A+
Crawlability
robots.txt present, sitemap with 25 URLs
PASS
robots.txt present, sitemap with 25 URLs
Info::
robots.txt is present
Got: 2715 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 25 entries
Info::
Sitemap index with 25 child sitemaps
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 2715 B Sitemaps referenced 1 User-agents Quora-Bot, PerplexityBot, Google-Extended, anthropic-ai, ClaudeBot, Claude-Web, OAI-SearchBot, *, GPTBot, Amazonbot, Applebot-Extended, CCBot, ChatGPT-User Blocking No — crawling allowed
Sitemap: https://www.nba.com/sitemap_index.xml

User-Agent: *
Disallow: /amp/
Disallow: /api/*
Disallow: /mediacentral/*
Disallow: /search
Disallow: /video/partners/
Disallow: /stats/events/ 
Disallow: /suns/tickets/vervelounge_requests.html
Disallow: /blazers/node/
Disallow: /bobcats/node/
Disallow: /bucks/node/
Disallow: /bulls/node/
Disallow: /cavaliers/node/
Disallow: /celtics/node/
Disallow: /clippers/node/
Disallow: /grizzlies/node/
Disallow: /hawks/node/
Disallow: /heat/node/
Disallow: /jazz/node/
Disallow: /kings/node/
Disallow: /knicks/node/
Disallow: /lakers/node/
Disallow: /magic/node/
Disallow: /mavericks/node/
Disallow: /nets/node/
Disallow: /nuggets/node/
Disallow: /pacers/node/
Disallow: /pelicans/node/
Disallow: /pistons/node/
Disallow: /raptors/node/
Disallow: /rockets/node/
Disallow: /sixers/node/
Disallow: /spurs/node/
Disallow: /suns/node/
Disallow: /thunder/node/
Disallow: /timberwolves/node/
Disallow: /warriors/node/
Disallow: /wizards/node/
Disallow: /blazers/users/
Disallow: /bobcats/users/
Disallow: /bucks/users/
Disallow: /bulls/users/
Disallow: /cavaliers/users/
Disallow: /celtics/users/
Disallow: /clippers/users/
Disallow: /grizzlies/users/
Disallow: /hawks/users/
Disallow: /heat/users/
Disallow: /jazz/users/
Disallow: /kings/users/
Disallow: /knicks/users/
Disallow: /lakers/users/
Disallow: /magic/users/
Disallow: /mavericks/users/
Disallow: /nets/users/
Disallow: /nuggets/users/
Disallow: /pacers/users/
Disallow: /pelicans/users/
Disallow: /pistons/users/
Disallow: /raptors/users/
Disallow: /rockets/users/
Disallow: /sixers/users/
Disallow: /spurs/users/
Disallow: /suns/users/
Disallow: /thunder/users/
Disallow: /timberwolves/users/
Disallow: /warriors/users/
Disallow: /wizards/users/

User-agent: GPTBot
Disallow: /
Allow: /standings
Allow: /schedule
Allow: /stats/help/glossary
Allow: /stats/draft/history
Allow: /stats/help/statminimums
Allow: /stats/history
Allow: /players
Allow: /player/*profile$
Allow: /team/*
Disallow: /team/*/schedule$

User-agent: Google-Extended
Disallow: /
Allow: /standings
Allow: /schedule
Allow: /stats/help/glossary
Allow: /stats/draft/history
Allow: /stats/help/statminimums
Allow: /stats/history
Allow: /players
Allow: /player/*profile$
Allow: /team/*
Disallow: /team/*/schedule$

User-agent: Amazonbot
Disallow: /

User-agent: anthropic-ai
Disallow: /

User-agent: Applebot-Extended
Disallow: /

User-agent: CCBot
Disallow: /

User-agent: ChatGPT-User
Disallow: /

User-agent: ClaudeBot
Disallow: /

User-agent: Claude-Web
Disallow: /

User-agent: Google-Extended
Disallow: /

User-agent: GPTBot
Disallow: /

User-agent: OAI-SearchBot
Allow: /

User-agent: Quora-Bot
Disallow: /

User-agent: PerplexityBot
Disallow: /

A+
Domain Intelligence
nba.com — via GoDaddy Corporate Domains, LLC, 32 years, 2 months old, hosted on Akamai
PASS
nba.com — via GoDaddy Corporate Domains, LLC, 32 years, 2 months old, hosted on Akamai
Info::
Domain registered until Nov 27, 2026 (3 months remaining)
Info::
DNSSEC is not enabled
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Info::
Registrar: GoDaddy Corporate Domains, LLC
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Info::
Hosting: Akamai
Got: AS20940
Domain expiry

101 days

November 27, 2026

SSL certificate

68 days

Issued by Let's Encrypt

Domain age

32 years, 2 months

Registered November 28, 1994

DNSSEC

Not enabled

Protects against DNS spoofing

Hosting

Akamai

ASN AS20940

95.101.239.178

Registrar

GoDaddy Corporate Domains, LLC

Unlocked 6 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Enable DNSSEC to protect visitors from DNS spoofing
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar GoDaddy Corporate Domains, LLC
Created November 28, 1994 (32 years, 2 months ago)
Expires November 27, 2026 (3 months)
Last Updated October 28, 2025
Name Servers a1-148.akam.net, a12-65.akam.net, a16-64.akam.net, a18-65.akam.net, a5-65.akam.net, a7-67.akam.net
DNSSEC Not enabled
Hosting
IP Address 95.101.239.178
ASN AS20940 (AKAMAI-ASN1 - Akamai International B.V., NL)
Provider Akamai
Data source: rdap (0.3s)

DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.

Why this matters

Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.

Learn more

DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.

Source: ICANN / RFC 4033

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A+
HTTP Probe Timing
Total 134 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
31 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
25 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
52 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
135 ms
Total Time Total request time from DNS lookup through full response.
135 ms

Connection waterfall

DNS Lookup 31 ms TCP Connect 25 ms TLS Handshake 52 ms Server Processing 27 ms Content Transfer 0 ms
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback