Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations157 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 88 ms lookupPASS
| A | 172.200.168.128 |
| AAAA | — |
| CNAME | — |
| NS | ns1.markmonitor.com, ns3.markmonitor.com, ns7.markmonitor.com, ns2.markmonitor.com, ns4.markmonitor.com, ns6.markmonitor.com, ns5.markmonitor.com |
| MX | 0 eltiempo-com.mail.protection.outlook.com |
| TXT | google-site-verification=dZosqvJOGTK2rwCxUKOZC-dWN2VpsYSLbiOG4vjdLjQ globalsign-domain-verification=1b85dcacab19819bdf886e8bb49858fc globalsign-domain-verification=7E53EF2A1874A035DF8E78FA4BD24C83 google-site-verification=sZq4EDJnnsXxXpOTwqwzurtn1DdhL8S3J_MFP9DLRvk globalsign-domain-verification=eedc5407ad148e1c78388eeb72f10e6f google-site-verification=2cDa3IwBMrcFN5ZT8lHjaynzs0GIDdk6H1svuV5I35g kjtp2hq303vxrtv1hyb9npmxxgfj2w5v G0R6U58509 _ewefzgaebkgy817d3k1uvsf9veo7k6t SPF v=spf1 ip4:179.1.6.50 ip4:201.245.163.100 ip4:136.147.180.192 ip4:136.147.180.19... google-site-verification=jeqs94WRI0ScIH4q1zexn4YL17BnAGD8PfEWu0HKCVk globalsign-domain-verification=b4eaf354ea54c16d2bebb649860e597b ciscocidomainverification=1ba1e0741ce906cfadc8fceec8e6051c21ac2820fba2d22832e53a... google-site-verification=T62uD82kfTXrVNUV8PtsW8RN9i_GA5c9wduW1n8NijU _cbjxlov0gc1772c8sb41n8esl0mh4fo globalsign-domain-verification=0FA40A616CDC65EFD4DDEF204F8A09B3 _brba4jixivfylg4sdpzuj7cytle7sti google-site-verification=t3Wu06h60pJ9aZtawxlq38ZNc-nfB-cCZ8TcRnzrumo adobe-idp-site-verification=129c6d29-6007-4459-bfbc-eff1fd4d1007 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 392 ms totalPASS
https://eltiempo.com
304 ms · HTTP/1.1
https://www.eltiempo.com/
88 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://eltiempo.com | 301 | 304 ms | HTTP/1.1 | Microsoft-Azure-Application-Gateway/v2 |
| 2 | https://www.eltiempo.com/ | 200 | 88 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 208 URLsPASS
# Specific robot directives / Directivas específicas para robots:
# Casa Editorial El Tiempo content is made available under our terms and conditions; for personal, non-commercial use / El contenido de Casa Editorial El Tiempo está disponible bajo nuestros términos y condiciones; para uso personal, no comercial;
# To our Terms of Service here: https://www.eltiempo.com/terminos-condiciones/ / Consultar nuestros Términos y Condiciones de Servicio aquí: https://www.eltiempo.com/terminos-condicioneshttps://www.eltiempo.com/terminos-condiciones/
# Use of any device, tool, or process designed to data mine or scrape the content, using automated means, it is prohibited without prior written permission from Casa Editorial El Tiempo / El uso de cualquier dispositivo, herramienta o proceso diseñado para extraer datos o raspar el contenido, utilizando medios automatizados, está prohibido sin el permiso previo por escrito de Casa Editorial El Tiempo.
# Prohibited uses include but are not limited to: / Los usos prohibidos del contenido incluyen, entre otros:
# (1) text and data mining activities; / (1) actividades de minería de textos y datos;
# (2) the development of any software, machine learning, artificial intelligence (AI), and/or large language models (LLMs); / (2) el desarrollo de cualquier software, aprendizaje automático, inteligencia artificial (IA) y/o grandes modelos de lenguaje (LLM);
# (3) creating or providing archived or cached data sets containing our content to others; and/or / (3) crear o proporcionar conjuntos de datos archivados o en caché que contengan nuestro contenido a otros; y/o
# (4) any commercial purposes / (4) cualquier propósito comercial.
# Contact for assistance: notificaciones@eltiempo.com / Contacto para asistencia: notificaciones@eltiempo.com
User-Agent: *
Disallow: /media/
Disallow: /colombia/notasfantasmas/
Disallow: /buscador/
Disallow: /especiales-td/
Disallow: /buscar/
Disallow: /search-results/
Disallow: /buscar?
Disallow: /articulo-recomendados/
Disallow: /track/
Disallow: /dictum/
Disallow: /club-vivamos/
Disallow: /files/
Disallow: /uploads/
Disallow: /custom-listing-tag/
Disallow: /get-ads-by-id/
Disallow: /javascripts/
User-agent: sitecheck.internetseer.com
Disallow: /
User-agent: Zealbot
Disallow: /
User-agent: MSIECrawler
Disallow: /
User-agent: SiteSnagger
Disallow: /
User-agent: WebStripper
Disallow: /
User-agent: WebCopier
Disallow: /
User-agent: Fetch
Disallow: /
User-agent: Offline Explorer
Disallow: /
User-agent: Teleport
Disallow: /
User-agent: TeleportPro
Disallow: /
User-agent: WebZIP
Disallow: /
User-agent: linko
Disallow: /
User-agent: HTTrack
Disallow: /
User-agent: Microsoft.URL.Control
Disallow: /
User-agent: Xenu
Disallow: /
User-agent: larbin
Disallow: /
User-agent: libwww
Disallow: /
User-agent: ZyBORG
Disallow: /
User-agent: Download Ninja
Disallow: /
User-agent: UbiCrawler
Disallow: /
User-agent: DOC
Disallow: /
User-agent: Zao
Disallow: /
User-agent: Slurp
Disallow: /
User-agent: Maxthon
Disallow: /
User-agent: CNCDialer
Disallow: /
User-agent: newsproxy.app
Disallow: /
User-agent: CCBot
Disallow: /
User-agent: ChatGPT-User
Disallow: /
User-agent: ClaudeBot
Disallow: /
User-agent: Claude-Web
Disallow: /
User-agent: cohere-ai
Disallow: /
User-agent: GPTBot
Disallow: /
User-agent: anthropic-ai
Disallow: /
#sitemaps
Sitemap: https://www.eltiempo.com/sitemap-default.xml
Sitemap: https://www.eltiempo.com/sitemap-index.xml
Sitemap: https://www.eltiempo.com/sitemap-google-news.xml
Sitemap: https://www.eltiempo.com/sitemap-articles-current.xml
Sitemap: https://www.eltiempo.com/sitemap-images-index.xml
Sitemap: https://www.eltiempo.com/sitemap-videos-index.xml
Sitemap: https://www.eltiempo.com/rss-news/eltiempo.xml
Sitemap: https://www.eltiempo.com/rss/eltiempo.xml
Sitemap: https://www.eltiempo.com/showcase-feed
User-agent: PerplexityBot
Disallow: /
User-agent: TurnitinBot
Disallow: /
User-agent: magpie-crawler
Disallow: /
User-agent: omgili
Disallow: /
User-agent: omgilibot
Disallow: /
User-agent: DataForSeoBot
Disallow: /
User-agent: Diffbot
Disallow: /
User-agent: news-please
Disallow: /
User-agent: AwarioRssBot
Disallow: /
User-agent: AwarioSmartBot
Disallow: /
User-agent: Bytespider
Disallow: /
User-agent: FacebookBot
Disallow: /
User-agent: Meta-ExternalAgent
Disallow: /
User-agent: Meta-ExternalFetcher
Disallow: /
User-agent: Meta-WebIndexer
Disallow: /
User-agent: ChatGPT Agent
Disallow: /
- https://www.eltiempo.com/bogota/metro-de-bogota
- https://www.eltiempo.com/politica/elecciones-colombia-2026/frente-por-la-vida
- https://www.eltiempo.com/politica/elecciones-colombia-2026/consulta-de-las-soluciones
- https://www.eltiempo.com/politica/elecciones-colombia-2026/gran-consulta-por-colombia
- https://www.eltiempo.com/politica/elecciones-colombia-2026/senado-y-camara
A+Domain Intelligenceeltiempo.com — via MarkMonitor Inc., 30 years, 11 months old, hosted on Microsoft AzurePASS
116 days
October 10, 2026
157 days
Issued by DigiCert Inc
30 years, 11 months
Registered October 11, 1995
Not enabled
Protects against DNS spoofing
Microsoft Azure
ASN AS8075
172.200.168.128
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice