Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations74 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records1 A records, 616 ms lookupPASS
| A | 212.1.41.48 |
| AAAA | — |
| CNAME | — |
| NS | ns2.mcs.de, ns3.mcs.de |
| MX | 100 mailin.hamburg.de 500 secondary.snafu.de |
| TXT | MS=ms37320466 294q3hq87uhsg7e0h17qg771c8 2mklf3t8anqddu8qe494ho9bg9 5r8urhbo615k9pob82m7bpk4b6 6p7dabu56slbs06mb2unn788te 99bo6iaj9nuagt5trghih29n78 adg0r6mhqbpv5b6b78lbk1ioog kr9c8mf89rj8afkm7rm8bijn7b nrnkonq5t5n9g7d0gtbqb7dsp8 o3tkef433rk3lg5m201lggshje ol048kjcm2icev1c51bmb9j90f q8eea6qhetq66ktvvu6dnijpri qe868hnim5959t79mnbeb5mhot qh5prgird2vl0bvvvlo9d1rf7g ric4bckvddukt7eqj7s4jb4pno udho6a3qg2m0tqvddgv3olj0mi usvvg34tqfav7jn2aiio9iaq9f D-TRUST=8E8LFBB46ZWI5VMLHWZWUZU D-TRUST=MHU66NWG8ULBY8B3IZ924LJ D-TRUST=TOSMUZSTDBR2KW2S75QHH2M D-TRUST=XGPMOBZM4O36WNPWKJTTM5Z D-TRUST=Z736N3U6B5I5K34VIO6N84U 4fnb4j86fsx1sy3w004xndxwgxfh0bbs bpnn5dflvlxccf2m8knk2qmp59kfr11p rd36v0r68cdk8t0l4rqxdfzc4vg8hf74 v9vlxl11q0d6l92j94d3r6qmtfv8v37w yh6tg246yms2lx41vg5ykfxhj882hb00 2a02:0ad0:0005:0001:0000:0000:0000:0048 QuoVadis=a16628a6-f26c-45ce-950a-4efee9bfab51 QuoVadis=e4cbdf1c-5183-4575-9299-4c597c9c87a2 facebook-domain-verification=dbvfs33q2zqzmz0t1lbetroho42w18 60f457201b3a7fe3a264b128806fc0669f27b9e4e38b1551f5e77a2780d8eaa a3e56c36e1d03ab670fd5a2d159b923d5489b9dba1e5345b9864144b25ab43e d4d27193627d903bca751564b1e01f121c4b1dd7f5efd191c4f09d0a1d8b55a dc967a15cbb90adf50e95ee7dae314a2eb8b66b43aa37a6fb0d6b0163c1f962c google-site-verification=4p9NvfZP0G0flDsOL3o8yAG5bGlJFMUcei9vXhStCNs google-site-verification=fvaBhWKb4vZCpIGZn6uHvS_kDSq3z9Tgvjaeo-ff_eM google-site-verification=hICfXqejK99RNrokpX8ea856f-TpYzhk48EzRcz_hlE google-site-verification=lGviib_hPjRn3NTEXdltsnuPAV0zMPKsUMe_pXqMM-s google-site-verification=oMK33F30yMPQUmiY9wD_w3x2sV2QJYd3dXP7faTAnuI google-site-verification=v61mUVK37pK7laptUAa0wW_5xrbP6rVXyIfYgd9WYbI google-site-verification=xKTAJC4VHl1maRK_6JrzQsyRDYhbHJoR0PlMIHYPNco _globalsign-domain-verification=NvAZB6HgqdotR8d-Bd9PuXQrXKcgSy_pkufMHA5L8f _telesec-domain-validation=2019-10-17_EsWjLFKa2XbjSAS1ix2xprx6iSmXoRqF8j3F6gr5i6... SPF v=spf1 include:_spf1.snafu.de include:_spf2.snafu.de include:dataport.de include... |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
ARedirect Chain1 redirect(s), 949 ms totalPASS
https://hamburg.de
425 ms · HTTP/1.1
https://www.hamburg.de/
524 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://hamburg.de | 301 | 425 ms | HTTP/1.1 | Apache |
| 2 | https://www.hamburg.de/ | 200 | 524 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
ACrawlabilityrobots.txt present, no sitemapPASS
A sitemap helps search engines discover and index your pages more efficiently.
No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.
Learn more ▾ ▴
A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.
Source: sitemaps.org / Google Search Central
User-agent: *
Disallow: /branchenbuch/*/*/ln0/
Disallow: /branchenbuch/*/*/*/ln0/
Disallow: /iason/hamburg/
Disallow: /iason/search
Disallow: /iason/search
Disallow: /iason/widget
Disallow: /iason/listing/
Disallow: /befi/$
Disallow: /befi/?$
Disallow: /befi/hamburg/
Disallow: /befi/widget
Disallow: /premiumpartner/
Disallow: /625042!search
Disallow: /search
Disallow: /newsletter
User-agent: hyscore
Disallow:/
User-agent: Teleport
Disallow:/
User-agent: Webwhacker
Disallow:/
User-agent: Webzip
Disallow:/
User-agent: Net Attache
Disallow:/
User-agent: SiteSnagger
Disallow:/
User-agent: HTTrack
Disallow:/
User-agent: WebCapture
Disallow:/
User-agent: WebSauger
Disallow:/
User-agent: proximic
Disallow:/
User-agent: PetalBot
Disallow:/
User-agent: 008
Disallow:/
User-agent: sogou spider
Disallow:/
User-agent: Baiduspider
Disallow:/
User-agent: AhrefsBot
Disallow:/
User-agent: SemrushBot-SA
Disallow:/
User-agent: Flamingo_SearchEngine
Disallow:/
User-agent: msnbot-media/1.1
Disallow:/
User-agent: msnbot-media/2.0b
Disallow:/
User-agent: scrapy
Disallow:/
User-agent: Diffbot
Disallow:/
User-agent: RyteBot
Disallow:/
User-agent: backlink-check.de
Disallow:/
User-agent: BacklinkCrawler
Disallow:/
User-agent: ExtractorPro
Disallow:/
User-agent: Fasterfox
Disallow:/
User-agent: LinkextractorPro
Disallow:/
User-agent: LinkWalker
Disallow:/
User-agent: MJ12bot
Disallow:/
User-agent: Openbot
Disallow:/
User-agent: rogerbot
Disallow:/
User-agent: searchpreview
Disallow:/
User-agent: SemrushBot
Disallow:/
User-agent: SEODAT
Disallow:/
User-agent: SEOENGBot
Disallow:/
User-agent: SEOkicks-Robot
Disallow:/
User-agent: True_Robot
Disallow:/
User-agent: URL Control
Disallow:/
User-agent: URL_Spider_Pro
Disallow:/
User-agent: xovi
Disallow:/
User-agent: um-IC
Disallow:/
Sitemap: https://www.hamburg.de/service-sitemap-hamburg.de-sitemap_index.xml
Sitemap: https://www.hamburg.com/service-sitemap-hamburg.com-sitemap_index.xml
No sitemap found
Adding a sitemap helps search engines discover your pages.
A+Domain Intelligencehamburg.de — hosted on PLUSSERVER-ASN1, DEPASS
Unknown
74 days
Issued by Let's Encrypt
Unknown
Status unknown
Protects against DNS spoofing
PLUSSERVER-ASN1, DE
ASN AS61157
212.1.41.48
Registrar unknown
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice