Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations63 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 58 ms lookupPASS
| A | 104.19.144.18, 104.19.255.17 |
| AAAA | 2606:4700::6813:9012, 2606:4700::6813:ff11 |
| CNAME | — |
| NS | jim.ns.cloudflare.com, karina.ns.cloudflare.com |
| MX | 0 familyhandyman-com.mail.protection.outlook.com |
| TXT | facebook-domain-verification=i2dqc6a18fl5tl1fa572fyxsdhlfzo MS=ms57535574 tollbit-domain-verification=f4ba329119ca024f96c3e64292a6a8dbb0c1763346408a0ae3ca... apple-domain-verification=olzhRR5rg2d2UNYW49LFHHu6GT8uOotGRaAyKY9dccU SPF v=spf1 ip4:209.206.126.0/24 include:spf.protection.outlook.com include:spf.autop... google-site-verification=RZEOnk0fDs193QTtv4L9WGeaZfJQFKl0DIonZzsqNnw |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 172 ms totalPASS
https://familyhandyman.com
58 ms · HTTP/1.1
https://www.familyhandyman.com/
114 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://familyhandyman.com | 301 | 58 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.familyhandyman.com/ | 200 | 114 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (16 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 14 URLsPASS
# This virtual robots.txt file was created by the Virtual Robots.txt WordPress plugin: https://www.wordpress.org/plugins/pc-robotstxt/
# www.familyhandyman.com robots.txt -- just crawl it.
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
# Block unwanted URL parameters
Disallow: /*?customize_changeset_uuid=
Disallow: /*?s=
Disallow: /*?_
Disallow: /*?page=
Disallow: /*?pmcode=
Disallow: /*?kclt=
Disallow: */?trkid=
Disallow: */?sort=
# Block Embed, PDF, and Reprint Sections
Disallow: */trackback/
Disallow: */comments/feed/
Disallow: */embed/
Disallow: */cgi-bin/
Disallow: */search/
# Specific bot directives
User-agent: AhrefsBot
Crawl-delay: 10
User-agent: Pinterestbot
Crawl-delay: 10
# Sitemap location
Sitemap: https://www.familyhandyman.com/sitemap_index.xml
- https://www.familyhandyman.com/post-site...
- https://www.familyhandyman.com/post-site...
- https://www.familyhandyman.com/post-site...
- https://www.familyhandyman.com/post-site...
- https://www.familyhandyman.com/post-site...
- https://www.familyhandyman.com/page-site...
- https://www.familyhandyman.com/listicle-...
- https://www.familyhandyman.com/listicle-...
- https://www.familyhandyman.com/listicle-...
- https://www.familyhandyman.com/listicle-...
- https://www.familyhandyman.com/project-s...
- https://www.familyhandyman.com/project-s...
- https://www.familyhandyman.com/categorie...
- https://www.familyhandyman.com/author-si...
A+Domain Intelligencefamilyhandyman.com — via MarkMonitor Inc., 30 years, 6 months oldPASS
636 days
March 13, 2028
63 days
Issued by Google Trust Services
30 years, 6 months
Registered March 12, 1996
Enabled
Protects against DNS spoofing
Unknown
2606:4700::6813:9012
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice