Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations56 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records3 A records, 53 ms lookupPASS
| A | 104.26.4.17, 172.67.73.94, 104.26.5.17 |
| AAAA | 2606:4700:20::ac43:495e, 2606:4700:20::681a:411, 2606:4700:20::681a:511 |
| CNAME | — |
| NS | max.ns.cloudflare.com, sima.ns.cloudflare.com |
| MX | 1 buzzsumo-com.mail.protection.outlook.com |
| TXT | SPF v=spf1 include:spf.mtasv.net include:spf.mailjet.com include:_spf.google.com inc... google-site-verification=OgAJZUogUA-rjQNqE5m0uNd3tGE_6Rf0Cm0ylla4TE4 google-site-verification=F_0XAnBv9MR0nSaSZ3v2vctyyTmXGnF3GmzZetd8uAw MS=ms38609505 box-domain-verification=d0369ff4a0618ff19f1d7f9c98c9bb65203e8a33febfc79cf2df6db7... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://buzzsumo.com
364 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://buzzsumo.com | 200 | 364 ms | HTTP/1.1 | cloudflare |
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 18 URLsPASS
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Sitemap: https://buzzsumo.com/wp-sitemap.xml
- https://buzzsumo.com/wp-sitemap-posts-po...
- https://buzzsumo.com/wp-sitemap-posts-pa...
- https://buzzsumo.com/wp-sitemap-posts-pr...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-posts-le...
- https://buzzsumo.com/wp-sitemap-posts-bu...
- https://buzzsumo.com/wp-sitemap-posts-bu...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-posts-bw...
- https://buzzsumo.com/wp-sitemap-taxonomi...
- https://buzzsumo.com/wp-sitemap-taxonomi...
- https://buzzsumo.com/wp-sitemap-taxonomi...
- https://buzzsumo.com/wp-sitemap-taxonomi...
- https://buzzsumo.com/wp-sitemap-users-1....
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencebuzzsumo.com — via NameCheap, Inc., 13 years, 9 months oldPASS
458 days
September 17, 2027
56 days
Issued by Google Trust Services
13 years, 9 months
Registered September 17, 2012
Enabled
Protects against DNS spoofing
Unknown
2606:4700:20::ac43:495e
NameCheap, Inc.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice