Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FHTTP Probe TimingActionTotal 3743 ms — DNS, TCP, TLS, TTFB, content transfer breakdownFIX
Connection waterfall
BTLS Certificate Expiry & Recommendations33 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 75 ms lookupPASS
| A | 23.185.0.4 |
| AAAA | 2620:12a:8000::4, 2620:12a:8001::4 |
| CNAME | — |
| NS | ha4.markmonitor.zone, ha2.markmonitor.zone, ha1.markmonitor.zone, ha3.markmonitor.zone |
| MX | 10 clarivate-com.mail.protection.outlook.com |
| TXT | amazonses:1bLBKSw4584VyJdd5h2uiKkvvEmuF047SBRAjYIg3mE= teamviewer-sso-verification=ba91dc85b0d44acb8fa9a9ea65bf6095 perplexity-ai-domain-verification-c2e37s=MMyxfVtTtH7pbdH37CqcxgwKa cisco-ci-domain-verification=7ceedc27f7e17c304ac4ee7b55ddfa017f7dd1d85fff2d1392d... pendo-domain-verification=faef4c26-f782-4dc9-a4e1-71d674bd21d3 stripe-verification=58d530ef1573b7b50870afa24c189eaaa1f895fefbf18f83cd462a3f6f12... atlassian-sending-domain-verification=5514f907-5cfb-458a-86e3-59dfc3e61b01 prod-ipms-virg-mail-relay onetrust-domain-verification=bca3201946e947d59354afbaf0a2a1ee wrike-verification=MTg4ODY4OmFkYjBlYWIyNmFjNmQ3OGNjMzc4NTUyNjhkNjcxMTQyM2NjZmU1M... google-site-verification=6xJQtsTdw6-hMQf66ukkU02ohNnErQfc97jiBLDcxQU atlassian-domain-verification=yad4dBd3vi7t43fccWicT4aTXI02uYnXm2oxttFGIxT5PgSvkt... atlassian-domain-verification=8tFc82GexRGcVzICTju72I9JNrk7RwpCr2zjU/TkK0Hd//hy94... 8xvy7dgjyjfw8p1s53565lqj39cxv58j amazonses:S8MiqSDjHfNuU1m+xTsekE/accNT37fLzJxar0MZ6lU= google-site-verification=G0ioJKKYGCAYmiZ8PfH_jJCqgwHlov3iv5CcszhYuNU TAILSCALE-uxh1c7HkC6ejbgrSHheg fastly-domain-delegation-6wZXvyAYvqY6eDHQ-455222-2021-12-21 figma-domain-verification=7270251e41c1756b6f9877a95f24b22bbefa77647b91c2fb6c6f3f... amazon-business-verification=5e11e03c29a48a6878321d845fcb95ca31515e7c495f5a65d07... google-site-verification=kndq9tJlPDM8YDUwVfClSusEQLndhFP2PctnMb5xnPQ google-site-verification=xeCiM_8T6Vw4Uu-3o3vElDjWFn085QMfNB-OQisn_ac amazonses:FVn34vigBQoVyX5VCsZM5aWBmX0NqfmCJQdJegft/yI= ca3-deffbea64c9a4b55a20d0b7bf0ef0ad4 atlassian-domain-verification=IQQpEMfZ8H1Bfj0D2PHxOYW85VZCKGAfD2NhiWYJKuZACJ7wVP... SPF v=spf1 include:spf.protection.outlook.com include:%{i}._ip.%{h}._ehlo.%{d}._spf.... stripe-verification=f27b232f3bd8f1e6d8184a89d9af02c59a58b12d546ed5616c1a1ba67148... P13hZM71v7Pn9+XotetoD650lqbxyGHaOoAFhwvaSjcQ0uE+uAyNvW4JhpJmDpgfLZNQXu82CdvutlQf... amazonses:nw5Z1IzUEIir9nF/jk14GnTfjv58WkPvRtDzbE33JK0= ca3-285cc9695946437e92f96ed896eed840 amazonses:QKKwALExzbnTwkz6YNq3R/NrHFdblvbyAv+EcQXLbp8= amazonses:SfFs1x0QwWPX0f58XI4DaLoIcfnFhoRNrsiBkz4XGmc= amazonses:CdtezgcC+zkifFVY5btFMa4fzQ4BpghBTE6zr+beieM= _y7x7z089ga6gwrsk1ist583rgzgjblc onetrust-domain-verification=236ec154a3aa4903a0c039c5514fbc35 amazonses:WTKgcymrJTCZa1ItnmODR1gk1QPZWRSIvOYrDvO8sqY= vmware-cloud-verification-0668ecb2-c73e-4a22-98c8-b5078550d143 webexdomainverification.5523f43614297acbe053ab06fc0a5471=b0075467-3e3a-415f-a903... smartsheet-site-validation=4wId9lqkLAxzx1XATZENSE8RrB62lnjQ adobe-idp-site-verification=b40301a0ecb7b5b2446d3bed0d384fbadf796285b16e9acb8f14... prod-cm-virg-mail-relay |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://clarivate.com
3146 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://clarivate.com | 200 | 3146 ms | HTTP/1.1 | nginx |
A+IPv6 ReadinessIPv6 reachable (1 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 16 URLsPASS
# General rules for all bots
User-agent: *
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/plugins/
Disallow: /wp-content/cache/
Disallow: /wp-content/themes/
Disallow: /wp-content/uploads/dlm_uploads/
Disallow: /wp-content/uploads/sites/3/dlm_uploads/
Disallow: /wp-content/uploads/sites/4/dlm_uploads/
Disallow: /wp-content/uploads/sites/5/dlm_uploads/
Disallow: /feed/
Disallow: /*/feed
Disallow: /trackback/
Disallow: /comments/
Disallow: /?s=
Disallow: /search/
Disallow: /*.pdf$
Allow: /wp-admin/admin-ajax.php
Allow: /privacy-center/notices-policies/privacy-policy/
Allow: /wp-content/themes/clarivate/src/favicon/
Allow: /wp-content/themes/clarivate/manifest.json
Allow: /wp-content/themes/clarivate/ieconfig.xml
Crawl-delay: 3
# Sitemaps
Sitemap: https://www.clarivate.com/sitemap_index.xml
Sitemap: https://www.clarivate.com/academia-government/sitemap_index.xml
Sitemap: https://www.clarivate.com/life-sciences-healthcare/sitemap_index.xml
Sitemap: https://www.clarivate.com/intellectual-property/sitemap_index.xml
# Allow all major search engine bots with no crawl delay
# Google
User-agent: Googlebot
User-agent: Googlebot-Image
User-agent: Googlebot-News
User-agent: Googlebot-Video
User-agent: Mediapartners-Google
User-agent: AdsBot-Google
# Bing / Microsoft
User-agent: Bingbot
User-agent: MSNBot
User-agent: BingPreview
User-agent: AdIdxBot
# Yahoo
User-agent: Slurp
# Baidu (China)
User-agent: Baiduspider
User-agent: Baiduspider-image
User-agent: Baiduspider-video
User-agent: Baiduspider-news
# Yandex (Russia)
User-agent: Yandex
User-agent: YandexBot
User-agent: YandexImages
User-agent: YandexVideo
User-agent: YandexNews
User-agent: YandexBlogs
User-agent: YandexMedia
# DuckDuckGo
User-agent: DuckDuckBot
# Sogou (China)
User-agent: Sogou
User-agent: Sogou web spider
User-agent: Sogou Pic Spider
User-agent: Sogou head spider
User-agent: Sogou Orion spider
User-agent: Sogou-Test-Spider
# Seznam (Czech Republic)
User-agent: SeznamBot
# Naver (Korea)
User-agent: Yeti
# Exabot (France)
User-agent: Exabot
# Cuil (historical)
User-agent: Twiceler
# Archive.org / Alexa
User-agent: ia_archiver
#Rules for major search engine bots
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/plugins/
Disallow: /wp-content/cache/
Disallow: /wp-content/themes/
Disallow: /wp-content/uploads/dlm_uploads/
Disallow: /wp-content/uploads/sites/3/dlm_uploads/
Disallow: /wp-content/uploads/sites/4/dlm_uploads/
Disallow: /wp-content/uploads/sites/5/dlm_uploads/
Disallow: /feed/
Disallow: /*/feed
Disallow: /trackback/
Disallow: /comments/
Disallow: /?s=
Disallow: /search/
Disallow: /*.pdf$
Allow: /wp-admin/admin-ajax.php
Allow: /privacy-center/notices-policies/privacy-policy/
Allow: /wp-content/themes/clarivate/src/favicon/
Allow: /wp-content/themes/clarivate/manifest.json
Allow: /wp-content/themes/clarivate/ieconfig.xml
Allow: /wp-content/uploads/2025/03/clarivate-privacy-notice-1273x691-1.png
Allow: /wp-content/uploads/2025/03/clvprivacypolicy.jpg
Crawl-delay: 0
# Search engine bots are now ALLOWED with no crawl delay.
# Next are other good bots like social media, AI, SEO, and analytics bots with a short crawl delay.
# Social Media Bots
User-agent: Twitterbot
User-agent: facebot
User-agent: facebookexternalhit
User-agent: facebookcatalog
User-agent: meta-externalagent
User-agent: meta-externalfetcher
# Allow other good bots (AI) with a short crawl delay
User-agent: GPTBot
User-agent: ChatGPT-User
User-agent: CCBot
User-agent: ClaudeBot
User-agent: anthropic-ai
User-agent: cohere-ai
User-agent: Writer
# Allow other good SEO and analytics bots with a short crawl delay
User-agent: AhrefsBot
User-agent: AhrefsSiteAudit
User-agent: SemrushBot
User-agent: DotBot
User-agent: BLEXBot
User-agent: Barkrowler
User-agent: MJ12bot
User-agent: SerpstatBot
User-agent: MozDotBot
User-agent: Screaming Frog SEO Spider
User-agent: DomainStatsBot
User-agent: ZoomBot
User-agent: SiteCheckerBot
User-agent: Cliqzbot
User-agent: SeobilityBot
User-agent: UptimeRobot
User-agent: Google-Structured-Data-Testing-Tool
User-agent: Google-Read-Aloud
User-agent: Google-InspectionTool
#Rules for good bots like social media, AI, SEO, and analytics bots
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wp-content/plugins/
Disallow: /wp-content/cache/
Disallow: /wp-content/themes/
Disallow: /wp-content/uploads/dlm_uploads/
Disallow: /wp-content/uploads/sites/3/dlm_uploads/
Disallow: /wp-content/uploads/sites/4/dlm_uploads/
Disallow: /wp-content/uploads/sites/5/dlm_uploads/
Disallow: /feed/
Disallow: /*/feed
Disallow: /trackback/
Disallow: /comments/
Disallow: /?s=
Disallow: /search/
Disallow: /*.pdf$
Allow: /wp-admin/admin-ajax.php
Allow: /privacy-center/notices-policies/privacy-policy/
Allow: /wp-content/themes/clarivate/src/favicon/
Allow: /wp-content/themes/clarivate/manifest.json
Allow: /wp-content/themes/clarivate/ieconfig.xml
Allow: /wp-content/uploads/2025/03/clarivate-privacy-notice-1273x691-1.png
Allow: /wp-content/uploads/2025/03/clvprivacypolicy.jpg
Crawl-delay: 3
# Good bots like Facebook, AhrefsBot, GPTBot, ChatGPT-User, and SemrushBot are now ALLOWED.
# Disallowed bots below are blocked with a crawl delay of 3600 seconds (1 hour).
# Security Scanners & Vulnerability Tools
User-agent: sqlmap
User-agent: sqlmap/1.0-dev
User-agent: Acunetix
User-agent: masscan
User-agent: Nessus
User-agent: CensysInspect
User-agent: AlphaBot
User-agent: Go-http-client
User-agent: Offline Explorer
User-agent: WebCopier
# General Scrapers & Crawlers
User-agent: Scrapy
User-agent: Nutch
User-agent: Heritrix
User-agent: BacklinkCrawler
User-agent: 008
User-agent: DataForSeoBot
User-agent: PetalBot
User-agent: Seekport Crawler
User-agent: Zoominfobot
User-agent: ZoominfoBot
User-agent: CrunchBot
User-agent: omgili
# HTTP Clients & Libraries
User-agent: Python-urllib
User-agent: python-requests
User-agent: libwww-perl
User-agent: httpx
User-agent: curl
User-agent: Wget
User-agent: OkHttp
User-agent: Java
# Plagiarism & Low-Value Bots
User-agent: TurnitinBot
User-agent: Yeti
# Specialized Crawlers (aggressive referrer spam bots)
User-agent: crawler4j
User-agent: OpenLinkProfiler
User-agent: spbot
#Rules for disallowed bots
Disallow: /
Allow: /privacy-center/notices-policies/privacy-policy/
Allow: /wp-content/uploads/2025/03/clarivate-privacy-notice-1273x691-1.png
Allow: /wp-content/uploads/2025/03/clvprivacypolicy.jpg
Allow: /wp-content/themes/clarivate/src/favicon/
Allow: /wp-content/themes/clarivate/manifest.json
Allow: /wp-content/themes/clarivate/ieconfig.xml
Crawl-delay: 3600
- https://clarivate.com/post-sitemap1.xml
- https://clarivate.com/post-sitemap2.xml
- https://clarivate.com/post-sitemap3.xml
- https://clarivate.com/post-sitemap4.xml
- https://clarivate.com/page-sitemap1.xml
- https://clarivate.com/page-sitemap2.xml
- https://clarivate.com/news-sitemap1.xml
- https://clarivate.com/news-sitemap2.xml
- https://clarivate.com/news-sitemap3.xml
- https://clarivate.com/news-sitemap4.xml
- https://clarivate.com/people-sitemap.xml
- https://clarivate.com/drug-sitemap.xml
- https://clarivate.com/lp-sitemap.xml
- https://clarivate.com/podcast-sitemap.xm...
- https://clarivate.com/webinar-sitemap.xm...
- https://clarivate.com/local-sitemap.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligenceclarivate.com — via MarkMonitor Inc., 17 years, 9 months oldPASS
108 days
October 1, 2026
33 days
Issued by Let's Encrypt
17 years, 9 months
Registered October 1, 2008
Not enabled
Protects against DNS spoofing
Unknown
2620:12a:8000::4
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice