Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FIPv6 ReadinessActionIPv6 records exist but unreachableFIX
Having AAAA records but an unreachable server is worse than no AAAA — clients may experience delays before falling back to IPv4.
Advertising IPv6 (AAAA records) without a reachable server means IPv6-preferring clients silently fail every connection.
Learn more ▾ ▴
Modern browsers prefer IPv6 if AAAA exists (Happy Eyeballs algorithm). If the IPv6 server isn't reachable, browsers fall back to IPv4 — but with seconds of added latency per request. Either fix IPv6 reachability or remove the AAAA records.
Source: RFC 8305 (Happy Eyeballs)
BDNSSECUnsigned (DNSSEC not deployed)REVIEW
BCAA RecordsNo CAA records (any CA may issue certificates)REVIEW
BReverse DNS0/4 IPs match cert SANREVIEW
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations55 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
CCDN & DeliveryActionAssets on AWS CloudFront (host media.wired.com, 38 assets); document served directly from originREVIEW
Asset hosts on a CDN
- media.wired.com — AWS CloudFront · assets: 38 · Cache Status: Hit from cloudfront
- dwgyu36up6iuz.cloudfront.net — AWS CloudFront · assets: 10 · Cache Status: Hit from cloudfront
- www.wired.com — Cloudflare · assets: 8 · Cache Status: DYNAMIC
- snap.licdn.com — Akamai · assets: 4
- analytics.tiktok.com — Akamai · assets: 3 · Cache Status: TCP_MEM_HIT from a104-70-121-47.deploy.akamaitechnologies.com (AkamaiGHost/22.6.3-da071da6976b6d633b0b37bcfe65c0fc) (-)
Other asset hosts
- www.googletagmanager.com — assets: 11 · Google
- bat.bing.com — assets: 3 · Microsoft Azure
- connect.facebook.net — assets: 3 · not attributed
- news.google.com — assets: 3 · below probe threshold
- uk-script.dotmetrics.net — assets: 3 · below probe threshold
- ads-static.conde.digital — assets: 2 · below probe threshold
- analytics.twitter.com — assets: 2 · below probe threshold
- asset.fwpub1.com — assets: 2 · below probe threshold
- config.aps.amazon-adsystem.com — assets: 2 · below probe threshold
- globalservices.conde.digital — assets: 2 · below probe threshold
- securepubads.g.doubleclick.net — assets: 2 · below probe threshold
- t.co — assets: 2 · below probe threshold
- trx-hub.com — assets: 2 · below probe threshold
- a.ad.gt — assets: 1 · below probe threshold
- ak.sail-horizon.com — assets: 1 · below probe threshold
- apis.google.com — assets: 1 · below probe threshold
- apps.rokt.com — assets: 1 · below probe threshold
- bd1cec50-00d1-4ce9-9572-785857419a1e.edge.permutive.app — assets: 1 · below probe threshold
- cdn-magiclinks.trackonomics.net — assets: 1 · below probe threshold
- cdn.gladly.com — assets: 1 · below probe threshold
- cdn.parsely.com — assets: 1 · below probe threshold
- cdn.sophi.io — assets: 1 · below probe threshold
- cdn.treasuredata.com — assets: 1 · below probe threshold
- cdnjs.cloudflare.com — assets: 1 · below probe threshold
- client.aps.amazon-adsystem.com — assets: 1 · below probe threshold
- googleads.g.doubleclick.net — assets: 1 · below probe threshold
- js.adsrvr.org — assets: 1 · below probe threshold
- martech.condenastdigital.com — assets: 1 · below probe threshold
- privacy.condenastdigital.com — assets: 1 · below probe threshold
- s.skimresources.com — assets: 1 · below probe threshold
- s.yimg.com — assets: 1 · below probe threshold
- sb.scorecardresearch.com — assets: 1 · below probe threshold
- sc-static.net — assets: 1 · below probe threshold
- sp.analytics.yahoo.com — assets: 1 · below probe threshold
- ssc.wired.com — assets: 1 · below probe threshold
- static.ads-twitter.com — assets: 1 · below probe threshold
- static.adsafeprotected.com — assets: 1 · below probe threshold
- tag.bounceexchange.com — assets: 1 · below probe threshold
- tr.snapchat.com — assets: 1 · below probe threshold
- www.redditstatic.com — assets: 1 · below probe threshold
The heavy static files already ride an edge network, but every visitor still waits on the origin for the HTML itself. Routing the document through the same CDN is usually a config change rather than a migration: a short edge TTL with stale-while-revalidate for cacheable HTML, or edge TLS termination alone when the response is per-user.
BCDN Cache ObservabilityNo CDN cache-status headers in the responseREVIEW
BOperational Status PageNo status page link detectedREVIEW
A+DNS Records2 A records, 17 ms lookupPASS
| A | 52.223.6.210, 166.117.251.134 |
| AAAA | 2600:9000:a41b:ef95:eff:32b3:411c:f36c, 2600:9000:a707:a46c:560f:b721:9702:d75e |
| CNAME | — |
| NS | ns-1116.awsdns-11.org, ns-1935.awsdns-49.co.uk, ns-28.awsdns-03.com, ns-836.awsdns-40.net |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt4.aspmx.l.google.com 10 alt3.aspmx.l.google.com |
| TXT | 3c5bnsm2366rtqny77w8cq9wvy49r0w9 907D-6CE2-7BD0-FF0C-7E83-E21D-AD2B-DD27 MS=ms32964175 MS=ms43391860 ZOOM_verify_PeuZagN7TzybBaD-uxsGAw _globalsign-domain-verification=5gwbTrtjX4CPebqVSR8L6SpOvnf_3_6K7X0z_Izh9q _globalsign-domain-verification=GXpUUS49HB9rYWZEmxJFtZdS61weLMlf91w9Dn-5O0 _globalsign-domain-verification=ln6G6qMbrMeJLZSOGjjxis2fcs9NHicunfT-JK_mCZ adobe-idp-site-verification=c2108b9dbc0fc05ff0794006df1c41b6c945bd2c8a904bef754e... airalo-domain-verification=8o95GSpImu3dWoe anthropic-domain-verification-qjhty4=rH0iOGSnUm12xzxooo18gnz9G atlassian-domain-verification=mYtQWl3namqmk5ikMKT48XVnS+XdjdbkLlkWMcNyvsddK2JDAi... docusign=093f2a18-6882-43f7-a9ae-b2594de9d47f facebook-domain-verification=75aqj8blnqc3dj5cy9b5d9mialys78 fastly-domain-delegation-duxxxum9cshse9phbfst-554686-2022-12-12 fastly-domain-delegation-grdt7uboiyaqqtgjenzi-789661-2024-07-19 figma-domain-verification=2edc90f8e8740d757633998df93b92af5494d0ad60e746b5a5a252... globalsign-domain-verification=Wq9iztGUzQcBBi1OLrEOlXtefwOzX7yfvhbsw-CVdo google-site-verification=39CB9sd7tH1nrsJcVjjUzO9sVoKZ-2MBshlRhqFX13k google-site-verification=8dMUQRGxbDNDoEIZXU-E4-GmKLNvgkFwwAmqY0qUroU google-site-verification=Njx9q6Atd2al1mD6wtXu2u83s0Sz6WZQa_r0jmg261k google-site-verification=h3oXJvoyRaANoWJ-cjd8H3Zv49YViS96em2ZhNfeGPo google-site-verification=tA0Sx_MrXe58GUfjaTg-EgrfF7wv1WdDVKKq7dyNuwc loaderio=b8d2a4d94bf4574bd8c95427c0fcbee6 openai-domain-verification=dv-LCvTXCMns2J5grLiXF1uTD2T SPF v=spf1 include:_u.wired.com._spf.smart.ondmarc.com ~all yahoo-verification-key=HFoI8YeAFA0EIy9UkTckoOvVblp1gSUBZM9B8KKeYNs= zapier-domain-verification-challenge=97705597-a31c-4c6d-aa76-7e01d2b3fe13 |
| CAA | Lookup not available with standard resolver |
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
A+Multi-Resolver DNS SpeedMean 4ms across 3 resolvers (spread 6ms)PASS
ARedirect Chain1 redirect(s), 185 ms totalPASS
https://wired.com
31 ms · HTTP/1.1
https://www.wired.com/
155 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://wired.com | 301 | 31 ms | HTTP/1.1 | nginx |
| 2 | https://www.wired.com/ | 200 | 155 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 60 URLsPASS
Sitemap: https://www.wired.com/sitemap.xml
Sitemap: https://www.wired.com/tagpages-sitemap.xml
Sitemap: https://www.wired.com/contributors-sitemap.xml
Sitemap: https://www.wired.com/bundles-sitemap.xml
Sitemap: https://www.wired.com/branded-sitemap.xml
Sitemap: https://www.wired.com/feed/google-latest-news/sitemap-google-news
Sitemap: https://www.wired.com/feed/rss
User-agent: *
Disallow: /*?
Allow: /*?page
Allow: /*.xml?
Allow: /*.js
Allow: /*.css
Allow: /*.ico
Allow: /verso/static
Allow: /*.svg
Allow: /*.png
Allow: /*.jpg
Allow: /*.jpeg
Allow: /*rss?
Allow: /*?id=
Disallow: /auth/
Disallow: /account/
Disallow: /user/
Disallow: /user-context
Disallow: /preview/
Disallow: /search
Disallow: /product/
Disallow: /cdn-cgi/
Disallow: /services.min.js
Disallow: /com.condenast/yv8
Disallow: /reject-all
###
Allow: /v2/offers/wira
Allow: /*?*utm_medium=social
Allow: /*?*utm_medium=syndication
Allow: /*?ref=
Allow: /story/madison-square-garden-jim-dolan-surveillance-machine/?src
Disallow: */testing-products-
###
User-agent: AmazonAdBot
User-agent: FacebookExternalHit
User-agent: Google-InspectionTool
User-agent: LinkedInBot
User-agent: Pinterestbot
User-agent: Storebot-Google
User-agent: TikTokSpider
User-agent: Twitterbot
Allow: /
User-agent: Amazonbot
User-agent: Applebot-Extended
User-agent: archive.org_bot
User-agent: Bravebot
User-agent: Brightbot 1.0
User-agent: Bytespider
User-agent: CCBot
User-agent: Claude-SearchBot
User-agent: Claude-User
User-agent: ClaudeBot
User-agent: cohere-ai
User-agent: cohere-training-data-crawler
User-agent: Diffbot
User-agent: DuckAssistBot
User-agent: factset_spyderbot
User-agent: FirecrawlAgent
User-agent: Google-CloudVertexBot
User-agent: Google-Extended
User-agent: GoogleOther
User-agent: heritrix
User-agent: ia_archiver
User-agent: ia_archiver-web.archive.org
User-agent: meta-externalagent
User-agent: meta-externalfetcher
User-agent: meta-webindexer
User-agent: MistralAI-User
User-agent: PanguBot
User-agent: Perplexity-User
User-agent: PerplexityBot
User-agent: PetalBot
User-agent: Scrapy
User-agent: Shap-User
User-agent: ShapBot
User-agent: Timpibot
User-agent: Yisouspider
User-agent: YouBot
User-agent: Webzio
User-agent: Webzio-Extended
Disallow: /
- https://www.wired.com/sitemap-2026-09.xm...
- https://www.wired.com/sitemap-2026-08.xm...
- https://www.wired.com/sitemap-2026-07.xm...
- https://www.wired.com/sitemap-2026-06.xm...
- https://www.wired.com/sitemap-2026-05.xm...
- https://www.wired.com/sitemap-2026-04.xm...
- https://www.wired.com/sitemap-2026-03.xm...
- https://www.wired.com/sitemap-2026-02.xm...
- https://www.wired.com/sitemap-2026-01.xm...
- https://www.wired.com/sitemap-2025-12.xm...
- https://www.wired.com/sitemap-2025-11.xm...
- https://www.wired.com/sitemap-2025-10.xm...
- https://www.wired.com/sitemap-2025-09.xm...
- https://www.wired.com/sitemap-2025-08.xm...
- https://www.wired.com/sitemap-2025-07.xm...
- https://www.wired.com/sitemap-2025-06.xm...
- https://www.wired.com/sitemap-2025-05.xm...
- https://www.wired.com/sitemap-2025-04.xm...
- https://www.wired.com/sitemap-2025-03.xm...
- https://www.wired.com/sitemap-2025-02.xm...
- https://www.wired.com/sitemap-2025-01.xm...
- https://www.wired.com/sitemap-2024-12.xm...
- https://www.wired.com/sitemap-2024-11.xm...
- https://www.wired.com/sitemap-2024-10.xm...
- https://www.wired.com/sitemap-2024-09.xm...
- https://www.wired.com/sitemap-2024-08.xm...
- https://www.wired.com/sitemap-2024-07.xm...
- https://www.wired.com/sitemap-2024-06.xm...
- https://www.wired.com/sitemap-2024-05.xm...
- https://www.wired.com/sitemap-2024-04.xm...
- https://www.wired.com/sitemap-2024-03.xm...
- https://www.wired.com/sitemap-2024-02.xm...
- https://www.wired.com/sitemap-2024-01.xm...
- https://www.wired.com/sitemap-2023-12.xm...
- https://www.wired.com/sitemap-2023-11.xm...
- https://www.wired.com/sitemap-2023-10.xm...
- https://www.wired.com/sitemap-2023-09.xm...
- https://www.wired.com/sitemap-2023-08.xm...
- https://www.wired.com/sitemap-2023-07.xm...
- https://www.wired.com/sitemap-2023-06.xm...
- https://www.wired.com/sitemap-2023-05.xm...
- https://www.wired.com/sitemap-2023-04.xm...
- https://www.wired.com/sitemap-2023-03.xm...
- https://www.wired.com/sitemap-2023-02.xm...
- https://www.wired.com/sitemap-2023-01.xm...
- https://www.wired.com/sitemap-2022-12.xm...
- https://www.wired.com/sitemap-2022-11.xm...
- https://www.wired.com/sitemap-2022-10.xm...
- https://www.wired.com/sitemap-2022-09.xm...
- https://www.wired.com/sitemap-2022-08.xm...
- https://www.wired.com/sitemap-2022-07.xm...
- https://www.wired.com/sitemap-2022-06.xm...
- https://www.wired.com/sitemap-2022-05.xm...
- https://www.wired.com/sitemap-2022-04.xm...
- https://www.wired.com/sitemap-2022-03.xm...
- https://www.wired.com/sitemap-2022-02.xm...
- https://www.wired.com/sitemap-2022-01.xm...
- https://www.wired.com/sitemap-2021-12.xm...
- https://www.wired.com/sitemap-2021-11.xm...
- https://www.wired.com/sitemap-2021-10.xm...
A+Domain Intelligencewired.com — via CSC Corporate Domains, Inc., 34 years, 4 months oldPASS
417 days
November 19, 2027
55 days
Issued by Amazon
34 years, 4 months
Registered November 20, 1992
Not enabled
Protects against DNS spoofing
Unknown
2600:9000:a707:a46c:560f:b721:9702:d75e
CSC Corporate Domains, Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice