Skip to content
https://phongtamphuoctien.vn

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
79
GRADE
C
FIX
3
REVIEW
8
PASS
5
INFO
1
Probed from Madrid, Spain
200 OK
Checks
17
5 PASS 8 REVIEW 3 FIX
D
Multi-Resolver DNS Speed
Action
Mean 241ms across 3 resolvers (spread 409ms)
FIX
Mean 241ms across 3 resolvers (spread 409ms)
Info::
Quad9: 0ms
Got: 0ms via 9.9.9.9:53
Info::
Google: 316ms
Got: 316ms via 8.8.8.8:53
Info::
Cloudflare: 409ms
Got: 409ms via 1.1.1.1:53
Info::
High latency spread between resolvers: 409ms (min 0ms / max 409ms)
Wide gap between the fastest and slowest public resolver suggests a geographic anycast issue or an authoritative-server cache problem. Users in different regions will see materially different DNS times.
F
HTTP Probe Timing
Action
Total 4103 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
FIX
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
349 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
283 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
285 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
4.10 s
Total Time Total request time from DNS lookup through full response.
4.10 s

Connection waterfall

DNS Lookup 349 ms TCP Connect 283 ms TLS Handshake 285 ms Server Processing 3.19 s Content Transfer 1 ms
D
CDN & Delivery
Action
No CDN detected
FIX
No CDN detected
Warning::
No CDN detected
A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN detected

Consider using a CDN to improve global delivery speed and reduce origin load.

B
DNSSEC
Unsigned (DNSSEC not deployed)
REVIEW
Unsigned (DNSSEC not deployed)
Info::
DNSSEC is not deployed
The zone is not DNSSEC-signed. Users on validating resolvers (Cloudflare 1.1.1.1, Quad9 9.9.9.9, growing default in mobile resolvers) get no protection against DNS spoofing for this domain. Most registrars now offer DNSSEC at a single click; consider enabling it for sites where authenticity matters (banking, healthcare, government).
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
C
Reverse DNS
Action
0/1 IPs match cert SAN
REVIEW
0/1 IPs match cert SAN
Info::
PTR lookup failed for 103.75.185.25: lookup 103.75.185.25: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
REVIEW
www/non-www, trailing slash, HTTP→HTTPS
Critical::
HTTP version does not redirect to HTTPS
Got: HTTP 0 Expected: 301 redirect to HTTPS

www / non-www

403https://www.phongtamphuoctien.vn/
200https://phongtamphuoctien.vn/

HTTP → HTTPS

http://phongtamphuoctien.vn/

HTTP version does not redirect to HTTPS

C
TLS Certificate Expiry & Recommendations
Action
21 days until leaf cert expires — 4 issues to address
REVIEW

Certificate validity

21
days left
0d 30d 60d 90d+
Renew soon — under 30 days remaining

Recommended actions

  • Renew certificate — 21 days remaining
  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
CDN Cache Observability
No CDN cache-status headers in the response
REVIEW
No CDN cache-status headers in the response
Info::
No CDN cache-status headers in the response
Without an X-Cache / CF-Cache-Status / X-Vercel-Cache / Age header, you can't tell from outside whether a request hit the cache or went to origin. Operationally important: enables debugging stale-content reports and verifying cache rules. Most managed CDN platforms emit at least one of these by default; absence often means the platform's diagnostic headers are stripped at an upstream proxy.
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
A
DNS Records
1 A records, 1 ms lookup
PASS
1 A records, 1 ms lookup
Info::
Resolves to 1 IPv4 address(es)
Got: 103.75.185.25
Info::
Single A record — no DNS redundancy
Multiple A records provide failover if one server goes down.
Info::
No IPv6 (AAAA) records
Info::
3 nameserver(s) configured
Got: ns3.inet.vn, ns2.inet.vn, ns1.inet.vn
Info::
No MX records — email not configured via DNS
Info::
No SPF record found in TXT records
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Info::
DNS resolution time: 1 ms
Got: 1 ms
A103.75.185.25
AAAA
CNAME
NSns3.inet.vn, ns2.inet.vn, ns1.inet.vn
MX
TXT
CAALookup not available with standard resolver
Resolved in 1 ms

Multiple A records provide failover if one server goes down.

Why this matters

Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.

Learn more

Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.

Source: SRE practice / DNS architecture

SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.

Why this matters

Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.

Learn more

SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.

Source: RFC 7208 (SPF)

A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://phongtamphuoctien.vn

https://phongtamphuoctien.vn

826 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://phongtamphuoctien.vn200826 msHTTP/1.1
A+
Crawlability
robots.txt present, sitemap with 16 URLs
PASS
robots.txt present, sitemap with 16 URLs
Info::
robots.txt is present
Got: 329 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 16 entries
Info::
Sitemap index with 16 child sitemaps
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 329 B Sitemaps referenced 1 User-agents Blocking No — crawling allowed
User-agent: *
Disallow: /wp-content/uploads/wc-logs/
Disallow: /wp-content/uploads/woocommerce_transient_files/
Disallow: /wp-content/uploads/woocommerce_uploads/
Disallow: /*?add-to-cart=
Disallow: /*?*add-to-cart=
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php

Sitemap: https://phongtamphuoctien.vn/sitemap_index.xml

A+
Health Check Endpoint
Health endpoint at https://phongtamphuoctien.vn/healthz (HTTP 200)
PASS
Health endpoint at https://phongtamphuoctien.vn/healthz (HTTP 200)
Info::
Public health endpoint at https://phongtamphuoctien.vn/healthz
Got: https://phongtamphuoctien.vn/healthz
Domain Intelligence
Domain intelligence data not available
INFO
Domain intelligence data not available

RDAP and WHOIS lookup both failed

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback