Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BRedirect Chain2 redirect(s), 526 ms totalREVIEW
https://bose.com
57 ms · HTTP/1.1
https://www.bose.com
264 ms · HTTP/1.1
https://www.bose.com/home
205 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://bose.com | 301 | 57 ms | HTTP/1.1 | ambassador-external |
| 2 | https://www.bose.com | 301 | 264 ms | HTTP/1.1 | cloudflare |
| 3 | https://www.bose.com/home | 200 | 205 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
Each redirect adds latency. Try to minimize the chain to 1 hop.
Redirect chain — each hop adds latency; combine into one redirect where possible.
Source: Google Search Central / web.dev
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations306 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 79 ms lookupPASS
| A | 52.84.174.116, 52.84.174.97, 52.84.174.20, 52.84.174.3 |
| AAAA | — |
| CNAME | — |
| NS | ns-987.awsdns-59.net, ns-1849.awsdns-39.co.uk, ns-312.awsdns-39.com, ns-1135.awsdns-13.org |
| MX | 10 mxb-00428a01.gslb.pphosted.com 10 mxa-00428a01.gslb.pphosted.com |
| TXT | openai-domain-verification=dv-2My9CqYKLwqNAvxbRuZhJB3G apple-domain-verification=W3Fa1PN8ZBG0KPRi miro-verification=ef2a8c56f0714e289733992c24f4214fff2c48e0 flexera-domain-verification-yvehsxhxzptbxbke 054163deb0014fa9b304ed2d4790ba85 MS=ms99166661 SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com include:9194398.spf03.hubspo... anthropic-domain-verification-qd8m97=hdgnp9whZseCVao2rR8iuoUVf vmware-cloud-verification-90cd634a-ae7d-4455-8e77-a047786148bb google-site-verification=QxX-QJhuRvqbVyagPE0v1jI17bH9biLYWSaDAWNWAVA google-site-verification=bWskYLjjltCKFlpwKBaAppdqOZjdNWyMbcAIz7wIHB0 atlassian-domain-verification=EDOVb9aJoafDn1NxtSwSmn97d3YVidPlAU8o8WIkJq1F8rgz1y... atlassian-sending-domain-verification=73c245fc-cd55-4665-8a54-9bdd59513799 _r2wlrmim9ipqieyfmymmj3h5c7qoh0x MS=ms47557510 smartsheet-site-validation=73pqNnRioMn04g7zMoUWGbfQBNi2azBL _bfbpepl191rgsmcelo7rl1aufqnxmgp mongodb-site-verification=gPNFIzw15NMQvqJDAbSd2XAGHQPFq7F1 google-gws-recovery-domain-verification=51509574 |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 4 URLsPASS
# ___ ___ _ _ _ _ ___ ___ ___
# / __|/ _ \| | | | \| | \ |_ _/ __|
# \__ \ (_) | |_| | .` | |) | | |\__ \
# |___/\___/ \___/|_|\_|___/ |___|___/
# ___ _____ _____ ___
# | _ \/ _ \ \ / / __| _ \
# | _/ (_) \ \/\/ /| _|| /
# |_| \___/ \_/\_/ |___|_|_\
#
# 01000010 01001111 01010011 01000101
User-agent: *
Disallow: */on/demandware.store/*
Disallow: /search*
Disallow: */null*
Disallow: /cart*
Disallow: /account*
Disallow: /order-history*
Sitemap: https://www.bose.com/sitemap_index.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencebose.com — via MarkMonitor Inc., 34 years, 10 months old, hosted on AWSPASS
188 days
December 19, 2026
306 days
Issued by Amazon
34 years, 10 months
Registered December 20, 1991
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
52.84.174.3
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice