Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations329 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 149 ms lookupPASS
| A | 65.8.180.104, 65.8.180.127, 65.8.180.129, 65.8.180.7 |
| AAAA | — |
| CNAME | — |
| NS | ns-1156.awsdns-16.org, ns-2027.awsdns-61.co.uk, ns-287.awsdns-35.com, ns-661.awsdns-18.net |
| MX | 0 cision-com.mail.protection.outlook.com |
| TXT | 2407693529a142e89e95498a5103a495 286941235C 43BpZkrzXUDJ-qVyum9mOVgrYs8E8NnjxL23R27M4XM 5fFrCK6G5QgqrbaUMT+UQ0LKdZeYA7A+tLhT19EIlJbJ5qvJUNwQygkheHgxhffEXC8wxk6MIeSnrwX8... DocuSign=bcc128af-77b4-4bd1-9986-cda426232ab0 MS=ms14553053 MS=ms20297659 MS=ms44636147 SN9UAFEYE5EJ1KDB9BGA4XW95G1CKX6WX7GYP2GP _acme-challenge.cisionone.ticket.cision.com=t51qB4J-ZN-yuBBb6C4JeRIow9wxD2mwPagN... _acme-challenge.go.ticket.cision.com=dfSjYBTNOY31o750OsXhnm0mXttJYAaZRX8lhdR410k _acme-challenge.ticket.cision.com=3Id451c1fycLIY-QldPMwaJ-c0lmGZw4FsuQxJoknXA _acme-challenge.ticket.cision.com=lnmBjZd359NNKhs2ZqYwdX5VK3kd1lA33wnpiP54QUU _z32vxbe335rnn3i7w5i7igyyvt6mu0e adobe-idp-site-verification=1553d16558a02c1c6b4ca07016d7af52ed95661d5838cfeabb23... apple-domain-verification=bwm2zoLMbMs48GMv atlassian-domain-verification=xOt0R3So3Ni3VW2/HzT2wJ/da3Rp52p7FLGeExB0ElOYVBnJTI... atlassian-sending-domain-verification=34bf43ce-48bb-49dc-b453-da16a903c494 box-domain-verification=d0369ff4a0618ff19f1d7f9c98c9bb65203e8a33febfc79cf2df6db7... brevo-code:590906840c68c6d0ad2ae16f57c55b05 ca3-50e3b6d95342400d9ea5c9db9b069787 ca3-ba15bb833e3e4d8c9c75b57a00091955 canva-site-verification=EudpNmi88Kxh5Bxz2ImIzg citrix-verification-code=37780e2d-9564-4c6c-8744-e6dbf081e203 cloudhealth=2f5bab71-dce3-4edf-901c-8c1231821383 configcat-domain-verification=08dc41b1-a81e-47fd-8c91-f77c1e6de932 docusign=54128de6-3dfd-47d2-9586-fffd1670f68b google-site-verification=0iiDDVBHVFeXTMzrk8O-N6O4YzAZXYIMLaXRoPaXoSs google-site-verification=ZJUrns6SiCXD2YxjQ7PJ91s-apYPLe0ibS6uNarkg7k google-site-verification=lwjkfFbj_l8UuwgH8-sdc00VH8xhBEvKV6-5Rv5TFR0 intersight=480724317f26114ac652ac16aeb6530b6f1294fae2c6414714cb979c66ea0d00 intersight=f1c683a9dc1c0b1399fbc507561d9826ebf3d3401efb656de0d33a994eaf8ced logmein-verification-code=a7c77113-15d8-47f9-8847-d18ee8019950 loom-site-verification=91d16c30034f4f5a8c0b3ae1b604d1e6 mgverify=d3c825d463f994ae09b1340afffd4f16497edef547983cb736e02b3787875059 miro-verification=67207456568b6aa3025ebeb34660e2dbacb16a48 mixpanel-domain-verify=e96d114d-a557-44fd-8841-6b470bcaf1c9 mongodb-site-verification=KN1d8SaDdpnJfFvCW6g9409Yr7YpzSd2 onetrust-domain-verification=324bf5dceaa647c08e6af6a595e1105a oneuptime-verification-QQbRlrsZpLhzFtyZgStp p7hqzd5h4ryt7rp5s3s3m0l2qnvrb2zk p_-TdTLivHhXEAn5TmfSmly2wVeujyonX9p0DLnghBc pendo-domain-verification=3b63ebd5-9e92-43b6-9861-147c4c6d59f2 ptcggj066n92bfdgytfl5qzcy10rvk10 q45xx0y9cfsbv3jn3gdc9jt7wzvntb39 r2mjjd9vjp3rdr0jd22wptkfh74scddf sending_domain76922=2abe02b5775c122cd0d098b7aa520416957193f1675bb7857dfdf6ce127d... stripe-verification=7f85bde62820c777f74e55f48ef998d0a6f04c7e14be20f7eb44adec959a... SPF v=spf1 include:%{i}._ip.%{h}._ehlo.%{d}._spf.vali.email include:_spf.qp-mail.com... y2phz06dvtlrb1p65rsqr4qpfqpv4rxh zoho-verification=zb77364950.zmverify.zoho.eu |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 142 ms totalPASS
https://cision.com
75 ms · HTTP/1.1
https://www.cision.com/
67 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://cision.com | 301 | 75 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.cision.com/ | 200 | 67 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 1 URLsPASS
User-agent: *
Disallow: /search/*
Disallow: /content/dam/cision/Resources/nifiles/*
Disallow: /*.pdf
Sitemap: https://www.cision.com/sitemap.xml
A+Domain Intelligencecision.com — via CSC Corporate Domains, Inc., 24 years, 6 months old, hosted on AWSPASS
254 days
February 24, 2027
329 days
Issued by DigiCert Inc
24 years, 6 months
Registered February 24, 2002
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
65.8.180.129
CSC Corporate Domains, Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice