Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations315 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 197 ms lookupPASS
| A | 13.35.202.109, 13.35.202.112, 13.35.202.127, 13.35.202.90 |
| AAAA | — |
| CNAME | — |
| NS | ns-118.awsdns-14.com, ns-1462.awsdns-54.org, ns-1736.awsdns-25.co.uk, ns-788.awsdns-34.net |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt3.aspmx.l.google.com 10 alt4.aspmx.l.google.com |
| TXT | facebook-domain-verification=3p23coxts8xk9or4lchziysj5zx1bd google-site-verification=2DKiIBM6JgkMDGWxGRrUOLyLIqI20DXzNo1uEkzmVbA google-site-verification=W8ET_FCceRanzywXtV48bLVEUdR4b8x5W5REQgqxISM google-site-verification=XXFiKOSIc6-v69EARNMxA7bzEkGAv7-26j7SWm3HDWc google-site-verification=vnm0212sTXFpGSCZvksALhj7SgM25JxLyTOmmsGVGt8 site-verification=d2263cab1c354f8a2c86c6dd844368c9 SPF v=spf1 include:_spf.google.com include:amazonses.com -all |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 665 ms totalPASS
https://xataka.com
470 ms · HTTP/1.1
https://www.xataka.com/
196 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://xataka.com | 301 | 470 ms | HTTP/1.1 | nginx/1.29.7 |
| 2 | https://www.xataka.com/ | 200 | 196 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 92 URLsPASS
#
# robots.txt
#
User-agent: Orthogaffe
Disallow: /
# Crawlers that are kind enough to obey, but which we'd rather not have
# unless they're feeding search engines.
User-agent: UbiCrawler
Disallow: /
User-agent: DOC
Disallow: /
User-agent: Zao
Disallow: /
User-agent: gsa-crawler
Disallow: /
# Some bots are known to be trouble, particularly those designed to copy
# entire sites. Please obey robots.txt.
User-agent: sitecheck.internetseer.com
Disallow: /
User-agent: Zealbot
Disallow: /
User-agent: AmazonAdBot
Disallow:
User-agent: MSIECrawler
Disallow: /
User-agent: SiteSnagger
Disallow: /
User-agent: WebStripper
Disallow: /
User-agent: WebCopier
Disallow: /
User-agent: Fetch
Disallow: /
User-agent: Offline Explorer
Disallow: /
User-agent: Teleport
Disallow: /
User-agent: TeleportPro
Disallow: /
User-agent: WebZIP
Disallow: /
User-agent: linko
Disallow: /
User-agent: HTTrack
Disallow: /
User-agent: Microsoft.URL.Control
Disallow: /
User-agent: Xenu
Disallow: /
User-agent: larbin
Disallow: /
User-agent: libwww
Disallow: /
User-agent: ZyBORG
Disallow: /
User-agent: Download Ninja
Disallow: /
# Sorry, wget in its recursive mode is a frequent problem.
# Please read the man page and use it properly; there is a
# --wait option you can use to set the delay between hits,
# for instance.
#
User-agent: wget
Disallow: /
#
# The 'grub' distributed client has been *very* poorly behaved.
#
User-agent: grub-client
Disallow: /
#
# Doesn't follow robots.txt anyway, but...
#
User-agent: k2spider
Disallow: /
#
# Hits many times per second, not acceptable
# http://www.nameprotect.com/botinfo.html
User-agent: NPBot
Disallow: /
# A capture bot, downloads gazillions of pages with no public benefit
# http://www.webreaper.net/
User-agent: WebReaper
Disallow: /
User-agent: CNCDialer
Disallow: /
User-agent: Maxthon
Disallow: /
User-agent: MJ12bot
Disallow: /
User-agent: Slurp
Disallow: /
User-agent: *
Disallow: /wp-content/
Disallow: /wp-admin/
Disallow: /wp-includes/
Disallow: /wpi/
Disallow: /trackback/
Disallow: /*/*/*/feed.xml
Allow: /retro/*
Disallow: /retro
Disallow: /login.php/
Disallow: /frontend.php/
Disallow: /api/1.0/migration
Disallow: /server
Disallow: /queue
Disallow: /mobile.php/
Disallow: /app.php/
Disallow: /main.php/
#Disallow: /redirect
Disallow: /approve
Disallow: /duplicate
Disallow: /1018282
Disallow: /api/
Disallow: /c/
Disallow: /morepostcomments
Disallow: /offtopic
Disallow: /pda
Disallow: /preview-main/*
Disallow: /tracker
Disallow: /clubcampusparty
Disallow: /entraenatrix
Disallow: /espaciohpultrabook
Disallow: /espaciohtcone
Disallow: /espaciohuawei
Disallow: /espaciolgseriex
Disallow: /espaciolumia
Disallow: /espacionokia
Disallow: /espaciotecnologiasford
Disallow: /espaciotoshiba
Disallow: /lgmobile
Disallow: /espaciovisa
Disallow: /movistartv
Disallow: /mundogalaxy
Disallow: /nuevoestilodeti
Disallow: /philipssmarttv
Disallow: /tecnologiakia
Disallow: /vivephilipstv
Disallow: /vodafoneadslafondo
Disallow: /wishlistpremiosxataka
Disallow: /.well-known/amphtml/apikey.pub
Disallow: /expertos/respuestas/*
Disallow: /usuario/*
Disallow: /busqueda?
Disallow: /search?q=
Disallow: /frontend_dev.php/
# Disallow: /la-cacharreria/search*?*
Sitemap: https://www.xataka.com/sitemap_news.xml
Sitemap: https://www.xataka.com/club/sitemap.xml
Sitemap: https://www.xataka.com/sitemap_index.xml
# ==========================================
# BLOCK LLM & SCRAPERS
# ==========================================
User-agent: AI2Bot
Disallow: /
User-agent: ChatGLM
Disallow: /
User-agent: ChatGLM-Spider
Disallow: /
User-agent: cohere-training-data-crawler
Disallow: /
User-agent: Diffbot
Disallow: /
User-agent: OmigiliBot
Disallow: /
User-agent: PetalBot
Disallow: /
User-agent: YouBot
Disallow: /
# ==========================================
# NOTA INTERNA: BOTS AUTORIZADOS (NO BLOQUEADOS)
# Según la tabla de directrices, tienen acceso permitido:
# Applebot-Extended, Bytespider, CCBot, ClaudeBot, GPTBot,
# Meta-ExternalAgent, ChatGPT-User, Claude-SearchBot,
# Claude-User, OAI-SearchBot, Perplexity-User, PerplexityBot.
# (ChatGLM aparece duplicado en origen; se ha bloqueado por seguridad).
# ==========================================
- https://www.xataka.com/medicina-y-salud/espana-hemos-glorificado-siesta-para-ciencia-dormir-30-minutos-al-dia-bandera-roja-para-tu-salud
- https://www.xataka.com/streaming/llega-a-netflix-clasico-indiscutible-gano-siete-oscar-gracias-al-imbatible-carisma-su-duo-protagonista
- https://www.xataka.com/movilidad/singapur-lujo-no-tener-ferrari-lamborghini-verdadero-lujo-simplemente-conducir-1
- https://www.xataka.com/ecologia-y-naturaleza/hojas-ramas-arboles-liquidos-belgrado-fascinante-solucion-biotecnologica-para-limpiar-aire-ciudades
- https://www.xataka.com/moviles/iphone-puede-hacer-mucho-que-creemos-clave-esta-atajos-asi-puedes-empezar-a-aprovecharlos
A+Domain Intelligencexataka.com — via NameCheap, Inc., 22 years old, hosted on AWSPASS
43 days
July 26, 2026
315 days
Issued by Amazon
22 years
Registered July 26, 2004
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
13.35.202.109
NameCheap, Inc.
Expiry timeline
Recommended actions
- Renew the domain or enable auto-renewal to prevent accidental expiry
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice