Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations80 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 57 ms lookupPASS
| A | 104.20.19.171, 172.66.168.133 |
| AAAA | 2606:4700:10::ac42:a885, 2606:4700:10::6814:13ab |
| CNAME | — |
| NS | nelly.ns.cloudflare.com, hal.ns.cloudflare.com |
| MX | 1 alt3.aspmx.l.google.com 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt4.aspmx.l.google.com |
| TXT | SPF v=spf1 include:_spf.google.com include:amazonses.com include:servers.mcsv.net ~a... facebook-domain-verification=5st0gx01skt3pix2iiw3ixqo06plqk pwa-site-verification=55Mu_no1D1M_buAmWL9XfJmUsw3CA789dxwUJDikvao= brave-ledger-verification=d686ec7cbaeb255267babd8bb2e87495842f011dfff28655c58f8b... v=DMARC1; p=quarantine; pct=1 OSSRH-68658 brave-ledger-verification=abfbe52dc8f1df1fd90196b31c31ec3b5b7e2488b980d485e519cd... openai-domain-verification=dv-DrE8gxonO2WEzuBu8ZwuJQ8H _dmarc. listennotes.com yandex-verification: fef7fe0c73e013cd google-site-verification=BtUtYiLJ_jY_IdRDfR4f1QGxyirk8UpIgLpYapoZS1k |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 194 ms totalPASS
https://listennotes.com
58 ms · HTTP/1.1
https://www.listennotes.com/
136 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://listennotes.com | 301 | 58 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.listennotes.com/ | 403 | 136 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 6 URLsPASS
# Welcome to Listen Notes!!!
# Hello, robots!!!!
# Podcast search API can be found at https://www.listennotes.com/api/
Sitemap: https://www.listennotes.com/sitemap.xml
#
# Hi good bots,
#
# We have to block you. We are getting a lot of backlink outreach emails.
# Those "outreach specialists" are using your services to find "backlink opportunities".
# That's how they found us.
#
User-agent: AhrefsBot
Disallow: /
User-agent: AhrefsSiteAudit
Disallow: /
User-agent: Linguee
Disallow: /
User-agent: SemrushBot
Disallow: /
User-agent: SemrushBot-SA
Disallow: /
User-agent: SemrushBot-BA
Disallow: /
User-agent: BLEXBot
Disallow: /
User-agent: dotbot
Disallow: /
User-agent: ia_archiver
Disallow: /
User-agent: MJ12bot
Disallow: /
User-agent: ZoominfoBot
Disallow: /
User-agent: adbeat_bot
Disallow: /
User-agent: Screaming Frog SEO Spider
Disallow: /
User-agent: MBCrawler/1.0
Disallow: /
User-agent: ltx71 - (http://ltx71.com/)
Disallow: /
User-agent: CCBot
Disallow: /
User-agent: TTD-Content
Disallow: /
User-agent: AwarioRssBot
User-agent: AwarioSmartBot
Disallow: /
User-agent: proximic
Disallow: /
#
# Other good bots
#
User-agent: Twitterbot
User-agent: facebookexternalhit
User-agent: LinkedInBot
Allow: /
User-agent: *
Allow: /endpoints/v1/community/lists/
Allow: /endpoints/v1/playlist/fetch_items/
Allow: /endpoints/v1/classifieds/posts/
Allow: /endpoints/v1/feeds/items/
Allow: /endpoints/v1/recommendations/academy/
Allow: /endpoints/v1/recommendations/interviews/
Allow: /endpoints/v1/recommendations/?*rec_type=channel*
Allow: /endpoints/v1/playlists/featured/
Allow: /endpoints/v1/labs/playing_episodes/
Allow: /*listen*?display
Allow: /*best-*?region
Allow: /podcasts/copyright/
Allow: /*/podcasts/copyright/
Disallow: /*?
Disallow: /random
Disallow: /episodes/random
Disallow: /channels/random
Disallow: /interviews/random
Disallow: /itunes/
Disallow: /directory*
Disallow: /podcast-directory*
Disallow: /transcribe
Disallow: /view.php
Disallow: /channels/*
Disallow: /episodes/*
Disallow: /e/p/*
Disallow: /c/r/*
Disallow: /tag/*
Disallow: /hunt/new/
Disallow: /404/
Disallow: /500/
Disallow: /endpoints/
Disallow: /oembed
Disallow: /embedded/e/
Disallow: /*/embed/
Disallow: /*/search/
Disallow: /search/
Disallow: /*/podcasts/*/similar/
Disallow: /podcasts/*/similar/
Disallow: /agi/
Disallow: /e/sitemap.xml
Disallow: /c/sitemap.xml
Disallow: /accounts/
Disallow: /errors/
Allow: /
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencelistennotes.com — via NameCheap, Inc., 9 years, 9 months oldPASS
2981 days
August 13, 2034
80 days
Issued by Google Trust Services
9 years, 9 months
Registered August 13, 2016
Enabled
Protects against DNS spoofing
Unknown
2606:4700:10::6814:13ab
NameCheap, Inc.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice