Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations89 days until leaf cert expires — 2 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 13 ms lookupPASS
| A | 104.18.34.245, 172.64.153.11 |
| AAAA | 2a06:98c1:3109::6812:22f5, 2606:4700:4405::ac40:990b |
| CNAME | — |
| NS | elisa.ns.cloudflare.com, gannon.ns.cloudflare.com |
| MX | 1 aspmx.l.google.com 5 alt2.aspmx.l.google.com 5 alt1.aspmx.l.google.com 10 alt3.aspmx.l.google.com 10 alt4.aspmx.l.google.com |
| TXT | MS=ms15058904 MS=ms95772151 Pv0TLiWeowXZIsAw68NzAb3SgjY 7aff834813804a3ea18721b6bce7740d asv=57fab8da76cd7db6399386b2fbb8266e ca3-b122d05a919141ba91aba958f04a3a83 GUID=9928b8b1-f83f-4518-bf35-ac7504f9b417 apple-domain-verification=WCdjJmlbmQSDdvD3 status-page-domain-verification=qh3cfw6syrg3 docusign=70668272-5104-4868-af0d-389211541998 1password-site-verification=VOWKAPWYWZCT5HUOWLC2SAZL5E openai-domain-verification=dv-UNBZKzk7GFSRuVEUk4KHWObW loom-site-verification=edd4369291874aacb2b5aae6ea089158 segment-site-verification=xopGmJnxbn2rPzZXsS2fMLslPYUndBeJ cursor-domain-verification-f88819=Y8P5LsyqtmltA7MfMr2jwtMiQ facebook-domain-verification=ckr53ulsmy1vs2dwppppt6xwhtc5fk anthropic-domain-verification-1mjwc0=ydAYQut9EZNXEQaKnOtAjzP66 logmein-verification-code=25ce4838-7980-4719-b4c5-e76450a6066f have-i-been-pwned-verification=37c31c95ebc27a82104fd378e23c6f3e google-site-verification=gB6gRbVH-PkcwwblYYT_s6peEZ-uOCU4SCN-m6t2-0Q google-site-verification=kHACMEqbYV5qgu3tprf-GnXzWeHvWVHgVncFCiQKlb4 asn-verification=113e130f52ef13092231213dbadd8d30f0143c37b2c2744d24b16bfbc770372... stripe-verification=4fa8f2705ed3ca0496b4d680bdec5d74213c22e6c1428282612504c2c55d... 0r4UVQn/K1PldOhFrE9MoJLiJXfQLSKU+uLPm4Z1uGfGrxtPLbQ+ymZcnBCVIkemqdAFahKrsLodU2cq... atlassian-domain-verification=vRVlNNYB4Ta6QoLCQtsmdBc6emoab1Jsldy9az8E47tQW4cHaj... SPF v=spf1 include:mail.zendesk.com include:_spf.google.com include:_spf.qualtrics.c... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 537 ms totalPASS
https://myfitnesspal.com
145 ms · HTTP/1.1
https://www.myfitnesspal.com/
391 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://myfitnesspal.com | 301 | 145 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.myfitnesspal.com/ | 200 | 391 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (2 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 7 URLsPASS
User-agent: ChatGPT-User
Disallow: /
User-agent: *
Disallow: /500
Disallow: /404
Disallow: /*/500
Disallow: /*/404
Disallow: /account/logout
Disallow: /account/settings
Disallow: /account/forgot-password
Disallow: /account/diary-settings
Disallow: /account/create
Disallow: /account/my-goals
Disallow: /account/change-goals-guided
Disallow: /account/new_goals
Disallow: /account/configure-units
Disallow: /add_to_diary
Disallow: /api
Disallow: /badges
Disallow: /blog/
Disallow: /bulletin
Disallow: /diary
Disallow: /exercise/mine
Disallow: /exercise/search
Disallow: /fitbit
Disallow: /food/duplicate
Disallow: /food/edit
Disallow: /food/mine
Disallow: /friends
Disallow: /grocery
Disallow: /invitations
Disallow: /meal
Disallow: /measurements
Disallow: /messages
Disallow: /oauth2
Disallow: /profile
Disallow: /plan
Disallow: /recipe_parser
Disallow: /recipe/box
Disallow: /recipe/edit
Disallow: /recipe/view
Disallow: /recipes
Disallow: /reports
Disallow: /rss
Disallow: /track
Disallow: /unsubscribe
Disallow: /user
Disallow: /vanilla
Disallow: /weight-loss-ticker
Sitemap: https://www.myfitnesspal.com/sitemap.xml
A+Domain Intelligencemyfitnesspal.com — via MarkMonitor Inc., 21 years, 8 months oldPASS
887 days
November 16, 2028
89 days
Issued by Google Trust Services
21 years, 8 months
Registered November 16, 2004
Enabled
Protects against DNS spoofing
Unknown
2a06:98c1:3109::6812:22f5
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice