Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DHTTP Probe TimingActionTotal 2171 ms — DNS, TCP, TLS, TTFB, content transfer breakdownFIX
Connection waterfall
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BRedirect Chain1 redirect(s), 4987 ms totalREVIEW
https://globo.com
2169 ms · HTTP/1.1
https://www.globo.com/
2818 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://globo.com | 301 | 2169 ms | HTTP/1.1 | |
| 2 | https://www.globo.com/ | 200 | 2818 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations46 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
ADNS Records1 A records, 3644 ms lookupPASS
| A | 186.192.83.12 |
| AAAA | — |
| CNAME | — |
| NS | ns01.globo.com, ns02.globo.com, ns03.globo.com, ns04.globo.com |
| MX | 32456 smtp.globo.com |
| TXT | _lh5u6ritt1fvq2eptlz8lfqoiwlbq6x _jxp8mhot5kd0yo72fkdnpopigtgp80h _aoez9hdge3rvhzsd4dg1f39iz95ha6i _4cdysw6n8ict420x0us2860aww1vp5f _0k100ojg2pcgwlzw3kxrc4qk18856jk _e5l2d5fdi0jbsoqrlzbclzr7qusrea6 _eraaupu3n4sn8eg9bcb5rk6dumommmo _b0a5n7fqyul67mfgw7kbxplh0128utl _x8y1baflfvadw4650oad6x7xbt8cua6 _43lhaqzj27trs0amukxx7adwa8jpxoa _fnbzhgtaw1lse1wplvqlvwc1q42aoe3 _42jgwo3ee57tyuvei51bvlizbyq3jcs _k03e1z8tkeuifmxgjk3398xhoaweo8u _vm0n1it67i2wiwdz9p07b0wf7do1mls _sziem69s3sgtzcpofrb7jinhsnvmvgp google-site-verification=4FnIz3QNnlETp_eOz7M5skXnoQO5tvv3gX1rCNn5Zag _dhxhi7sr2utg4c3cy7525ymyvfvmaff _y0awmt7u8bz3ksr8g9wyurbvp1eb8cx _axmsu1xm79iz1uqfuz4v7p5ij566cc2 _lmokx13u9acbcnonhj50wo3q4sm4kaq _dl6e79my3aueq18nyf5ejnizuzttee7 _w1cwadocrn628owited8yjc7l0g51wd _glsvprckhi3azkrwcxxs1wrz83gschd _exbwr08lj80h0kkkrizp3pw2cexnv7l _tflf7u5bqmb3ybu8ei38d779cdou12e facebook-domain-verification=az0i8tu9502l8fbi1usht04qdsjn4m _4mw53q8j6e9iq1h8s1olxommeunvs2u _c7n01n6e1949au4zfb21vwdbvlgvp1n _9av03gskqgzeeft0884tezamok0tu0y _uhci19e4aemirbxpi712zzuhvnbm3aq _o3pc0p26fy10lio215ka99vfpidy63f _d05km4loz4jndi9e4r42nxzrw5tl6mt _1eubvxaqfo79tt540zk1j684vycmyne _3m5ueoc5yk81xywtvx6thx1dviylh9c _d6e80svfkh348kmopt1bld56ztb6zb1 _9ch6029hmpmktqy08dif8sfmrvkt99n _0dkmux5lxaepe5045ikhuy6g1wvxqwr _hgpe7qjmz28v33dksvy3khq1v3tj46h _gsm24sali25whkd0qlo32r3s69zd8v5 _zuw5j70fygpe6z3lk8i9ta7xwy6iw2z _485q27majjuq1fpqpqex1wiqh3lal3k _w9zmpfkhceoloiw0iocv3pm0ab67qzk google-site-verification=6LARWGFe1P3xHhGi10Scl7GzwyP3-tIapXSvE4tUxE8 _574q01w7ny3sjip9wckaf5uo0n0v1ja _p66dr9xql756uovb9qwp03fksfwsckr _xnopa6rdei6rdz1d7slx6gdbn2noaq7 _peexjfskh95hl6f6nl4n3wn4wd9q84j _gpjfpbv63ai6z7dph8dtnytven4utsw MS=ms72811081 _o7bcdtl7fhvodl7rxp10ufugfhavqon _3h826n231tcxt8lti0yvaal4hiczqb2 _l3v535s4b5mo68ym6x35764220m56e6 _aee8rfyz5criv42yqby46t0822uks84 _yxaukc4a5tj0ozh5pdij5eoz65q22on _llmq75jsmusu1tcuneqptphw4m4z2sg _t9pgu3nligsecdg9z333m4zpnghxto3 _ixtn00x6em6x74mfo8cowgjvq3q7a8t _pf2szieeah5ebdmog2tqgpe1w47vsmt _yjraw7s2cfn3pi38bss2fgtrny5k0eu _z1xtlcjsbf88ifvyb7h77mq039dn2bq _3qehk8d3b403sidaidjx57w7vx4i8x5 _s1cccq6h1pxyf2s35gq4torqbu0hh4e _fl3hfmrfc8voc17vr6r8v3go73hzoli _ro5ou01dg1ae2nkx9zm0b7i1bbc9n43 SPF v=spf1 ip4:201.7.188.128/26 include:_gl1.globo.com include:_lw1.globo.com includ... _uwzmykot109essrlgskmqzu51uj6cuo _s1xv8ye231wt8c5rn1x7fsld4j6px1c _6u5fdr5yg15ujwx8h9fuj7who7xixx3 _xhb8sytaiblgxi5rq4n4sxa6lexsmsv _rrfv3s9lik3g4p0dd31ih5ev5pbzfi1 _sahxy1pqtcag9372tbp4clj4pqwm6iv _b7npqt83nrqwve8ne60o5dh6eb3mdbw _d4nrkt58uk249z9m615oa13cjutc030 _z9kcjd8vme06dsplt06u1ay1rzgad4u google-site-verification=PaYFJwINcUruUkgNnJZur41Ir_MuN8GuVkhJHEees-g _jrk1ph235untlkzitpbh4lqm2jilvz6 _noglalltl40avaqgswc0upqqndezw60 _tl3wquii8pi001xnmqizfywuy9vbjkv _px38ox64fzcr5k3j92u1h4kggi79m9c _68oy2gy750yvfuvcd151ea48dxbgxie _2x2vi75zpd099r8xmzbsukucrz1cktt _9g53qw0mkxv5tjcvve827j2g0ka8y5h kwennmfrzkwjw73kanzyrzgmnumqd8e _zkex77dhqb3ndwrpwjezfns2lfye85a _upkgynkc03d4dg2g0vzl7fwyxba5503 _po0aw8w15hdt641is1kbke5vvdxp4zt _3lx6nxtco60a1bgmr839812tbrj9nyq _mbta3mveretx4m1f4tjyd2ttamg1llj _m8nn1kyn6jp30n1f99wz8atdt5adluy google-site-verification=cHjvy0telLWqDbzDa6SgRm9Mr8UO1trDYvyPk0Av_S4 _a18c6tolrevdubeynathtltrd3rawou _0hhrx6os66sxrw29vpjinu70qh1blfi _wde9v2lwlq5sbni10tiu1gc5a9xb1uz _4kso45y242jvnbo44yqyo4z3lcciqjc _9xf7hvj4616jkixrt5s909zh4qjwtyt |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
Slow DNS adds latency to every page load. Consider a faster DNS provider.
DNS resolution is slow — anycast DNS providers (Cloudflare, Route 53) typically resolve <50ms globally.
Source: DNS performance benchmarks
A+Crawlabilityrobots.txt present, sitemap with 1 URLsPASS
#
# robots.txt
#
User-Agent: *
Disallow: /busca/
Disallow: /beta/
Disallow: /historico-home/
Disallow: *globo-cdn-src/*
Disallow: /alt-a/
Disallow: /alt-b/
Disallow: /alt-c/
Disallow: /alt-d/
Disallow: /recomendado/
Disallow: /explore/
Sitemap: http://www.globo.com/sitemap-image.xml
######
User-agent: CCBot
Disallow: /
User-agent: GPTBot
Disallow: /
User-agent: Google-Extended
Disallow: /
######
- https://www.globo.com/
- https://s2.glbimg.com/7-g5T7bMnViHzh_4Zh-hkru6ZWQ=/0x120:1998x1326/927x560/i.s3.glbimg.com/v1/AUTH_bc8228b6673f488aa253bbcb03c80ec5/internal_photos/bs/2021/v/P/xfchGsSnyz0lAVnjlPNg/rib4224.jpg
- https://s2.glbimg.com/igHyCvBMMWXYbOkiq44dwH8WU-s=/11x0:750x415/398x224/i.s3.glbimg.com/v1/AUTH_59edd422c0c84a879bd37670ae4f538a/internal_photos/bs/2021/A/M/WFLscYS2yNBxE7rjHYlQ/resgate-afogamento-penha.jpg
- https://s2.glbimg.com/eXrWtIBDZmi-KVbRJeb8eeWenag=/345x42:720x297/293x200/i.s3.glbimg.com/v1/AUTH_59edd422c0c84a879bd37670ae4f538a/internal_photos/bs/2021/t/z/mZbkq4QmmjM8QtvOarcQ/whatsapp-image-2021-01-20-at-15.jpg
- https://s2.glbimg.com/16fsFmqKHQyOJhKNhGh9WL3I7Zs=/90x0:543x309/293x200/i.s3.glbimg.com/v1/AUTH_59edd422c0c84a879bd37670ae4f538a/internal_photos/bs/2021/P/4/DgBImYT1eOdExzFGm2eA/general-miotto.jpeg
A+Domain Intelligenceglobo.com — via 1API GmbH, 27 years, 8 months old, hosted on Globo Comunicacao e Participacoes SA, BRPASS
126 days
December 21, 2026
46 days
Issued by Let's Encrypt
27 years, 8 months
Registered December 21, 1998
Not enabled
Protects against DNS spoofing
Globo Comunicacao e Participacoes SA, BR
ASN AS28604
186.192.83.12
1API GmbH
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice