Skip to content
https://fzcars.ir

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
77
GRADE
C
FIX
3
REVIEW
9
PASS
5
INFO
0
Probed from Madrid, Spain
200 OK
Checks
17
5 PASS 9 REVIEW 3 FIX
D
Multi-Resolver DNS Speed
Action
Mean 211ms across 3 resolvers (spread 369ms)
FIX
Mean 211ms across 3 resolvers (spread 369ms)
Info::
Google: 76ms
Got: 76ms via 8.8.8.8:53
Info::
Quad9: 113ms
Got: 113ms via 9.9.9.9:53
Info::
Cloudflare: 445ms
Got: 445ms via 1.1.1.1:53
Info::
High latency spread between resolvers: 369ms (min 76ms / max 445ms)
Wide gap between the fastest and slowest public resolver suggests a geographic anycast issue or an authoritative-server cache problem. Users in different regions will see materially different DNS times.
D
HTTP Probe Timing
Action
Total 2741 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
FIX
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
79 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
2.06 s
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
60 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
2.71 s
Total Time Total request time from DNS lookup through full response.
2.74 s

Connection waterfall

DNS Lookup 79 ms TCP Connect 2.06 s TLS Handshake 60 ms Server Processing 511 ms Content Transfer 27 ms
D
CDN & Delivery
Action
No CDN (document or assets)
FIX
No CDN (document or assets)
Warning::
No CDN (document or assets)
Neither the HTML document nor the page's subresources are served through an edge network. A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN (document or assets)

Consider using a CDN to improve global delivery speed and reduce origin load.

C
DNSSEC
Action
Zone signed but parent has no DS record
REVIEW
Zone signed but parent has no DS record
Warning::
DNSSEC keys published but parent zone has no DS record
The zone publishes DNSKEY records but the registry has not been updated with the corresponding DS record. From a validating resolver's perspective the domain is unsigned. Submit the DS record to your registrar to complete the delegation.
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
C
Reverse DNS
Action
0/2 IPs match cert SAN
REVIEW
0/2 IPs match cert SAN
Info::
PTR lookup failed for 185.143.234.238: lookup 185.143.234.238: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
Info::
PTR lookup failed for 185.143.233.238: lookup 185.143.233.238: no such host
No reverse DNS record set for this IP. Common on bare cloud-VM IPs without provider-side PTR; not a security issue.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
Crawlability
no robots.txt, no sitemap
REVIEW
no robots.txt, no sitemap
Info::
No robots.txt found
robots.txt is optional but recommended. It tells search engine crawlers which pages to index.
Info::
No sitemap.xml found
A sitemap helps search engines discover and index your pages more efficiently.

robots.txt is optional but recommended. It tells search engine crawlers which pages to index.

Why this matters

No robots.txt — crawlers fetch /robots.txt and get 404; not breaking but means default crawl behavior with no directives or sitemap reference.

Learn more

A minimal robots.txt with `User-agent: * / Allow: / / Sitemap: https://example.com/sitemap.xml` covers the basics. Without it, crawlers behave fine but lose the sitemap signal and can't be selectively blocked from crawl-traps.

Source: robotstxt.org

A sitemap helps search engines discover and index your pages more efficiently.

Why this matters

No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.

Learn more

A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.

Source: sitemaps.org / Google Search Central

robots.txt No robots.txt found

No robots.txt found

This is fine for most sites — a missing robots.txt allows all crawling by default.

sitemap.xml No sitemap found

No sitemap found

Adding a sitemap helps search engines discover your pages.

B
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
REVIEW
www/non-www, trailing slash, HTTP→HTTPS
Critical::
Both www and non-www versions serve content
Got: Both variants return 200 Expected: One variant 301-redirects to the other
Info::
HTTP correctly redirects to HTTPS permanently
Got: HTTP 301

www / non-www

200https://www.fzcars.ir/
200https://fzcars.ir/

Inconsistent — duplicate content risk

HTTP → HTTPS

301http://fzcars.ir/ https://fzcars.ir/

Consistent

B
TLS Certificate Expiry & Recommendations
87 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

87
days left
0d 30d 60d 90d+

Recommended actions

  • Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: 404, /health: 404, /healthz: 404, /ping: 404, /status: 404.
A+
DNS Records
2 A records, 149 ms lookup
PASS
2 A records, 149 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 185.143.234.238, 185.143.233.238
Info::
No IPv6 (AAAA) records
Info::
2 nameserver(s) configured
Got: o.ns.arvancdn.ir, i.ns.arvancdn.ir
Info::
No MX records — email not configured via DNS
Info::
No SPF record found in TXT records
SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.
Info::
DNS resolution time: 149 ms
Got: 149 ms
A185.143.234.238, 185.143.233.238
AAAA
CNAME
NSo.ns.arvancdn.ir, i.ns.arvancdn.ir
MX
TXT
CAALookup not available with standard resolver
Resolved in 149 ms

SPF helps prevent email spoofing. Add a TXT record starting with 'v=spf1'.

Why this matters

Without SPF, receiving servers can't validate sending IPs — your domain is easier to spoof in phishing.

Learn more

SPF complements DMARC. Both should be published. SPF records list authorized sending IPs (e.g., `v=spf1 include:_spf.google.com ~all` for Google Workspace). After publishing, verify in Google Postmaster Tools or mxtoolbox.

Source: RFC 7208 (SPF)

A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://fzcars.ir

https://fzcars.ir

566 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://fzcars.ir200566 msHTTP/1.1ArvanCloud
A+
Domain Intelligence
fzcars.ir — hosted on ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
PASS
fzcars.ir — hosted on ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
Info::
Hosting: ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
Got: AS205585
Domain expiry

Unknown

SSL certificate

87 days

Issued by Let's Encrypt

Domain age

Unknown

DNSSEC

Status unknown

Protects against DNS spoofing

Hosting

ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR

ASN AS205585

185.143.234.238

Registrar

Registrar unknown

Lock status unknown 2 NS records
Expiry timeline
Today
+1 year
SSL expiry Danger zone (≤30 days)
Registrar
Name Servers i.ns.arvancdn.ir, o.ns.arvancdn.ir
Hosting
IP Address 185.143.234.238
ASN AS205585 (ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR)
Provider ARVANCLOUD-CDN-IR - Noyan Abr Arvan Co. ( Private Joint Stock), IR
Data source: whois (0.8s)
A+
CDN Cache Observability
Cache state: BYPASS
PASS
Cache state: BYPASS
Info::
CDN cache state observable via 1 header(s)
Got: x-cache=BYPASS
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback