Skip to content
https://wpengine.com

Infrastructure

· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
93
GRADE
A
FIX
0
REVIEW
2
PASS
7
INFO
0
Probed from Madrid, Spain
200 OK
Checks
9
7 PASS 2 REVIEW
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
TLS Certificate Expiry & Recommendations
50 days until leaf cert expires — 4 issues to address
REVIEW

Certificate validity

50
days left
0d 30d 60d 90d+

Recommended actions

  • Add includeSubDomains to the HSTS directive
  • Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+
DNS Records
2 A records, 97 ms lookup
PASS
2 A records, 97 ms lookup
Info::
Resolves to 2 IPv4 address(es)
Got: 172.64.150.213, 104.18.37.43
Info::
No IPv6 (AAAA) records
Info::
2 nameserver(s) configured
Got: kara.ns.cloudflare.com, jim.ns.cloudflare.com
Info::
4 mail exchanger(s) configured
Info::
CAA records not checked
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Info::
SPF record present in TXT
Info::
DNS resolution time: 97 ms
Got: 97 ms
A172.64.150.213, 104.18.37.43
AAAA
CNAME
NSkara.ns.cloudflare.com, jim.ns.cloudflare.com
MX
1 aspmx.l.google.com
5 alt2.aspmx.l.google.com
10 aspmx3.googlemail.com
10 aspmx2.googlemail.com
TXT
_nrmjrlkwyszgkqbmfx81licw2kmxzow
docker-verification=3273bf3c-471f-4ac7-a2f4-df07ad1b8d48
canva-site-verification=_WIxJdNmxl6VqSBYyDjUCA
google-site-verification=B-Btjk-77YDTHz9oAG-Mh0DO2Vm-rTeJQN5KGYxsFus
google-site-verification=M6hOtehJSoyxeogONWn71iYsV-R45rZh3IYATuc1roc
1fnhf0prfq7z2044j8r9x3sk9zf8g633
c4fmy14y8y7dtbnwtpw1cmr1503g64c4
apple-domain-verification=eZxVv8GkPbj1emuV
g9wc23jgjsscsxqxz3h5trypft90rjd4
adobe-idp-site-verification=1ddcce3ad118fce5e72e9e3800b13b44a6dcadd28796cfc1b8bd...
t7935hqjxrbsg6lhvxpymqwhzx3wz32t
jamf-site-verification=Fd2Vp7x-bxVmqwiUtnW8AA
MS=ms46413913
wrr2q64mqr7jrxqjzt6qflq2d89d391s
cnjvqz73kch4r7hkz8fgxs4198vxbbjl
miro-verification=a53d6fe59bd5411e3df40b35f894611817d07e6d
drift-domain-verification=a3cdeb0f82279fd70b4bad1f5a8350e515feca6d93aef93c6e0fcd...
cursor-domain-verification-qapwwg=q7ruwFAUovUbr3VxoCRxzDBzh
6y4l59sk7n7wbbhsdggz91kf6wts19dm
google-site-verification=5trLJFGk1-V6eA1Ywp8nCR59bbivFFlugRn7CQj3vAw
SPF v=spf1 ip4:104.18.36.22 ip4:149.72.22.42 ip4:66.102.0.0/20 ip4:74.125.0.0/16 ip4...
google-site-verification=IEo383bwWgfkCwftM0janzuymSRM46MJ3kKMpAQ8xu8
insomnia-validation=92e0cc29397b41f0ba8bbf3767bf71a07ba2763175e1574b8257f93459f3...
parsec-domain-verification=td_35c3hwTUWMNyoi44MRaKrojoo6w
zapier-domain-verification-challenge=33cb2c31-3d2e-49fb-b101-3b33d8c47021
docusign=986c4e3e-cb44-497b-9ae3-556c71766145
pendo-domain-verification=da8ec78f-8fd2-4428-a442-9ce65ff01aaa
facebook-domain-verification=6yaak3k1wnwbbc1nsmjv9eht3c58vt
679876c3-ae88-483e-aa5c-f1d0da5b19c9
docusign=1749d088-e0ca-4612-b2fd-6ee7acecd61f
1password-site-verification=NRXXKB5TT5CUJFLNMPYKGDJGOI
CAALookup not available with standard resolver
Resolved in 97 ms

CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.

Why this matters

Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.

A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://wpengine.com

https://wpengine.com

674 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://wpengine.com200674 msHTTP/1.1cloudflare
A+
Crawlability
robots.txt present, sitemap with 12 URLs
PASS
robots.txt present, sitemap with 12 URLs
Info::
robots.txt is present
Got: 2043 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 12 entries
Info::
Sitemap index with 12 child sitemaps
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 2043 B Sitemaps referenced 16 User-agents * Blocking No — crawling allowed
# Routed from 4.0
# Apply to all bots
crawl-delay: 5
User-agent: *

# Block the admin area but allow ajax callbacks
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php

# WEB-3507 Rationale unknown
Disallow: */*/audio/
Disallow: /site.webmanifest

# WEB-5082 Google has a number of junk URLs to both of these paths
Disallow: /solution-center/tag/

# Prevent builder calendar filters to be crawled
Disallow: /*/2023-
Disallow: /*/day/
Disallow: /*eventDisplay

# To optimize crawl budget for SEO
Disallow: /*/?__hstc=
Disallow: /*/?utm_
Disallow: /*/?nabe=
Disallow: /*/?print
Disallow: /*/?wtime=
Disallow: /*/?coupon=
Disallow: /*/?wvideo=
Disallow: /*/?_hsenc=
Disallow: /*/?local-download=
Disallow: /*/?_ga=
Disallow: /*/?es_p=
Disallow: /*/?w_agcid=
Disallow: /*/?kaid=
Disallow: /*/?tribe-bar-date=
Disallow: /*/?amp=
Disallow: /*/?fl_rand_seed=
Disallow: /*/?clientId=
Disallow: /*/?budget=
Disallow: /*/?ss-track=
Disallow: /*/?language=
Disallow: /*/?inf_contact_key=
Disallow: /*/?ref=
Disallow: /*/?s=
Disallow: /*/?sa=
Disallow: /*/?a=
Disallow: /*/?p=
Disallow: /*/?_gl=
Disallow: /*/?cid=
Disallow: /*/?o=

# Block 404s coming from other sites (added 6 Nov 24)
Disallow: /page/

# Link to Yoast sitemaps
Sitemap: https://wpengine.com/sitemap_index.xml
Sitemap: https://wpengine.com/builders/sitemap_index.xml
Sitemap: https://wpengine.com/sitemap-au.xml
Sitemap: https://wpengine.com/sitemap-ca.xml
Sitemap: https://wpengine.com/sitemap-dk.xml
Sitemap: https://wpengine.com/sitemap-fi.xml
Sitemap: https://wpengine.com/sitemap-fr.xml
Sitemap: https://wpengine.com/sitemap-gb.xml
Sitemap: https://wpengine.com/sitemap-ie.xml
Sitemap: https://wpengine.com/sitemap-nl.xml
Sitemap: https://wpengine.com/sitemap-us.xml
Sitemap: https://wpengine.com/case-studies/case-studies-sitemap.xml
Sitemap: https://wpengine.com/solution-center/page-sitemap.xml
Sitemap: https://wpengine.com/solution-center/solution-sitemap.xml
Sitemap: https://wpengine.com/support/support-sitemap.xml
Sitemap: https://wpengine.com/resources/sitemap_index.xml

A+
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
PASS
www/non-www, trailing slash, HTTP→HTTPS
Info::
www/non-www redirect configured correctly (preferred: non-www)
Info::
HTTP correctly 301-redirects to HTTPS

www / non-www

301https://www.wpengine.com/
200https://wpengine.com/

Preferred variant: non-www

HTTP → HTTPS

301http://wpengine.com/ https://wpengine.com/

Consistent

A+
Domain Intelligence
wpengine.com — via MarkMonitor Inc., 16 years, 4 months old, hosted on Cloudflare
PASS
wpengine.com — via MarkMonitor Inc., 16 years, 4 months old, hosted on Cloudflare
Info::
Domain registered until Mar 10, 2027 (10 months remaining)
Info::
DNSSEC is not enabled
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Info::
Registrar: MarkMonitor Inc.
Warning::
Registrar lock is NOT enabled
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Info::
Hosting: Cloudflare
Got: AS13335
Domain expiry

268 days

March 10, 2027

SSL certificate

50 days

Issued by Google Trust Services

Domain age

16 years, 4 months

Registered March 10, 2010

DNSSEC

Not enabled

Protects against DNS spoofing

Hosting

Cloudflare

ASN AS13335

172.64.150.213

Registrar

MarkMonitor Inc.

Unlocked 2 NS records
Expiry timeline
Today
+1 year
Domain expiry SSL expiry Danger zone (≤30 days)
Recommended actions
  • Enable DNSSEC to protect visitors from DNS spoofing
  • Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
Registrar MarkMonitor Inc.
Created March 10, 2010 (16 years, 4 months ago)
Expires March 10, 2027 (10 months)
Last Updated February 6, 2025
Name Servers jim.ns.cloudflare.com, kara.ns.cloudflare.com
DNSSEC Not enabled
Hosting
IP Address 172.64.150.213
ASN AS13335 (CLOUDFLARENET - Cloudflare, Inc., US)
Provider Cloudflare
Data source: rdap (0.3s)

DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.

Why this matters

Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.

Learn more

DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.

Source: ICANN / RFC 4033

The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.

Why this matters

Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.

Learn more

Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.

Source: ICANN / domain-security best practice

A
HTTP Probe Timing
Total 795 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
PASS
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
30 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
17 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
22 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
689 ms
Total Time Total request time from DNS lookup through full response.
796 ms

Connection waterfall

DNS Lookup 30 ms TCP Connect 17 ms TLS Handshake 22 ms Server Processing 620 ms Content Transfer 106 ms
A
CDN & Delivery
Cloudflare (DYNAMIC)
PASS
Cloudflare (DYNAMIC)
Info::
Site is served via Cloudflare CDN (edge: CDG)
Got: cf-ray: 9efec6c0494fd142-CDG
Info::
CDN cache status: DYNAMIC
CDN Detected: Cloudflare
Provider Cloudflare Cache Status DYNAMIC Evidence cf-ray: 9efec6c0494fd142-CDG
All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback