Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations129 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records4 A records, 20 ms lookupPASS
| A | 3.168.73.22, 3.168.73.23, 3.168.73.119, 3.168.73.27 |
| AAAA | 2600:9000:2801:1200:e:682f:1700:93a1, 2600:9000:2801:4400:e:682f:1700:93a1, 2600:9000:2801:c200:e:682f:1700:93a1, 2600:9000:2801:8200:e:682f:1700:93a1, 2600:9000:2801:6400:e:682f:1700:93a1, 2600:9000:2801:f800:e:682f:1700:93a1, 2600:9000:2801:f000:e:682f:1700:93a1, 2600:9000:2801:a800:e:682f:1700:93a1 |
| CNAME | — |
| NS | ns-1270.awsdns-30.org, ns-1702.awsdns-20.co.uk, ns-415.awsdns-51.com, ns-572.awsdns-07.net |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt4.aspmx.l.google.com 10 alt3.aspmx.l.google.com |
| TXT | 1password-site-verification=OMZZCX32ABEJFANQJEZIDV24YM MS=ms58603718 YbAMQjB2yzXf6DTU9dR9LYMQNGptykV9gN251w0knS5h2Iu4Nhk9kw6s1nzmgOCFnvxo/lekGs1PSCy3... _varnish-cdn-verify=HDE7KlwrXuRjAf0ZTR6RVI _varnish-cdn-verify=HDE7KlwrXuRjAf0ZTR6RXK astro-domain-verification=cmivtccwb1m0001ndjl1iztiv atlassian-domain-verification=73PL1GfNmV1AxBDVgP2myjKgwuPWrvUuHeM8MOKAOiwPtjVr/G... atlassian-domain-verification=T5IChTF3ZKTnWvAaklZlegxf60QcBh8c11dnQa0rehmgPfEBKr... docker-verification=ab84c6ca-d2b1-4aca-a2b4-e39155b6c1bd fastly-domain-delegation-29tfXEmvnByNT8JY-442665-2021-10-26 google-site-verification=1pgyIHHF6q_XtdnSiBJFZiJrXtcg-vpNdfWzhJtb8pM google-site-verification=CvJrFeKFUvWtMd11AkMfLIwBCKnMr2e4f6dzowPw32A google-site-verification=LyzhGgOsJB-JpC1mIPb_3uHZnrL399W8jgPVrIVJE1U google-site-verification=uRwOU1tXpvCsRXnHyApK_yaMeXiTmni8cIW2KelXWO8 miro-verification=eff9412c1aa1655d0a279f7d6704841b6a02b591 openai-domain-verification=dv-Ch3hqu8uKY999lSI95laAO0X SPF v=spf1 include:_u.vg.no._spf.smart.ondmarc.com ~all wiz-domain-verification=0d1ca40c73f3acaac00205197ba9f96c34b47cf912732aa7eff00097... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 527 ms totalPASS
https://vg.no
394 ms · HTTP/1.1
https://www.vg.no/
133 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://vg.no | 301 | 394 ms | HTTP/1.1 | nginx |
| 2 | https://www.vg.no/ | 200 | 133 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (2 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 269 URLsPASS
# All crawlers and Open AI Search BOT rules
User-agent: *
User-agent: OAI-SearchBot
Disallow: /sok*?*
Disallow: /tegneserier/salesposter
Disallow: /poll
Disallow: /informasjon/redaksjonelle-avgjorelser/182
Disallow: /informasjon/redaksjonelle-avgjorelser/212
Disallow: /preview
Disallow: /?vcheck=1
Disallow: /?_escaped_fragment_=/kategori/144/bolig-tv
Disallow: /?_escaped_fragment_=/kategori
Disallow: /hei
Disallow: /rabattkode/
Allow: /
# Google Bot News rules
User-agent: Googlebot-News
Disallow: /annonsorinnhold/
Disallow: /kommersielt-innhold/
Disallow: /innstikk/
Disallow: /?embed=true
Disallow: /arkiv/
Disallow: /front/
Disallow: /ads/prewarm/
# Start AI crawler block
#
# VG does not permit unlicensed use of our content for training large language models.
# All use, reproductions and extractions of our content for such purposes require specific
# approval by VG. We explicitly disallow text and data mining and other technical means
# designed to or with the effect that they enable unlicensed use of our content for training
# AI models.
User-agent: AI2Bot
User-agent: Ai2Bot-Dolma
User-agent: Amazonbot
User-agent: anthropic-ai
User-agent: Applebot-Extended
User-agent: Bytespider
User-agent: CCBot
User-agent: Claude-Web
User-agent: ClaudeBot
User-agent: cohere-ai
User-agent: cohere-training-data-crawler
User-agent: Crawlspace
User-agent: Diffbot
User-agent: FacebookBot
User-agent: FriendlyCrawler
User-agent: Google-Extended
User-agent: iaskspider/2.0
User-agent: ICC-Crawler
User-agent: ImagesiftBot
User-agent: img2dataset
User-agent: Kangaroo Bot
User-agent: Meta-ExternalAgent
User-agent: omgili
User-agent: omgilibot
User-agent: PanguBot
User-agent: PerplexityBot
User-agent: PetalBot
User-agent: Scrapy
User-agent: SemrushBot-OCOB
User-agent: SemrushBot-SWA
User-agent: Sidetrade indexer bot
User-agent: Timpibot
User-agent: VelenPublicWebCrawler
User-agent: Webzio-Extended
User-agent: YouBot
Disallow: /
# End AI crawler block
# Start Sitemaps
Sitemap: https://www.vg.no/sitemaps/files/articles-48hrs.xml
Sitemap: https://www.vg.no/sitemap.xml
Sitemap: https://www.vg.no/dinepenger/sitemap.xml
# End Sitemaps
- https://www.vg.no/nyheter/i/JOrzJ4/usa-shamar-elkins-31-drepte-barna-sine-i-louisiana
- https://www.vg.no/nyheter/i/43OM1e/brann-i-bygaard-i-oslo-folk-soeker-tilflukt-paa-balkonger
- https://www.vg.no/sport/i/n19pAa/chelsea-clinton-loep-boston-marathon-foreldrene-moette-henne-i-maal
- https://www.vg.no/nyheter/i/zOlq0q/trump-paa-historisk-lavmaal-i-ny-meningsmaaling
- https://www.vg.no/nyheter/i/3p1v40/axios-vance-drar-til-iran-samtaler-i-pakistan-i-dag
A+Domain Intelligencevg.no — via Domeneshop AS, 15 years, 1 months oldPASS
Unknown
129 days
Issued by Amazon
15 years, 1 months
Registered June 10, 2011
Not enabled
Protects against DNS spoofing
Unknown
2600:9000:24f9:bc00:e:682f:1700:93a1
Domeneshop AS
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033