Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BCAA RecordsNo CAA records (any CA may issue certificates)REVIEW
BReverse DNS0/4 IPs match cert SANREVIEW
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations56 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN Cache ObservabilityNo CDN cache-status headers in the responseREVIEW
BOperational Status PageNo status page link detectedREVIEW
A+DNS Records2 A records, 19 ms lookupPASS
| A | 23.33.42.71, 23.33.42.84 |
| AAAA | 2600:141b:1c00:36::17d2:5ca4, 2600:141b:1c00:36::17d2:5ca7 |
| CNAME | — |
| NS | a1-63.akam.net, a3-66.akam.net, a10-66.akam.net, a11-67.akam.net, a24-64.akam.net, a26-65.akam.net |
| MX | 10 dr-dk.mail.protection.outlook.com |
| TXT | MS=ms13518666 5j3r5r4qz56m68tqpr2791w1dzn1j8fq 66856f972vn9ppljm1s4kbk8v68sfj19 6xv24v70jr68ywwfjhbd0lrpnz32dfmj 7xb94tlv6xcqd7tl6wswngqk7815xjw2 _3gp0pfi8dzfn91wt7may7dxfywj92mp _jtpqow30et1z58y3nmdd3u2x1pyepro _tnxvfsg87yv1b8h5ovakt73gw9o1fd6 _uhq86kwgk9rv1esrwn7v5cv47vqczxp _xkd4jht5zhwtyxii1fw8t38k80bdvi9 f72mdk7mbxbv9zqd3r3knffbf6csk0k8 nys7zf0jc9m9n4tdvc6qcbwtjylrq02c rb9r1d02qpz0vg0lzgr8fbrgq5mmrhlt sb24x5tzscpnz43dl18ww9yff4yl7wsk sklpgg9g1zqyhn2nr28ly5hvlf28yc7t vs8m767qqwyq5s7c93710t40r19nxw35 w59vx836v760xcnpyhm5v40dk35y5s9s z8dhs315ydpp3jnqnb8dsq6yyf4zt9y3 zk6rl2rplmv14gwmc9hn6dpkyxxz7zzg dropbox-domain-verification=vfbykpvh1hfe 7MhXFXitgLg9kT1mUZKq/XaBwFSuYbzi/ithxjxNmik= xDhOdtwBdIMPyEOc/+AO32l/q0D7uv/N6Du4aRJEiGM= jamf-site-verification=cNKkwaQuXMDHsQg-XCPjaw bw=hDOdQC0nqFCY9/u1cmCZoF7f06Z2qEpM4a25pXZJeVV1 amazonses:ZYfeeKBs7Rvv7CZzNNRG45m47kTC/AX8PQiJwb2bMLQ= mongodb-site-verification=yhnAdynSmrN2Pe8OlZNt0W7gwMk9gg1b segment-site-verification=0KTW3TLgT5fOd41jrtLczJbrYDHGD0JL mixpanel-domain-verify=499ed8ee-cf8b-4158-89b6-fe536140ca93 teamviewer-sso-verification=f4204d89b9f3461296c2c15789ec6df5 anthropic-domain-verification-jtr46m=6oZ17UOEEASl5vxt26SoHY4Qb adobe-idp-site-verification=7f32e0b0-b088-4a47-82f4-a61aa2134ab9 google-site-verification=5ZwZRd__Hulm5hw7-8oMeV30ED66vLZcvnSiRemoqRw google-site-verification=6Ng60nC6s3sFw6wW1Yfd_KNin9C7Phlsh6WMZWGsEeA google-site-verification=7jYezkQTsdoWUAstoxlYvxnRxDDAqgVnoQT7YWJtGxE google-site-verification=AQ0fCr9IethCjZL_y72zXFkATbSovBs8OF1iHxbh3qY google-site-verification=Fxxz_p0Fq_OdYF2z-6_JBH3zfWSR-Q91DoRqkn_llR0 google-site-verification=WdHD_OjNWRViXSvPThSHynaZLQgv-C4lQ32Q-nSXvLo google-site-verification=WqMImrxRQ4kQx8PF0D-Ch7P2JK2TT6Fd4i_Tjm3O304 google-site-verification=dYs1jtngQb_MXBSUU_sW49oFrtHAUw9ZrSUcdqaKYbQ google-site-verification=frmI5FkuXAcKe39yVb6s3aZsXt9lkM0A1sDCRWwkgoo google-site-verification=iGF5KVqi50rehOOgHqeS0kEe8ok6AWGsAA6xfnGggTA google-site-verification=taQR3GYtNHlEhe2L2yGTUvPCXWzv1QeYKIpgTkCOgag _globalsign-domain-verification=cKxrPxxbe9GiCDtUSwr2GfctgIkrQIlcRNJyCG2KpR intersight=721d94ae60c79715b227cbb6da696cb8d416a08a6b9564f5c58ffabacbb4ada4 6cqLXtWJi5+1z7hXz3W4sIPiY/MCdU8eu73HAdqgSxljFN2kT2aBIoxf59pdZbc2vG63NqW/4pg5KsTO... atlassian-domain-verification=1BPhIxzpqtA+7LxDw2OBD0Yv3XZ99GX8rdNnzfOatdo1QQModq... figma-domain-verification=3ee8648d228a537cb059d44866821d8b613f144974a7fe41a3300e... SPF v=spf1 ip4:195.137.194.1/24 ip4:52.28.56.226 ip4:52.28.45.240 ip4:52.16.224.164 ... |
| CAA | Lookup not available with standard resolver |
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
A+DNSSECSigned and validatingPASS
A+Multi-Resolver DNS SpeedMean 5ms across 3 resolvers (spread 7ms)PASS
ARedirect Chain1 redirect(s), 428 ms totalPASS
https://dr.dk
164 ms · HTTP/1.1
https://www.dr.dk/
264 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://dr.dk | 301 | 164 ms | HTTP/1.1 | |
| 2 | https://www.dr.dk/ | 200 | 264 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (2 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 2 URLsPASS
Sitemap: https://www.dr.dk/sitemapindex.xml
User-agent: GPTBot
Disallow: /
User-agent: ChatGPT-user
Disallow: /
User-agent: Google-Extended
Disallow: /
User-agent: Google-NotebookLM
Disallow: /
User-agent: Gemini-Deep-Research
Disallow: /
User-agent: OAI-SearchBot
Disallow: /
User-agent: CCbot
Disallow: /
User-agent: anthropic-ai
Disallow: /
User-agent: Claude-Web
Disallow: /
User-agent: ClaudeBot
Disallow: /
User-agent: Claude-User
Disallow: /
User-agent: Claude-SearchBot
Disallow: /
User-Agent: omgili
Disallow: /
User-Agent: omgilibot
Disallow: /
User-agent: PerplexityBot
User-agent: Perplexity-User
Disallow: /
User-agent: DuckAssistBot
Disallow: /
User-agent: DeepSeekBot
User-agent: DeepSeek
Disallow: /
User-agent: Amazonbot
Disallow: /
User-agent: Amazonbot-Video
Disallow: /
User-agent: Applebot-Extended
Disallow: /
User-agent: Applebot
Disallow: /
User-agent: Bytespider
Disallow: /
User-agent: cohere-ai
Disallow: /
User-agent: Timpibot
Disallow: /
User-agent: YouBot
Disallow: /
User-agent: Brightbot 1.0
Disallow: /
User-agent: FirecrawlAgent
Disallow: /
User-agent: PetalBot
Disallow: /
User-agent: MistralAI-User
Disallow: /
User-agent: VelenPublicWebCrawler
Disallow: /
User-agent: wpbot
Disallow: /
User-agent: iAskBot
Disallow: /
User-agent: PanguBot
Disallow: /
User-agent: meta-externalagent
Disallow: /
User-agent: Ai2Bot-Dolma
Disallow: /
User-agent: ZanistaBot
Disallow: /
User-agent: *
Disallow: /beta/
Disallow: /bonanza20_assets/
Disallow: /kgf
Disallow: /kgf/
Disallow: /tjenester/share/
Disallow: /tjenester/esi
Disallow: /l/
Disallow: /nav/tekstttv/
Disallow: /NR/exeres*
Disallow: /nyheder/webdok/*/zone/*
Disallow: /P3/find/
Disallow: /programoversigttiltryk
Disallow: /staging/
Disallow: /stage/
Disallow: /Templates/
Disallow: /test/
Disallow: /login/
Disallow: /search/*
Disallow: /soeg/*
Disallow: /drtv/soeg*
Disallow: /lyd/programmer?q*
Disallow: /cgi-bin/fttx1.exe/
Disallow: /dr-laer/mediebiblioteket/
Disallow: /download/Forside/2021/
Disallow: /download/Forside/2022/
Disallow: /nyhedsbrev/
Disallow: /undervisning_flash/
Disallow: /auth/
Disallow: /mad/opskrift/soeg?query
A+Domain Intelligencedr.dk — 28 years, 7 months oldPASS
308 days
March 31, 2027
56 days
Issued by Let's Encrypt
28 years, 7 months
Registered March 11, 1998
Status unknown
Protects against DNS spoofing
Unknown
2600:141b:1c00:36::17d2:5ca4
Registrar unknown
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice