Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations168 days until leaf cert expires — 5 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 143 ms lookupPASS
| A | 74.208.4.76, 74.208.4.77 |
| AAAA | — |
| CNAME | — |
| NS | ns-1and1.ui-dns.biz, ns-1and1.ui-dns.com, ns-1and1.ui-dns.org, ns-1and1.ui-dns.de |
| MX | 10 mxint02.1and1.com 10 mxint01.1and1.com |
| TXT | flexera-domain-verification-cirulrgfuoqjowff cursor-domain-verification-d1n5yf=w2r1ZcAKmOE1LGVfF35tOrP2J canva-site-verification=Mn1rJGJqRy3NFoReL7Hh_Q cDfR2ST6H5gj+ScY8crTs/Dxl832YhRnLkG4TNN7HFqX/e/KA0u9kQy3jnakfN082WY/bg8rf4JS8ZDr... mindmanager-verification=1ea2fdbe5379cc0f8cfe95fa5ecfdc1ff943a7bd015aed8afb5717d... figma-domain-verification=bf994688b54b476ea25cff12b37502eef47a3bad935472aa4fbafa... facebook-domain-verification=b3w01jklxzo2sgze380kki78rwjulw google-site-verification=7id4gRISGXuz1RUhyLwoP_ncZF__hnDd3091L59Zd5Q google-site-verification=Ppm1wKD3IMF3PXA_B1Sd6pOP3ph0zTw8jqGs0rB2ggA MS=ms70624413 kkxiJXqSJtWUZ2/o3eK8DwCBVO9ylNRrevp0TRnhTkjiLoHgAbayf2mjofvur8eHJT6wQA1rx+qzXXGW... google-site-verification=xGX9Zq6QAsl8aJNYJp4d3giTg0Ol78ol9FOYjw7qxAA openai-domain-verification=dv-7zY6w7UZZIx7SY50c3kEOiqV adobe-idp-site-verification=544e1c199daf0cfa42a1fa60cc497471e9b14f4254769aae17f4... xtmjsmgvp2523q5hmg8hc3tfjmj89kc3 b11x9hk35krgqs2f0k7qmwvg5yn9px9l globalsign-domain-verification=75CF0B9D35A5C0889E80EB664D71FC07 sending_domain420932=d1b745ca1571640e1ab0b72bb5a902cd132ba7e11b4b04a2942410b51b4... atlassian-domain-verification=KAEkvhtoErKIDdiyb7e0wzavuISNOteHVzuoJX6M4VNN5REeLH... _m23k7icdi3rylo7yk29qsq0k268bnef docker-verification=35a6b6c2-d734-4c9a-bb4d-06aa17a200c2 lrl3344l5ffgcbmj18nqzq95m1d2xdv9 y3tp0zpnksgdn5yywfgpgdmgj45bh0k9 SPF v=spf1 redirect=_spf-corporate.ionos.com v9jysz1dv845wvtyp95rh7w6p7ysjb57 mwdv5x11l34w7tj9xlgp4tzddgpcbhnw k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDGoQCNwAQdJBy23MrShs1EuHqK/dtDC33... jdwtnsy7h3h8r1b0gctkrcjvg2nq9smk MS=ms74588552 16jqfwnyjzty27xhym9330vd1gghv47j google-site-verification=BWZwAm23uhDORmKCFef9BGOloahl2OQp7KKKaBC9mBE wpnv3wbbchbnlysjtlmmd1tj0jkm21kw anthropic-domain-verification-q686va=63OyRCIjDzlpOJyunsqnZbzQZ tgyghxbsy1jrdsj63yrrwqyjjxdrpnjc browserstack-domain-verification=295b3a4b-fd77-4fdd-b60e-2826eb73e21c ztdc3ky6k5km3ybkws238xd45wm85jhr _cy60bt2y80p02hlbtl45v566ji704fz docusign=ae5f3aad-650b-4569-a7ba-0c6b2788049d pardot420932=5748908f75ee14541f04593acddce2ce132f9b051f849be3ce865d8cf448e9fa vyjbz4kfb2x08kjcpncrc9gfmgj861lw |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 849 ms totalPASS
https://ionos.com
397 ms · HTTP/1.1
https://www.ionos.com/
452 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://ionos.com | 301 | 397 ms | HTTP/1.1 | Apache |
| 2 | https://www.ionos.com/ | 200 | 452 ms | HTTP/1.1 | Apache |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 1027 URLsPASS
Sitemap: https://www.ionos.com/sitemap.xml
User-agent: *
#print
Disallow: /details-print
#terms and conditions
Disallow: /terms-
#Popups etc.
Disallow: /details-
Disallow: /popup
Disallow: /Feature
Disallow: /*-popup$
#Results
Allow: /server-configurator
Disallow: /domaincheckresult
Disallow: /tariffselect
#crawl delay
User-agent: Slurp
Crawl-delay: 300
User-agent: msnbot
Crawl-delay: 300
User-agent: dotbot
User-agent: kinshoo
Disallow: /
A+Domain Intelligenceionos.com — via World4You Internet Services GmbH, 26 years, 6 months old, hosted on IONOSPASS
989 days
March 1, 2029
168 days
Issued by Sectigo Limited
26 years, 6 months
Registered February 29, 2000
Not enabled
Protects against DNS spoofing
IONOS
ASN AS8560
74.208.4.77
World4You Internet Services GmbH
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice