Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FIPv6 ReadinessActionIPv6 records exist but unreachableFIX
Having AAAA records but an unreachable server is worse than no AAAA — clients may experience delays before falling back to IPv4.
Advertising IPv6 (AAAA records) without a reachable server means IPv6-preferring clients silently fail every connection.
Learn more ▾ ▴
Modern browsers prefer IPv6 if AAAA exists (Happy Eyeballs algorithm). If the IPv6 server isn't reachable, browsers fall back to IPv4 — but with seconds of added latency per request. Either fix IPv6 reachability or remove the AAAA records.
Source: RFC 8305 (Happy Eyeballs)
DURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSFIX
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
HTTP version does not redirect to HTTPS
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BDNSSECUnsigned (DNSSEC not deployed)REVIEW
CReverse DNSAction0/4 IPs match cert SANREVIEW
BTLS Certificate Expiry & Recommendations157 days until leaf cert expires — 1 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable DNSSEC on your domain for DNS spoofing protection
BOperational Status PageNo status page link detectedREVIEW
BHealth Check EndpointNo conventional health endpoint foundREVIEW
A+DNS Records2 A records, 126 ms lookupPASS
| A | 150.171.27.10, 150.171.28.10 |
| AAAA | 2620:1ec:33::10, 2620:1ec:33:1::10 |
| CNAME | — |
| NS | ns1-204.azure-dns.com, ns2-204.azure-dns.net, ns3-204.azure-dns.org, ns4-204.azure-dns.info, dns1.p09.nsone.net, dns2.p09.nsone.net, dns3.p09.nsone.net, dns4.p09.nsone.net |
| MX | 10 bing-com.mail.protection.outlook.com |
| TXT | facebook-domain-verification=09yg8uzcfnqnlqekzsbwjxyy8rdck7 google-site-verification=OkRY8R261shK5B8uEwvsFZp9nQ2gRoHavGlruok1azc google-site-verification=SHuSHN0Hv3nwBI9So329KwfbQ7xLif64SRwcGSdWNAU v=msv1 t=6097A7EA-53F7-4028-BA76-6869CB284C54 SPF v=spf1 include:spf.protection.outlook.com -all |
| CAA | Lookup not available with standard resolver |
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
ACAA Recordsissue: digicert.com, globalsign.com, microsoft.comPASS
A+Multi-Resolver DNS SpeedMean 0ms across 3 resolvers (spread 1ms)PASS
ARedirect Chain1 redirect(s), 133 ms totalPASS
https://bing.com
44 ms · HTTP/1.1
https://www.bing.com:443/?toWww=1&redig=...
89 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://bing.com | 301 | 44 ms | HTTP/1.1 | |
| 2 | https://www.bing.com:443/?toWww=1&redig=... | 200 | 89 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 12 URLsPASS
User-agent: msnbot-media
Disallow: /
Allow: /th?
User-agent: Twitterbot
Disallow:
User-agent: *
Disallow: /academic/profile
Disallow: /academic/search
Disallow: /account/
Disallow: /aclick
Disallow: /alink
Disallow: /amp/
Allow: /api/maps/
Disallow: /api/
Disallow: /bfp/search
Disallow: /bing-site-safety
Disallow: /blogs/search/
Disallow: /ck/
Disallow: /copilotsearch?q=
Disallow: /cr$
Disallow: /cr?
Disallow: /entities/search
Disallow: /entityexplore$
Disallow: /entityexplore?
Disallow: /fd/
Disallow: /fun/api/
Disallow: /fun/g/
Disallow: /history
Disallow: /hotel/reviews?
Disallow: /hotels/search
Disallow: /HpImageArchive.aspx
Disallow: /hpm
Disallow: /hpmob
Disallow: /images/async/?
Disallow: /images/async?
Disallow: /images/hosted/?
Disallow: /images/hosted/search?
Disallow: /images/hosted?
Disallow: /images/search%3F
Disallow: /images/search%5C
Disallow: /images/search/?
Disallow: /images/search?
Disallow: /images/searchbyimage
Disallow: /images?
Disallow: /inboxcommerce
Disallow: /local
Disallow: /maps/adsendpoint
Disallow: /merchant/reviews?
Disallow: /notifications/
Disallow: /offers/proxy/dealsserver/api/log
Disallow: /offers/proxy/dealsserver/buy
Disallow: /ping
Disallow: /product/reviews?
Disallow: /profile/history?
Disallow: /proFile/history?
Disallow: /Proxy.ashx
Disallow: /results
Disallow: /rewardsapp/
Disallow: /search
Disallow: /Search
Disallow: /settings
Disallow: /shenghuo
Allow: /shop$
Allow: /shop/
Disallow: /shop/collections
Disallow: /shop/productpage
Disallow: /shop/topics
Disallow: /shop?*
Disallow: /social/search?
Disallow: /spbasic
Disallow: /spresults
Disallow: /static/
Disallow: /th$
Disallow: /th?
Disallow: /translator/?ref=
Disallow: /travel/api
Disallow: /travel/css
Disallow: /travel/flight/flightSearch
Disallow: /travel/flight/flightSearchAction
Disallow: /travel/flight/search/?
Disallow: /travel/flight/search?
Disallow: /travel/flights
Disallow: /travel/flight-search
Disallow: /travel/hotel/hotelMiniSearchRequest
Disallow: /travel/hotel/hotelSearch
Disallow: /travel/hotels/checkout
Disallow: /travel/hotels/detail
Disallow: /travel/hotels/search/?
Disallow: /travel/hotels/search?
Disallow: /travel/hotel-search
Disallow: /travel/scripts
Disallow: /travel/secure
Disallow: /url
Disallow: /videos/browsing
Disallow: /videos/explore
Disallow: /videos/favorites
Disallow: /videos/feed
Disallow: /videos/music
Disallow: /videos/trending
Disallow: /widget/cr
Disallow: /widget/entity/search/?
Disallow: /widget/render
Disallow: /widget/snapshot
Disallow: /work
Sitemap: https://www.bing.com/sitemap.xml
- https://www.bing.com/home_sitemap.xml
- https://www.bing.com/travelguide/sitemap...
- https://www.bing.com/sitemap/shop/sitema...
- https://www.bing.com/images/feed/sitemap...
- https://www.bing.com/images/create/sitem...
- https://www.bing.com/api/maps/mapcontrol...
- https://www.bing.com/visualsearch/sitema...
- https://www.bing.com/maps/sitemap.xml
- https://www.bing.com/copilotsearch/sitem...
- https://www.bing.com/tools/sitemap.xml
- https://www.bing.com/ai/sitemap.xml
- https://www.bing.com/forbusiness/sitemap...
A+Domain Intelligencebing.com — via MarkMonitor Inc., 30 years, 9 months oldPASS
248 days
January 30, 2027
157 days
Issued by Microsoft Corporation
30 years, 9 months
Registered January 29, 1996
Not enabled
Protects against DNS spoofing
Unknown
2620:1ec:33::10
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice