Skip to content
https://Cocinaldia.es

Infrastructure

· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.
SCORE
85
GRADE
B
FIX
1
REVIEW
9
PASS
6
INFO
1
Probed from New York, United Stated
200 OK
Checks
17
6 PASS 9 REVIEW 1 FIX
D
CDN & Delivery
Action
No CDN (document or assets)
FIX
No CDN (document or assets)
Warning::
No CDN (document or assets)
Neither the HTML document nor the page's subresources are served through an edge network. A CDN can significantly improve load times for users around the world by caching content at edge nodes closer to them.
No CDN (document or assets)

Consider using a CDN to improve global delivery speed and reduce origin load.

B
DNSSEC
Unsigned (DNSSEC not deployed)
REVIEW
Unsigned (DNSSEC not deployed)
Info::
DNSSEC is not deployed
The zone is not DNSSEC-signed. Users on validating resolvers (Cloudflare 1.1.1.1, Quad9 9.9.9.9, growing default in mobile resolvers) get no protection against DNS spoofing for this domain. Most registrars now offer DNSSEC at a single click; consider enabling it for sites where authenticity matters (banking, healthcare, government).
B
CAA Records
No CAA records (any CA may issue certificates)
REVIEW
No CAA records (any CA may issue certificates)
Info::
No CAA records published
Without CAA records, any publicly-trusted CA can issue certificates for this domain. Adding a CAA record (`yourdomain. IN CAA 0 issue "letsencrypt.org"`) restricts issuance to CAs you authorize. Required by CAB Forum baseline since 2017; the default of 'any CA' is widely supported but is the broader attack surface for issuance fraud.
B
Reverse DNS
0/1 IPs match cert SAN
REVIEW
0/1 IPs match cert SAN
Info::
PTR for 82.98.171.200 does not match any cert SAN: hl1420.dinaserver.com
Common when behind a CDN or shared hosting (PTR points at the provider's hostname). Mismatch can also affect mail deliverability if this IP sends email -- many MTAs reject mail when forward+reverse DNS disagree.
C
IPv6 Readiness
Action
No IPv6 support
REVIEW
No IPv6 support
Info::
No IPv6 (AAAA) records found
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No IPv6 Support
About 40% of internet users have IPv6. Consider adding AAAA records.

IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.

Why this matters

No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.

Source: Google IPv6 stats

B
URL Variants
www/non-www, trailing slash, HTTP→HTTPS
REVIEW
www/non-www, trailing slash, HTTP→HTTPS
Critical::
HTTP version does not redirect to HTTPS
Got: HTTP 429 Expected: 301 redirect to HTTPS

www / non-www

https://www.Cocinaldia.es/
200https://Cocinaldia.es/

HTTP → HTTPS

429http://Cocinaldia.es/

HTTP version does not redirect to HTTPS

B
HTTP Probe Timing
Total 1315 ms — DNS, TCP, TLS, TTFB, content transfer breakdown
REVIEW
DNS Lookup DNS Lookup — time to resolve the domain name to an IP address.
27 ms
TCP Connect TCP Connect — time to establish a TCP connection to the server.
85 ms
TLS Handshake TLS Handshake — time to complete the HTTPS encryption handshake.
89 ms
Time to First Byte Time to First Byte — how long the server takes to respond with the first byte of data.
1.31 s
Total Time Total request time from DNS lookup through full response.
1.32 s

Connection waterfall

DNS Lookup 27 ms TCP Connect 85 ms TLS Handshake 89 ms Server Processing 1.11 s Content Transfer 2 ms
B
TLS Certificate Expiry & Recommendations
79 days until leaf cert expires — 3 issues to address
REVIEW

Certificate validity

79
days left
0d 30d 60d 90d+

Recommended actions

  • Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
  • Enable DNSSEC on your domain for DNS spoofing protection
  • Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
B
Operational Status Page
No status page link detected
REVIEW
No status page link detected
Info::
No operational status page link detected
Status pages communicate planned maintenance and incidents to users -- a hallmark of operationally-mature services. Most SaaS teams publish one via Atlassian Statuspage, Instatus, BetterUptime, or a self-hosted Cachet. Smaller sites legitimately don't need one; flagged as Info, not a failure.
B
Health Check Endpoint
No conventional health endpoint found
REVIEW
No conventional health endpoint found
Info::
No conventional health endpoint found
Health endpoints (/health, /healthz, /status, /ping, /api/health) let uptime monitors, load balancers, and orchestration systems (Kubernetes, ECS, Fly.io) verify the service is alive. Marketing sites and small services often skip them legitimately; flagged as Info, not a failure. Probe results: /api/health: connection error, /health: connection error, /healthz: connection error, /ping: connection error, /status: connection error.
A+
DNS Records
1 A records, 21 ms lookup
PASS
1 A records, 21 ms lookup
Info::
Resolves to 1 IPv4 address(es)
Got: 82.98.171.200
Info::
Single A record — no DNS redundancy
Multiple A records provide failover if one server goes down.
Info::
No IPv6 (AAAA) records
Info::
4 nameserver(s) configured
Got: ns3.gestiondecuenta.com, ns4.gestiondecuenta.com, ns.gestiondecuenta.com, ns2.gestiondecuenta.com
Info::
1 mail exchanger(s) configured
Info::
SPF record present in TXT
Info::
DNS resolution time: 21 ms
Got: 21 ms
A82.98.171.200
AAAA—
CNAME—
NSns3.gestiondecuenta.com, ns4.gestiondecuenta.com, ns.gestiondecuenta.com, ns2.gestiondecuenta.com
MX
10 mail.Cocinaldia.es
TXT
SPF v=spf1 a mx ~all
CAALookup not available with standard resolver
Resolved in 21 ms

Multiple A records provide failover if one server goes down.

Why this matters

Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.

Learn more ▾

Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.

Source: SRE practice / DNS architecture

A+
Subdomain Takeover
No subdomain takeover risk detected
PASS
No subdomain takeover risk detected
Info::
No CNAME record present
A
Multi-Resolver DNS Speed
Mean 65ms across 3 resolvers (spread 99ms)
PASS
Mean 65ms across 3 resolvers (spread 99ms)
Info::
Cloudflare: 2ms
Got: 2ms via 1.1.1.1:53
Info::
Google: 92ms
Got: 92ms via 8.8.8.8:53
Info::
Quad9: 101ms
Got: 101ms via 9.9.9.9:53
A+
Redirect Chain
No redirects — direct access
PASS
No redirects — direct access
Info::
No redirects — direct access
Got: https://Cocinaldia.es

https://Cocinaldia.es

751 ms · HTTP/1.1 FINAL

#URLStatusTimeProtocolServer
1https://Cocinaldia.es200751 msHTTP/1.1HTTPd
A+
Crawlability
robots.txt present, sitemap with 1 URLs
PASS
robots.txt present, sitemap with 1 URLs
Info::
robots.txt is present
Got: 115 bytes
Info::
sitemap.xml is present
Info::
sitemap.xml is valid XML
Info::
sitemap.xml contains 1 entries
Info::
Sitemap index with 1 child sitemaps
Info::
robots.txt references sitemap
robots.txt 200 OK
Size 115 B Sitemaps referenced 1 User-agents * Blocking No — crawling allowed
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
sitemap: https://cocinaldia.es/sitemap_index.xml
sitemap.xml 200 OK
Type Sitemap Index URLs 1 entries Valid XML Yes
A+
CDN Cache Observability
Cache state: fresh (Age=0)
PASS
Cache state: fresh (Age=0)
Info::
CDN cache state observable via 1 header(s)
Got: age=0
Domain Intelligence
Domain intelligence data not available
INFO
Domain intelligence data not available

RDAP and WHOIS lookup both failed

All checks on this page are automated. Results are estimates - run targeted manual reviews when the score affects a release decision.

Send Feedback