Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations68 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Extend HSTS max-age to at least 31536000 (1 year) to meet the preload list criteria
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 96 ms lookupPASS
| A | 104.19.222.17, 104.19.223.17 |
| AAAA | 2606:4700::6813:de11, 2606:4700::6813:df11 |
| CNAME | — |
| NS | sima.ns.cloudflare.com, chad.ns.cloudflare.com |
| MX | 5 mxa-00543801.gslb.pphosted.com 5 mxb-00543801.gslb.pphosted.com 10 aspmx.l.google.com 50 alt2.aspmx.l.google.com 50 alt1.aspmx.l.google.com 100 aspmx3.googlemail.com 100 aspmx2.googlemail.com |
| TXT | paloaltonetworks-site-verification=341cd8a6c026568fbf2f1d688bd2ab3a93300ac792771... apple-domain-verification=k42cyDihDFgZyDji teamviewer-sso-verification=3c92f68977df46f8a836faf3dee19b1c apple-domain-verification=gkrEgGUVeHhuHMMruqzgVlhai0KyQuU8fFjhDCxRBZg status-page-domain-verification=71jf0xbkm9dv 7baha1sqkqhek96j30iigj5jhj google-site-verification=PCetuilY5Boe-estav7CPomAMy-r1Itp_pkS_w7zlb8 docusign=44e85aef-c293-4280-a57e-c6805015f751 twilio-domain-verification=8cef33ec97d09c8ffd8ca03b2a7ef585 _rj7cydrznqqclu1nvwivn7ci3u67pup sdzzsstffjsvrm1tl6w3vzjhnwnk7w6x stripe-verification=4C074D42C2767E2A9C88645EF9A435F8A6B32AF96C2C0AA8E459842ABBF1... MS=ms89782890 google-site-verification=0BkiWmFJ3j6n9dB155uT7bjYG2W-SvIjaW43B2nVlic facebook-domain-verification=8y8dsk7b387u8fdzhwd38r7918jd61 mixpanel-domain-verify=c76c83bd-b6f1-42d9-a0fc-b9046f981edb segment-site-verification=ymbSTvWR2lTKLIR4Cxtyv1bEQz5ShY9J mongodb-site-verification=3dYblW5pflsGhK9sIKXE02aRNButG7TG 886cc7c2-4930-4e6c-82f7-b749a331f6bf box-domain-verification=bd7e193ce1d8807fc0c92872c1d8ebab1fc8207e9cddd5e2562279f6... cursor-domain-verification-axv2zp=mYKLERga3bfWGVc9QKs4zFEH1 google-site-verification=I7WDPOWEyGgthDtKQo87fedNKpc0HBvj63qimMVfvQU slack-domain-verification=3t9FUgZ4ZU1fSFKsi6RSvcHMatYSJsZ5n6zIQYPT CKO=cli_mbaj5wmc4fpu7gy6arlev3ipsy _x4vbsuduc7he5rma9yk4jq187rqtpqo docker-verification=91d288c2-871b-4e61-ad9b-17dc7a66dded jamf-site-verification=XIIIvRTCj711MkK70OauJA SPF v=spf1 mx ip4:13.228.3.214/32 ip4:166.78.71.191/32 include:sendgrid.net include:... google-site-verification=ZsldpD3RCgz2ntLBhPvWKAsL5uFtgUcxNuP5U0HDNe8 notion-domain-verification=FDuhhiLdG51uQQ069lihmtNg7812kZsCNV3zrF8Trap shopify-verification-code=3qnHrrZ3HBGVPKTMpMgTOja8jUB3oj atlassian-domain-verification=mPIKsb4ANOnJdLnDcm5/XNWhVwAf77WKi84paGU6D1gpB2lKTI... google-site-verification=UmBlyd162v42XnvTlkcyJCcsFVFzbZP1xlqeAF1QrYY google-site-verification=QBNOiaBV-QoDHr_zovE1c1GTZnj4LS0dvSp0LktqXjY miro-verification=57041690cd985a8c994e4fc960e73460e844a257 tverrblc66rfaf718t8nkv3ska _r7ph0jpxjinr0eiyfj2rnxb54691eyc box-domain-verification=bd7e193ce1d8807fc0c92872c1d8ebab1fc8207e9cddd5e256 adobe-idp-site-verification=d1d24ca7de8f48eabcb6db556f51aeb77f354775e863452fee8f... facebook-domain-verification=598suasmwyal84kh3gglgawu4kp26h |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 131 ms totalPASS
https://crypto.com
70 ms · HTTP/1.1
https://crypto.com/es-es
61 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://crypto.com | 302 | 70 ms | HTTP/1.1 | cloudflare |
| 2 | https://crypto.com/es-es | 200 | 61 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
If permanent, use 301 instead.
302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.
Learn more ▾ ▴
Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).
Source: Google Search Central
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 20 URLsPASS
User-agent: waybackurls
Disallow: /
Disallow: /*
User-agent: AdsBot-Google
User-agent: Googlebot
User-agent: AdsBot-Google-Mobile
Disallow: /document/*
Allow: /
Allow: /crm/
Allow: /crm/*
Disallow: /nft/login?*
Disallow: /nft/*?*lang=
Disallow: /nft/*?*editions-mode=
User-agent: *
Disallow: /feed/podcast/
Disallow: /podcast/
Disallow: /podcast/*
Disallow: /miami_moon_gp2024
Disallow: /cdn-cgi/*
Disallow: /cdn-cgi/
Disallow: /levelup-lite
Disallow: /*/levelup-lite
Disallow: /nft/login?*
Disallow: /nft/*?*lang=
Disallow: /nft/*?*editions-mode=
Sitemap: https://crypto.com/sitemap/sitemap-index.xml
- https://crypto.com/sitemap/sitemap-auror...
- https://crypto.com/sitemap/sitemap-unive...
- https://crypto.com/sitemap/sitemap-compa...
- https://crypto.com/sitemap/sitemap-produ...
- https://crypto.com/sitemap/sitemap-event...
- https://crypto.com/sitemap/sitemap-marke...
- https://crypto.com/sitemap/sitemap-resea...
- https://crypto.com/sitemap/sitemap-how-t...
- https://crypto.com/sitemap/sitemap-gloss...
- https://crypto.com/sitemap/sitemap-conte...
- https://crypto.com/sitemap/sitemap-trend...
- https://crypto.com/sitemap/sitemap-bitco...
- https://crypto.com/sitemap/sitemap-mkt-w...
- https://crypto.com/sitemap/sitemap-crypt...
- https://crypto.com/sitemap/sitemap-stock...
- https://crypto.com/sitemap/sitemap-predi...
- https://crypto.com/sitemap/sitemap-in-ap...
- https://crypto.com/sitemap/sitemap-notic...
- https://crypto.com/sitemap/sitemap-trans...
- https://crypto.com/sitemap/news-sitemap....
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencecrypto.com — via Network Solutions, LLC, 33 years, 5 months oldPASS
2882 days
May 7, 2034
68 days
Issued by Google Trust Services
33 years, 5 months
Registered May 6, 1993
Enabled
Protects against DNS spoofing
Unknown
2606:4700::6813:df11
Network Solutions, LLC
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice