Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations83 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Submit your domain to hstspreload.org to be added to the Chrome preload list
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 19 ms lookupPASS
| A | 199.60.103.65, 199.60.103.165 |
| AAAA | — |
| CNAME | — |
| NS | a9-67.akam.net, a24-64.akam.net, a26-65.akam.net, a5-66.akam.net, a1-158.akam.net, a22-67.akam.net |
| MX | 5 mxb-005c0b02.gslb.pphosted.com 5 mxa-005c0b02.gslb.pphosted.com |
| TXT | zapier-domain-verification-challenge=ab209f91-f279-4b1d-8092-10b85e0eca02 tinfoil-site-verification: 07368c6d6911b8038f617dd518501a5654d5d08a=12c7c6ac968a... northpass-domain-verification=ae825879144ab624ebcda7a08276ee04 docker-verification=aa08f590-81a9-482f-97a8-a8c78d07fe77 docusign=085e7679-8929-4902-96f0-77b5f36ed535 MS=459662B08FE7ABE5CD420C8A0DA91B47F187B31A atlassian-domain-verification=HjhlR3SDqq8UtKGvvXbYPGi4DhIGJv+m+Dz0pgPI2h2XaGUqwc... mongodb-site-verification=0ABzrJtBKQCDqL5XioMeERYPpmZR5NCX kmhttr9bu4pp6vpi78p5l91fsc 1password-site-verification=RHJFOJLIFVDHLEB6XDVGNUTQD4 atlassian-domain-verification=HYtLFBZ74v9/kJSRXvExAUfmlR30L2kE7vr66ADGgF5tOVNCxz... google-site-verification=xoL8bdppyhgtVfkgs4cDeJIoDPQPg8x6C1YQerjksHg Probe.ly=73e000a9-a5df-48a5-a8f6-f4f6cee5e2ad apple-domain-verification=t3JvA54ZdhjAFCq8 anthropic-domain-verification-n9kpp6=x3uODB3u9pluExGeSvnMnNu9D hcp-domain-verification=371d48d56f5582be8b86a87b94ce5f9bc0ae4dae4321c67d4ce49437... openai-domain-verification=dv-ggQyYeYflbMrGNMgDEIIXA1F google-site-verification=3NIJJy8B-jPLKM6_ubj_Q4R7KyMB_8K167-va6Ea7Sg MS=9235921E61AE6D9F1A514BD1562DF6929212AD4A postman-domain-verification=9f619f012c271146a30289c5bf9c4b036fbc3e31ffc644c675de... google-site-verification=iVrwH6-iIeT2rnheK2ocsVTfvLosfanyJ4hEgnFWlHI dropbox-domain-verification=vq0003kxspf2 figma-domain-verification=80c9c654e7c18602ab0d41343f68c94dff3a26d4a3d2ff1fd2f643... adobe-idp-site-verification=5777e7077aa021fff13a14be21f34a2e63cdb5a9fe91bc13995b... ZOOM_verify_eRV87FRgSGeEEEdLh5Js1g atlassian-domain-verification=NaCxqlNT6zkIChXfg5gzj3cOWHQK7hzrqei/lYM7Sg9/pbWnda... docusign=1abeb306-299a-451b-8e2d-e48b433eba0f miro-verification=37c157ec056714cd8093465ce52fb881c36d13dd e9ae689e51780de2c0b9345581b12b339cf0762531ac7ecf66b924d128409aa MS=ms13378337 canva-site-verification=4E3AiC01BuQI6dk2iaRETQ jetbrains-domain-verification=eazcd0noqv6hwga0hjrblh4vi pendo-domain-verification=UgO-HNJWEFrV9IlVMnOwhvRFCFE google-site-verification=BQjfne_GAus5wkarvtRrAMRIl1XM1Nnpor8kby8jPRM cursor-domain-verification-1wnytz=GI7qmTy0E9CWWjkuuN9ivuUtb google-site-verification=OjtVno32jIZGrZs_rFhWNx9V2VYjWgupz_WqTcehje8 SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all notion-domain-verification=Z2D0SFJsOZXQZ3JXOX9QCaUGLSPZSH4psgHTitrkM2 abuseipdb-verification=VGYlkw6Q |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://doubleverify.com
60 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://doubleverify.com | 200 | 60 ms | HTTP/1.1 | cloudflare |
A+Crawlabilityrobots.txt present, sitemap with 403 URLsPASS
Add a 'Sitemap:' directive to robots.txt so search engines can discover your sitemap.
robots.txt omits Sitemap: directive — crawlers must fetch /sitemap.xml by convention; reliable but missing the explicit hint.
Source: sitemaps.org
User-agent: *
Disallow: /_hcms/preview/
Disallow: /hs/manage-preferences/
Disallow: /hs/preferences-center/
Disallow: /*?*hs_preview=*
Disallow: /*?*hsCacheBuster=*
- https://doubleverify.com/ja/solutions/authentic-advantage
- https://46126064.fs1.hubspotusercontent-na1.net/hubfs/46126064/assets/graphics/module-transitions/transition-slant-right-light-purple-mobile.svg
- https://46126064.fs1.hubspotusercontent-na1.net/hubfs/46126064/assets/graphics/module-transitions/transition-slant-left-gray-mobile.svg
- https://46126064.fs1.hubspotusercontent-na1.net/hubfs/46126064/assets/graphics/module-transitions/transition-slant-right-gray.svg
- https://46126064.fs1.hubspotusercontent-na1.net/hubfs/46126064/assets/graphics/module-transitions/transition-slant-left-navy-mobile.svg
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencedoubleverify.com — via GoDaddy Corporate Domains, LLC, 18 years, 11 months old, hosted on CloudflarePASS
1524 days
August 18, 2030
83 days
Issued by Let's Encrypt
18 years, 11 months
Registered August 18, 2007
Not enabled
Protects against DNS spoofing
Cloudflare
ASN AS209242
199.60.103.65
GoDaddy Corporate Domains, LLC
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice