Infrastructure
· 17 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DURL VariantsActionwww/non-www, trailing slash, HTTP→HTTPSFIX
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
HTTP version does not redirect to HTTPS
BDNSSECUnsigned (DNSSEC not deployed)REVIEW
BCAA RecordsNo CAA records (any CA may issue certificates)REVIEW
BReverse DNS0/2 IPs match cert SANREVIEW
BHTTP Probe TimingTotal 1061 ms — DNS, TCP, TLS, TTFB, content transfer breakdownREVIEW
Connection waterfall
BTLS Certificate Expiry & Recommendations60 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryGoogle Cloud CDNREVIEW
BCDN Cache ObservabilityNo CDN cache-status headers in the responseREVIEW
BOperational Status PageNo status page link detectedREVIEW
BHealth Check EndpointNo conventional health endpoint foundREVIEW
A+DNS Records1 A records, 34 ms lookupPASS
| A | 8.232.197.155 |
| AAAA | 2600:1901:0:60c5:: |
| CNAME | — |
| NS | ns16.domaincontrol.com, ns15.domaincontrol.com |
| MX | 1 aspmx.l.google.com 5 alt1.aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 alt4.aspmx.l.google.com 10 alt3.aspmx.l.google.com |
| TXT | google-site-verification=gHU4mh5nA41ckLws8ERB8QAi9VhYP4-VS6LC8kku35c SPF v=spf1 include:dc-aa8e722993._spfm.home-run.co ~all google-site-verification=iaP9dQyYKHVoGaQeKwQL1Md9B0_kmzHkBLV1e0jyw9M google-site-verification=RqdT5UOFsVeryQSAwOwemDzPWgUW1YsWtBmNQAeVFvA |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
A+Subdomain TakeoverNo subdomain takeover risk detectedPASS
A+Multi-Resolver DNS SpeedMean 16ms across 3 resolvers (spread 22ms)PASS
A+Redirect ChainNo redirects — direct accessPASS
https://home-run.co/?srsltid=AfmBOooLD5k...
2848 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://home-run.co/?srsltid=AfmBOooLD5k... | 200 | 2848 ms | HTTP/1.1 | Google Frontend |
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 1131 URLsPASS
User-Agent: *
Allow: /
Disallow: /account
Disallow: /account/*
Disallow: /cart
Disallow: /login
Disallow: /order-confirmation
Disallow: /order-tracking
Disallow: /order-tracking/*
Disallow: /search
Disallow: /dev-preview
Disallow: /dev-preview/*
Sitemap: https://home-run.co/sitemap.xml
A+Domain Intelligencehome-run.co — via GoDaddy.com, LLC, 2 years, 4 months oldPASS
614 days
May 17, 2028
60 days
Issued by Google Trust Services
2 years, 4 months
Registered May 17, 2024
Status unknown
Protects against DNS spoofing
Unknown
2600:1901:0:60c5::
GoDaddy.com, LLC
Expiry timeline
Domain cannot be transferred without explicit unlock from the registrar. This protects against unauthorized transfers.
Registrar lock (clientTransferProhibited et al.) prevents unauthorized domain transfers — strongest defense against domain hijacking.
Source: ICANN / domain-security best practice