Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations106 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 143 ms lookupPASS
| A | 54.236.221.201, 13.219.135.160 |
| AAAA | — |
| CNAME | — |
| NS | ns-354.awsdns-44.com, ns-1442.awsdns-52.org, ns-1625.awsdns-11.co.uk, ns-924.awsdns-51.net |
| MX | 1 aspmx.l.google.com 5 alt2.aspmx.l.google.com 5 alt1.aspmx.l.google.com 10 aspmx3.googlemail.com 10 aspmx2.googlemail.com |
| TXT | adobe-idp-site-verification=cd8dab640ab786a9457c8757f4188cd682dd687a694d1d9c251e... onetrust-domain-verification=8881bc01e7e0412cad34d32fc0145175 iContact1868438 _globalsign-domain-verification=f-B_7ErtvSe_2e1SkhSsTab6DQA-AVd2vcvY3gqskQ google-site-verification=o9Cc96uw3KJMePLolKG-TaGic7flrBYu2FjuPPs2_vU MS=ms74398949 google-site-verification=lUiR109Fr7wCImumZGxhwFOVpN6NoxbM-gVms6DPZ9w google-site-verification=POOfOsJMEB5Ri-U6Mo39E50MVbZ5lI_ToYpQsVUlk04 google-site-verification=SODhr8ecRnsxj4j2lGDk90I971LOOi7nzHBX_6WyPxs google-site-verification=vw3kHoAblBxht2HcQBeUC2t1TpT7g2zZl6o9SA4KnKI atlassian-domain-verification=QUsZX4LdPWTYZgx09JhShFot27EJnUl/5CyxXFsiGebXl2QD8F... docusign=24332464-d32b-451f-885a-34ef99704247 facebook-domain-verification=rdkk3wmnfq3vskkm60xy9363wcfwz1 knowbe4-site-verification=f8a0eecde40ecb172ead956570d9179c SPF v=spf1 include:_spf.google.com include:amazonses.com include:_spf.salesforce.com... figma-domain-verification=ab02dae66e56531cc42e8f3ccb45f9c32e96ba95854cd97d30bf95... _globalsign-domain-verification=ddgpRWXMmBK6n6pJf9ZbSOxdTxCpSUkpoHqzFKlYna anthropic-domain-verification-nrbcdk=AgOvAe4kMHRePalLaPL7TFAmE tollbit-domain-verification=927113b9a3f6ab22b17f1108bc995776d32c06b6fb41b6a9fcdd... facebook-domain-verification=qin59bzanvkwqtsgtaeq228wxcklp5 asv=26bebc6c9c16d8228da462c6e4a0406d google-site-verification=3MHmY5h0pvTFzEFxl8v7z7Q2Qin8p7qyyrCPWtTUJpY |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 918 ms totalPASS
https://medpagetoday.com
396 ms · HTTP/1.1
https://www.medpagetoday.com/
522 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://medpagetoday.com | 301 | 396 ms | HTTP/1.1 | Varnish |
| 2 | https://www.medpagetoday.com/ | 200 | 522 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 5 URLsPASS
# Ziff Davis content is made available for your non-commercial use subject to our
# Terms of Use here: https://www.medpagetoday.com/about/terms
# Use of any robot, crawler, or other tool to scrape, harvest, extract, or retrieve any content on
# this website using automated means is prohibited without written permission from Ziff Davis.
# Prohibited uses include but are not limited to:
# (1) text and data mining under Art. 4 of the EU Directive on Copyright in the Digital Single
# Market;
# (2) development or operation of artificial intelligence or machine learning software or
# databases, including by training, fine-tuning, embedding, and retrieval-augmented generation;
# (3) creating data sets containing our content or sharing it with others; and
# (4) any commercial purposes.
# Contact licensing@ziffdavis.com for assistance.
Sitemap: https://www.medpagetoday.com/sitemap-index.xml
Sitemap: https://www.medpagetoday.com/videositemap.xml
Sitemap: https://www.medpagetoday.com/latest-newssitemap.xml
User-agent: *
Disallow: /userInfo
Disallow: /trigger/checkv2
Disallow: /contentfeed/getdata?type=synopsi
Disallow: /auth
User-agent: "008"
User-agent: AddSearchBot
User-agent: AI2Bot
User-agent: Ai2Bot-Dolma
User-agent: Amazonbot
User-agent: AmazonBuyForMe
User-agent: anthropic-ai
User-agent: Applebot
User-agent: Applebot-Extended
User-agent: AwarioRssBot
User-agent: AwarioSmartBot
User-agent: bigsur.ai
User-agent: Bytespider
User-agent: CCBot
User-agent: Channel3Bot
User-agent: ChatGLM-Spider
User-agent: ChatGPT-User
User-agent: ClaudeBot
User-agent: Claude-SearchBot
User-agent: Claude-User
User-agent: Claude-Web
User-agent: cohere-ai
User-agent: cohere-training-data-crawler
User-agent: Cotoyogi
User-agent: Crawl4AI
User-agent: Datenbank Crawler
User-agent: DeepSeekBot
User-agent: Devin
User-agent: DDM-DCipher/1.0.7
User-agent: DDM*
User-agent: Diffbot
User-agent: DuckAssistBot
User-agent: FacebookBot
User-agent: GPTBot
User-agent: GROK-2
User-agent: HTTrack
User-agent: iAsk
User-agent: iaskspider
User-agent: ICC-Crawler
User-agent: ImagesiftBot
User-agent: Kangaroo Bot
User-agent: Kunato
User-agent: laion-huggingface-processor
User-agent: LCC
User-agent: LinerBot
User-agent: LinkupBot
User-agent: Magpie-crawler
User-agent: meta-externalagent
User-agent: meta-externalfetcher
User-agent: Manus-User
User-agent: mistral.ai
User-agent: MistralAI-User
User-agent: netEstate Imprint Crawler
User-agent: NovaAct
User-agent: Nutch
User-agent: OAI-SearchBot
User-agent: Offline Explorer
User-agent: Omgili
User-agent: Omgilibot
User-agent: PanguBot
User-agent: Peer39_crawler/1.0
User-agent: PeopleInc-DCipher-Scraper/1.1.0
User-agent: PerplexityBot
User-agent: Perplexity-User
User-agent: PetalBot
User-agent: Poggio-Citations
User-agent: QualifiedBot
User-agent: SBIntuitionsBot
User-agent: Scrapy
User-agent: SeekrBot
User-agent: Spider
User-agent: TavilyBot
User-agent: Timpibot
User-agent: TwinAgent
User-agent: Velen Crawler
User-agent: Webzio-Extended
User-agent: Wrtn
User-agent: xAI-Web-Crawler
User-agent: YouBot
User-agent: ZanistaBot
User-agent: Ai2Bot-DeepResearchEval
User-agent: Anchor Browser
User-agent: Anomura
User-agent: atlassian-bot
User-agent: Big Sur AI
User-agent: Brandwatch
User-agent: Bravebot
User-agent: Cloudflare-AutoRAG
User-agent: Echobot Bot
User-agent: Factset_spyderbot
User-agent: ICC Crawler
User-agent: KlaviyoAIBot
User-agent: LINER Bot
User-agent: meta-webindexer
User-agent: Novellum AI Crawl
User-agent: SemrushBot-OCOB
User-agent: SemrushBotSwa
User-agent: ShapBot
User-agent: VelenPublicWebCrawler
Disallow: /
A+Domain Intelligencemedpagetoday.com — via CSC Corporate Domains, Inc., 22 years, 8 months old, hosted on AWSPASS
1266 days
December 2, 2029
106 days
Issued by Amazon
22 years, 8 months
Registered December 2, 2003
Not enabled
Protects against DNS spoofing
AWS
ASN AS14618
13.219.135.160
CSC Corporate Domains, Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice