Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations31 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 121 ms lookupPASS
| A | 192.0.66.119 |
| AAAA | — |
| CNAME | — |
| NS | ns01.msddns.com, ns03.msddns.com, dns2.p03.nsone.net, dns1.p03.nsone.net, dns3.p03.nsone.net, ns02.msddns.com, dns4.p03.nsone.net, ns04.msddns.com |
| MX | 0 msdcloud.mail.protection.outlook.com |
| TXT | onetrust-domain-verification=1478f1a6e1ed4c2c9c099a356b4e1284 ibmid= 81d5ac3b-53ce-4d24-9062-4057a4045f96 mongodb-site-verification=ItgIzlgsIWpv1dzm84x1QzLoYJAlTcvO Dynatrace-site-verification=3a44c6ac-87f4-4c95-a4b2-61b75996bcf9__556f2vbvbo83bs... onetrust-domain-verification=6095750f880442f6a27969ee753b9623 TNvYRxzRPZ9bp12r3tS8oIWZ7CqmudOjsx7_f2a9UCg smartsheet-site-validation=2XUbLMBJFkkltyH3ngZFOlnIqFv29PvY mongodb-site-verification=PuKOAIC2peU8LwH9FMFY0YcqPdtcPdXZ mongodb-site-verification=I5lG10QLafEXrk8Q2O8Duu84hUOkoLxm remarkable-domain-verification=4b36037e-af38-45a6-a388-0b533e44d530 ... atlassian-domain-verification=ciUKXFyshP71uhmcYlixwC3ClAKoTjYehQTYKZ/4WdBAEfdP7Z... teamviewer-sso-verification=3dfc5700d0fb490ea1335107680a2dcf g4mp7kf92k0pttl4dwpc66sm3y4hhslc ys4kh6150g7rsrgnr5kzmqzykkwpbhlv smartsheet-site-validation=GOXFlXMlgROG9pZt7L1hLFsqtmKsCw3D google-site-verification=Mxpc7VG_3cBpAqm9gE0YjgVs80pVkZs6-mSZTJeDZSM SPF v=spf1 include:spf1.merck.com include:spf2.merck.com ~all meta-work-account-domain-verification=b21f858f-9e4f-4797-8eec-7b6deba1c12a MS=ms73390276 cloudhealth=1f6ab3c0-a9a8-4379-b750-c416c5a023d7 rvxhp3tp6ft3s0tm57v4fmnt2x59clpq jlvgnenmenn78fup62soefgcph adobe-idp-site-verification=c9df9d351e2d97fe46b43740c6593677199a0bc21036f69a3e30... 44e4c91b36f190hu3vc5j589r 20q8kh5vb8lc34dg17lk07rh5n 2mjbhlht9j0g3928i2oe5nqi6a 76dkj9u7598f7503gp8j9thda8 google-site-verification=k7Tz6dZz7mJa7iQ8I1cqR2Kn_gDRTYoWEMMhcSFyYT4 appspace-domain-verification=f5ee13f2c71814a40d6354018ec5f8025ca10f17c08c58927e1... zm4xgs82p44jf5nbr2fv8k95d34vljck kjDXtGLRgdP5O01I8wySejNk1/dm/A3GVOA1+hhDBKzg7pDUohIuvQh+yqF8s4c5ypL6vo1xh0shh6oa... docker-verification=55bc797b-4c8f-40c0-ac57-17a644048b79 flexera-domain-verification-pjdxpopuhvhasmse vmware-cloud-verification-1840573e-2bc4-4fb4-b45d-cdc1083f431d NM3NBUfHMehhQbbV4KLwYKCcHEGbMIeUrR8WXIn+ECtXmrshEmZFlLtQN/Ve4ley/2xE5Dj5oFB51rYZ... google-site-verification=3FzJ88NeaXEIhicFwNbTkVCZbN3If4NqR1JZ7F0rU8o ehklccfrmqtog011qavchou5oo smartsheet-site-validation=r3Eb_Uesikv5Y2hbkQapKITHfg03B91p _globalsign-domain-verification=J7ojurG8pfHB1_T7RRXWhSXvJnAJ-Ly9X4moPnOfve facebook-domain-verification=9kjy8qvfwmsr3wjj8wci2waq80vl1c v=DMARC1; p=none; pct=100; rua=mailto:sensehubfeedlot@merck.com w0sg3gyn09nh3tqmf65frh18nddvmx3v mongodb-site-verification=o7H6ABW4ieD3bnFBQolivwtqBAFNd2zt workplace-domain-verification=cZLaRzArPk5jzUj4tcvJm8xtxeWedR autodesk-domain-verification=QidA8UKJFkGFps0q21Ve 0ed1fe018a31147b85218b4de29ec808fd5b4ab1d8 1password-site-verification=WOZWLMKFDJDBZI2GB6FKQCO4YA mongodb-site-verification=EAy8hzGVPrh0smAXi9A0MQ1V7vlwR0L7 google-site-verification=fFR6UZDhXRia_VuIGTVOCOlwQzpsndzqs6PubIIOfnk 2a6hcn5keoukshbma518dg69a5 8gcvl81vgkbcnq6nz80f12rq0cy438h2 MS=ms81705768 extensis-domain-verification=f9447776-1a22-4bda-b0da-16c1a41aea1c y24y8d5tf27321g3h6rs2z3q8k8md9ls google-site-verification=TNvYRxzRPZ9bp12r3tS8oIWZ7CqmudOjsx7_f2a9UCg |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 686 ms totalPASS
https://merck.com
5 ms · HTTP/1.1
https://www.merck.com/
681 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://merck.com | 301 | 5 ms | HTTP/1.1 | nginx |
| 2 | https://www.merck.com/ | 200 | 681 ms | HTTP/1.1 | nginx |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 10 URLsPASS
Sitemap: https://www.merck.com/sitemap_index.xml
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
- https://www.merck.com/page-sitemap.xml
- https://www.merck.com/story-sitemap.xml
- https://www.merck.com/event-sitemap.xml
- https://www.merck.com/personnel-sitemap....
- https://www.merck.com/news_item-sitemap....
- https://www.merck.com/news_item-sitemap2...
- https://www.merck.com/news_item-sitemap3...
- https://www.merck.com/scientist-sitemap....
- https://www.merck.com/bdl_item-sitemap.x...
- https://www.merck.com/content_topic-site...
A+Domain Intelligencemerck.com — via MarkMonitor Inc., 33 years, 10 months old, hosted on WordPress.com (Automattic)PASS
540 days
December 8, 2027
31 days
Issued by Let's Encrypt
33 years, 10 months
Registered December 9, 1992
Not enabled
Protects against DNS spoofing
WordPress.com (Automattic)
ASN AS2635
192.0.66.119
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice