Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
CTLS Certificate Expiry & RecommendationsAction27 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Renew certificate — 27 days remaining
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 16 ms lookupPASS
| A | 75.2.70.75, 99.83.190.102 |
| AAAA | — |
| CNAME | — |
| NS | anton.ns.cloudflare.com, kayleigh.ns.cloudflare.com |
| MX | 10 aspmx.l.google.com 20 alt1.aspmx.l.google.com 30 alt2.aspmx.l.google.com 40 alt3.aspmx.l.google.com 50 alt4.aspmx.l.google.com |
| TXT | 685a8460-a63f-426d-a398-0ce5c5485d7f MS=ms37773757 OSSRH-85778 ZOOM_verify__yI8ldaESdiTJB42371Y2w adobe-idp-site-verification=241f059912cdb853363e6676fb04983aa12600af39048f69a66b... anthropic-domain-verification-ybx150=37r25cAGq1G6VteCZi4UJhX8V apple-domain-verification=l7filDZfhTtFoqgI astro-domain-verification=cm0hz5n0z051w01n9aexol6ld asv=b2c5e40e3a9e50071193ae39ae533b84 atlassian-domain-verification=AoI8OwGMsd0GaUYitgNF2mZFOsM/3RJfP6CSdx4CXptlaCIHdg... atlassian-sending-domain-verification=5538e16e-f74f-4e11-ba97-8a5bc5c252fe cursor-domain-verification-ack1r7=YOtd2m82KEEhJxtFtur038S6q docusign=2c33c80f-c080-445d-a5bd-f9161d97301a google-site-verification=DDQ8yM0vEwvpXOwEwkpDB0MYNUmTBZ54k00le38Ozm4 google-site-verification=NSxSD_Q5tjJJl5ujLirGyIQk6iRCoLQ26eNG2Mo54Iw google-site-verification=UcprMWfhB_QXMEfzZDX-YWZSgijB1ZaFqDr7w3c4uPM google-site-verification=WEVSzG9ThR4JCeO05noov2AgwBCmxueS6CYMWz70PDM google-site-verification=aq3qdZ-z3RZMe9EAdXVjDLzSCawxxLjKWd4uNs52qbA google-site-verification=st7HDOXchqYGlTG_FILIyTEUT_HasI2CEYc5boxktZY jamf-site-verification=3YOs098r0WJFAqCKHo0NLA jetbrains-domain-verification=5njjnmbclsu9bc3i0w0606lua manus-domain-verification-y8caky=LRzW3noilE1xPiZehv2zgY1pj notion-domain-verification=GpPdxAb1FFLRl7p5NLg0RZYqnfJKNGnroV9vNDJiXYr openai-domain-verification=dv-fUqyTwnKRLR8awPbGLkRqVLY proxy-ssl.webflow.com stripe-verification=ab7d00eea6c317282504169e1f87e304b73708a71ec12cff12d64a55d7cf... SPF v=spf1 include:_spf.google.com include:6381084.spf05.hubspotemail.net include:ma... |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 147 ms totalPASS
https://moloco.com
81 ms · HTTP/1.1
https://www.moloco.com/
67 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://moloco.com | 301 | 81 ms | HTTP/1.1 | |
| 2 | https://www.moloco.com/ | 200 | 67 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 3052 URLsPASS
User-agent: *
# Duplication and Query Strings
Disallow: *page=*
Disallow: /search?query=*
Disallow: /*?edit*
Disallow: /*utm_*
Disallow: /*category=*
Disallow: /*interested_in_solution*
Disallow: /*?lang=*
Disallow: /*?r=0
Disallow: /*sort_by=*
Disallow: /*filter_by=*
Disallow: /*ticket_form_id=*
Disallow: *?page_id=
Disallow: *_page=
# Attachments
Disallow: /hc/article_attachments/
# Marketing Pages
Disallow: */landing-pages/*download*
Disallow: */landing-pages/*thank-you*
Disallow: */landing-pages/*thanks*
Disallow: */landing-page/form-3
Disallow: */landing-page/form-2
Disallow: */landing-page/form-1
#Other pages
Disallow: */untitled
Disallow: */dpa-mcm/*
Disallow: */dpa-dsp/*
Disallow: */dpa-sdk/*
Disallow: */dpa-agency/*
Disallow: */sronlineterms/*
Disallow: */generalterms-ma/*
Disallow: */content-guideline-ads/*
Disallow: */content-guideline-ads-rmg/*
# JavaScript directories
Disallow: /static/js/
Disallow: /ui/vendor/jquery.sparkline/
Disallow: /_next/static/chunks/
# Known Scraper Bots
User-agent: Teleport
Disallow: /
User-agent: WebZIP
Disallow: /
User-agent: CherryPicker
Disallow: /
User-agent: ERNIE-Bot
Disallow: /
User-agent: BlowFish/1.0
Disallow: /
User-agent: grub
Disallow: /
User-agent: Bytespider
Disallow: /
User-agent: SiteSnagger
Disallow: /
User-agent: Titan
Disallow: /
User-agent: Barkrowler
Disallow: /
# Malicious Bots
User-agent: 008
Disallow: /
User-agent: Alexibot
Disallow: /
User-agent: BackDoorBot/1.0
Disallow: /
User-agent: Bullseye/1.0
Disallow: /
User-agent: ExtractorPro
Disallow: /
User-agent: Kenjin Spider
Disallow: /
User-agent: WWW-Collector-E
Disallow: /
# High-Risk Regional Bots
User-agent: Sogou
Disallow: /
User-agent: Yandex
Disallow: /
User-agent: Mail.RU_Bot
Disallow: /
User-agent: MegaIndex
Disallow: /
User-agent: Szukacz/1.4
Disallow: /
# Data Scraping Bots
User-agent: BotALot
Disallow: /
User-agent: Bullseye/1.0
Disallow: /
User-agent: BunnySlippers
Disallow: /
User-agent: BuiltBotTough
Disallow: /
User-agent: CheeseBot
Disallow: /
User-agent: Crescent
Disallow: /
User-agent: EroCrawler
Disallow: /
User-agent: Foobot
Disallow: /
User-agent: Harvest/1.5
Disallow: /
User-agent: InfoNaviRobot
Disallow: /
User-agent: JennyBot
Disallow: /
User-agent: Mister PiX
Disallow: /
User-agent: moget
Disallow: /
User-agent: NetAnts
Disallow: /
User-agent: NICErsPRO
Disallow: /
User-agent: ProPowerBot/2.14
Disallow: /
User-agent: Radiation Retriever
Disallow: /
User-agent: RepoMonkey
Disallow: /
User-agent: RepoMonkey Bait & Tackle/v1.01
Disallow: /
User-agent: True_Robot
Disallow: /
User-agent: URL_Spider_Pro
Disallow: /
User-agent: Web Image Collector
Disallow: /
User-agent: WebAuto
Disallow: /
User-agent: WebBandit
Disallow: /
User-agent: WebCopier
Disallow: /
User-agent: Website Quester
Disallow: /
User-agent: Webster Pro
Disallow: /
User-agent: WebStripper
Disallow: /
User-agent: Wget
Disallow: /
User-agent: Zeus
Disallow: /
# SEO Monitoring Bots - Set Crawl Delays
User-agent: dotbot
crawl-delay: 5
User-agent: Rogerbot
Crawl-delay: 5
User-agent: ia_archiver
Crawl-delay: 5
User-agent: MJ12bot
Crawl-delay: 5
User-agent: Xenu
Crawl-delay: 5
User-agent: AhrefsBot
Crawl-delay: 1
User-agent: CCBot
Crawl-delay: 5
User-agent: SemrushBot
Crawl-delay: 5
User-agent: DataForSeoBot
Crawl-delay: 5
User-agent: XoviBot
Crawl-delay: 5
User-agent: Screaming Frog SEO Spider
Crawl-delay: 1
User-agent: Keyword Density/0.9
Crawl-delay: 5
User-agent: LinkextractorPro
Crawl-delay: 5
User-agent: LinkScan/8.1a Unix
Crawl-delay: 5
User-agent: BLEXbot
Crawl-delay: 5
User-agent: spbot
Crawl-delay: 5
# Sitemap
Sitemap: https://www.moloco.com/sitemap.xml
Sitemap: https://www.moloco.com/sitemap.xml
A+Domain Intelligencemoloco.com — via GoDaddy.com, LLC, 26 years, 9 months old, hosted on AWSPASS
2362 days
December 2, 2032
27 days
Issued by Let's Encrypt
26 years, 9 months
Registered December 2, 1999
Not enabled
Protects against DNS spoofing
AWS
ASN AS16509
75.2.70.75
GoDaddy.com, LLC
Expiry timeline
Recommended actions
- Renew the TLS certificate or verify auto-renewal is working
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice