Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BURL Variantswww/non-www, trailing slash, HTTP→HTTPSREVIEW
www / non-www
Inconsistent — duplicate content risk
HTTP → HTTPS
Consistent
BTLS Certificate Expiry & Recommendations70 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records3 A records, 55 ms lookupPASS
| A | 18.196.221.37, 18.185.81.127, 3.72.121.83 |
| AAAA | — |
| CNAME | — |
| NS | d.ns14.net, c.ns14.net, b.ns14.net |
| MX | 100 morgenpost-de.mail.protection.outlook.com |
| TXT | ahrefs-site-verification_85c9ada5714024784dd4ce2446bee1ccccc1206ed26c745b0f7b725... swisssign-check=2riNyZhLtNYUl_8uanXq23pYaSk MS=ms17724065 google-site-verification=PMEXkBCtYama_tXgb7z9mFu_v9zEm5RhICvZ-_GrojQ SPF v=spf1 include:spf.protection.outlook.com include:spf.funkemedien.de -all facebook-domain-verification=l7gzd9xab6g74bvmix1p6x3ldyxj9h google-site-verification=lA7mdbLACtqpFaxJeOIj3SxP-QnOPWMcfsP_8AzJkZA adobe-idp-site-verification=1817294f-b27b-457d-b7ff-a083919f44a4 google-site-verification: cav9Y_NkGywFRDz_giyujLtv8KzD9uRTrYm7BmFUliM |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 215 ms totalPASS
https://morgenpost.de
95 ms · HTTP/1.1
https://www.morgenpost.de:443/
120 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://morgenpost.de | 301 | 95 ms | HTTP/1.1 | awselb/2.0 |
| 2 | https://www.morgenpost.de:443/ | 200 | 120 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
A+Crawlabilityrobots.txt present, sitemap with 239 URLsPASS
Sitemap: https://www.morgenpost.de/sitemaps/news.xml
User-agent: *
Allow: /static/*/client.js
Allow: /static/*/main.css
Allow: /static/*/favicon.png
Disallow: /stats/*
Disallow: /*?config*
Disallow: /*.xmli*
Disallow: /*?service=Ajax
Disallow: /*?service=ajax
Disallow: /config/*
Disallow: /test/*
Disallow: /Test/*
Disallow: /template/*
Disallow: /*?*token=*
Disallow: /*?*eventId=*
Disallow: /static/*
Disallow: /migration_import_no_section/*
Disallow: /secure/
Disallow: /socialmedia/*
Disallow: *reader_id=READER_ID*
Disallow: /suche/*
Disallow: /*?widgetid=
Disallow: /newsletter-result/
Disallow: *tpcc=*
Disallow: /resources/
Disallow: /bin/
Disallow: /downloads/
Disallow: /service/newsletter-adconsent
Disallow: /pagespeed_static/
Disallow: /resources/img/*icon*pagespeed
# search engines
User-agent: Cliqzbot
User-agent: Baiduspider
User-agent: Flamingo_SearchEngine
User-agent: SeznamBot
User-agent: Sogou spider
User-agent: Yandex
Disallow: /
# seo tools
User-agent: AhrefsBot
User-agent: BacklinkCrawler
User-agent: DataForSeoBot
User-agent: deepcrawl
User-agent: LinkChecker
User-agent: linkdebot
User-agent: Linkfluence Yak Bot
User-agent: Majestic
User-agent: Majestic12
User-agent: MJ12bot
User-agent: OnPageBot
User-agent: OpenindexSpider
User-agent: openindexspider
User-agent: Optimizer
User-agent: RyteBot
User-agent: SemrushBot
User-agent: SemrushBot-SA
User-agent: Semrushbot-SI
User-agent: Seobility
User-agent: SEOdiver
User-agent: SEOkicks
User-agent: SEOkicks-Robot
User-agent: SISTRIX
User-agent: sistrix
User-agent: SISTRIX Crawler
User-agent: SISTRIX Optimizer
User-agent: SiteAuditBot
Disallow: /
# ai tools
User-agent: AddSearchBot
User-agent: ai2bot
User-agent: AihitBot
User-agent: AllenAI
User-agent: Amazon-Kendra
User-agent: Amazonbot
User-agent: Anomura
User-agent: anthropic-ai
User-agent: Applebot-Extended
User-agent: archive.org_bot
User-agent: AtlassianBot
User-agent: BedrockBot
User-agent: Brightbot
User-agent: ByteDance
User-agent: Bytespider
User-agent: CCBot
User-agent: ClaudeBot
User-agent: Claude-Web
User-agent: Cloudflare-Authorag
User-agent: Cloudflare-Autorag
User-agent: CloudVertexBot
User-agent: Cohere-Training-Data-Crawler
User-agent: Cotoyogi
User-agent: cohere-ai
User-agent: CrawlSpace
User-agent: DeepSeekBot
User-agent: Diffbot
User-agent: FacebookBot
User-agent: FactSet_SpyderBot
User-agent: FireCrawlAgent
User-agent: FriendlyCrawler
User-agent: Google-Cloud-Vertex-Bot
User-agent: Google-Extended
User-agent: GoogleOther
User-agent: GPTBot
User-agent: Grok-DeepSearch
User-agent: GrokBot
User-agent: ia_archiver
User-agent: ia_archiver-web.archive.org
User-agent: ICC-Crawler
User-Agent: ImagesiftBot
User-agent: img2dataset
User-agent: KangarooBot
User-agent: KlaviyoAIBot
User-agent: LingueeBot
User-Agent: meta-externalagent
User-agent: Meta-WebIndexer
User-agent: MistralAI
User-agent: MyCentralAIScraperBot
User-agent: omgili
User-agent: omgilibot
User-agent: OpenAI
User-agent: PanguBot
User-agent: peer39_crawler
User-agent: peer39_crawler/1.0
User-agent: PerplexityBot
User-agent: PoseidonResearchCrawler
User-agent: QualifiedBot
User-agent: SBIntuitionsBot
User-agent: ShapBot
User-agent: SidetradeIndexerBot
User-agent: Terracotta
User-agent: Timpibot
User-agent: ThinkBot
User-agent: TikTokSpider
User-agent: VelenPublicWebCrawler
User-agent: XAI-Grok
User-agent: YandexAdditional
User-agent: YouBot
Disallow: /
# other
User-agent: arquivo-web-crawler
User-agent: arquivo.pt
User-agent: Barkrowler
User-agent: bigsur.ai
User-agent: BLEXBot
User-agent: browsertrix
User-agent: brozzler
User-agent: Buddybot
User-agent: BuiltWith
User-agent: Cincraw
User-agent: coccocbot
User-agent: contao/crawler
User-agent: Devin
User-agent: Dmbot
User-agent: DomainStatsBot
User-agent: DotBot
User-agent: dotbot
User-agent: fluid
User-agent: HaosouSpider
User-agent: HappyWing
User-agent: harsilbot
User-agent: hatena antenna
User-agent: Heritrix
User-agent: ImagesiftBot
User-agent: kazbtbot
User-agent: Kraken
User-agent: LinerBot
User-agent: linkdebot
User-agent: Linkfluence Yak Bot
User-agent: mail.RU_Bot
User-agent: MetaJobBot
User-agent: Monsidobot
User-agent: netEstate
User-agent: OGDWCtcxCrawler
User-agent: PetalBot
User-agent: ResearchBot
User-agent: Riddler
User-agent: SentiBot
User-agent: rogerbot
User-agent: Semanticbot
User-agent: SemanticScholarBot
User-agent: SirdataBot
User-agent: spbot
User-agent: special_archiver
User-agent: SplitSignalBot
User-agent: Tag-Crawler
User-agent: Testcrawler
User-agent: thinkers-bot
User-agent: Toplistbot
User-agent: uipbot/1.0
User-agent: urlsuma
User-agent: User-agent
User-agent: VsuSearchSpider
User-agent: weborama-fetcher
User-agent: WiseGuys Robot
User-agent: wpbot
User-agent: Yeti
Disallow: /
# ad-bots
User-agent: AmazonAdBot
Disallow: /stats/*
Disallow: /*?config*
Disallow: /*.xmli*
Disallow: /*?service=Ajax
Disallow: /*?service=ajax
Disallow: /config/*
Disallow: /test/*
Disallow: /Test/*
Disallow: /template/*
Disallow: /*?*token=*
Disallow: /*?*eventId=*
Disallow: /static/*
Disallow: /migration_import_no_section/*
Disallow: /secure/
Disallow: /socialmedia/*
Disallow: *reader_id=READER_ID*
Disallow: /suche/*
Disallow: /*?widgetid=
Disallow: /newsletter-result/
Disallow: *tpcc=*
Disallow: /resources/
Disallow: /bin/
Disallow: /downloads/
Disallow: /service/newsletter-adconsent
Disallow: /pagespeed_static/
Disallow: /resources/img/*icon*pagespeed
# disallow only articles
User-agent: DuckAssistBot
User-agent: Gemini-Deep-Research
User-agent: ChatGPT-User
User-agent: Google-NotebookLM
User-agent: GoogleAgent-Mariner
User-agent: meta-externalfetcher
User-agent: MistralAI-User
User-agent: NovaAct
User-agent: Perplexity-User
User-agent: Claude-SearchBot
Disallow: /*/article*.html
Disallow: /stats/*
Disallow: /*?config*
Disallow: /*.xmli*
Disallow: /*?service=Ajax
Disallow: /*?service=ajax
Disallow: /config/*
Disallow: /test/*
Disallow: /Test/*
Disallow: /template/*
Disallow: /*?*token=*
Disallow: /*?*eventId=*
Disallow: /static/*
Disallow: /migration_import_no_section/*
Disallow: /secure/
Disallow: /socialmedia/*
Disallow: *reader_id=READER_ID*
Disallow: /suche/*
Disallow: /*?widgetid=
Disallow: /newsletter-result/
Disallow: *tpcc=*
Disallow: /resources/
Disallow: /bin/
Disallow: /downloads/
Disallow: /service/newsletter-adconsent
Disallow: /pagespeed_static/
Disallow: /resources/img/*icon*pagespeed
- https://www.morgenpost.de/kultur/article411792811/dominique-horwitz-drei-seelen-wohnen-ach-in-seiner-brust.html
- https://img.sparknews.funkemedien.de/411792809/411792809_1776891853_v16_9_1600.webp
- https://www.morgenpost.de/politik/article411792661/popstar-dua-lipa-finanziert-pick-up-fuer-ukrainisches-frontlazarett.html
- https://img.sparknews.funkemedien.de/408044510/408044510_1776885446_v16_9_1600.webp
- https://www.morgenpost.de/politik/article411784446/trump-oder-die-mullahs-am-ende-kommt-es-darauf-an-wer-zuerst-zucktE2809D.html
A+Domain Intelligencemorgenpost.de — hosted on AWSPASS
Unknown
70 days
Issued by Amazon
Unknown
Status unknown
Protects against DNS spoofing
AWS
ASN AS16509
18.185.81.127
Registrar unknown
Expiry timeline
Recommended actions
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice