Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
BRedirect Chain1 redirect(s), 1117 ms totalREVIEW
https://nick.com
1048 ms · HTTP/1.1
https://www.nick.com
68 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://nick.com | 301 | 1048 ms | HTTP/1.1 | redirectv2 |
| 2 | https://www.nick.com | 200 | 68 ms | HTTP/1.1 |
See the visual redirect chain in the HTTP Probe tab →
BTLS Certificate Expiry & Recommendations74 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records3 A records, 14 ms lookupPASS
| A | 100.28.104.175, 54.157.108.158, 98.83.184.133 |
| AAAA | 2600:1f18:297:ba18:6ddc:5d8f:6053:f003, 2600:1f18:297:ba24:b508:76de:f4a:df34, 2600:1f18:297:ba0e:7900:f622:48a8:f266 |
| CNAME | — |
| NS | dns1.p09.nsone.net, dns2.p09.nsone.net, dns3.p09.nsone.net, dns4.p09.nsone.net, ns0004.secondary.cloudflare.com, ns0243.secondary.cloudflare.com |
| MX | 10 mxb-00262c01.gslb.pphosted.com 10 mxa-00262c01.gslb.pphosted.com |
| TXT | MS=ms43505158 _c785yb69kebe2fqcd2r79n5cy7tgzd6 adobe-idp-site-verification=4c1afe9e-ea70-4283-a27a-c211c24996de anthropic-domain-verification-szzpnd=1oS3pSFvkZz9fRtgMDqc6RfY4 appspace-domain-verification=95717daa24b5c09519b505de173a1b8d2d0d37ec64cb70ce7d6... atlassian-domain-verification=E+wiTTQbdi+aIBlOe7MvMyDmxBdCed/oDG6hRZquh5QIu+JegS... autodesk-domain-verification=1ELtjJ5P8L1FzmOu2zE- dOa1jKtzwocvMPDZ4RCZjzy2mn29ay6oWXzzXOQl2NdqbeC1JRzgHSvfGLZhbXDS7e8arcLGCdWJ1jlh... docusign=c656d342-fb5e-4e7f-bbe7-fd61c95e0b5f docusign=da9feae3-6675-4993-a5ef-0f13210bf0cd elevenlabs=H5kuOqr8fZrhkFwf4r_Yujuxp6wI5N_aiKWp1i0QbN4 elevenlabs=oLxS0_BBKCrkY4U1UA2b2CNL58srDC1eIcrGISL79RE facebook-domain-verification=hu1vbd8pmomwgcs84mipl48qewkei3 fmkC9A6fCOoLNvhwUIukBydNiKsE7UWkFgh1pIsc6mtS5t2phJawuy6nGC+FhwKHqOziPCIgkkFgq+na... google-site-verification=BKSvTIhqwuqEExYWEL-gd8ViqrptdoOZR_ru9hC3Gj4 google-site-verification=Pc-StFXwwBP0U4Z8Y_4WXWSDzHd5aLkj49RBSUCGhpg google-site-verification=bAY8L3ZScqc1NLXkb-noiZmDIYgoh6SYq0izUBC6XW0 google-site-verification=d0qBTvjAVfCv0JdJ8pJBtHFNyKJAmbkelezml9etm1w google-site-verification=sJrJYwyh4FOgmB3JAmkF1HlRdCfq48del70tgIKBc7Y jamf-site-verification=fl0PsPTZnYtdYIzIMUEZng onetrunt-domain-verification=d26d044576ba4747b202a09912956d18 onetrust-domain-verification=6a975d7ca6b84942bb0d839e1dd2443b onetrust-domain-verification=d26d044576ba4747b202a09912956d18 openai-domain-verification=dv-zh3tRzlRfTe7BO8zc2T59Y7r parallels-domain-verification=19f7e985539e42cca485ea9a8dc3dd94c6f9931d85d8423b8e... smartsheet-site-validation=CfnD14dI_ticq4r6b9zNvmXh_6TJZ7za SPF v=spf1 include:_netblocks.viacom.com include:spf.protection.outlook.com ip4:129.... wombat-verification=3KwxVCQV1HEp-aRXRTKKaZ5G0frhk y9kn97kf46mnl8vfpk6rmc6bk5vnsnzs |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+IPv6 ReadinessIPv6 reachable (7 ms)PASS
ACrawlabilityrobots.txt present, no sitemapPASS
A sitemap helps search engines discover and index your pages more efficiently.
No sitemap.xml — Google relies on crawl-graph discovery alone, slowing indexing of deep or fresh URLs.
Learn more ▾ ▴
A sitemap accelerates Google's discovery of new and updated content. Most CMSes auto-generate one; static-site frameworks need a build-step plugin. Reference it from robots.txt and submit in Search Console to confirm Google can fetch it.
Source: sitemaps.org / Google Search Central
User-agent: *
Disallow: /embed
Disallow: /api/
User-agent: PetalBot
Disallow: /
Sitemap: https://www.nick.com/xmlsitemap/video
Sitemap: https://www.nick.com/xmlsitemap/episode
Sitemap: https://www.nick.com/xmlsitemap/game
Sitemap: https://www.nick.com/xmlsitemap/hub
No sitemap found
Adding a sitemap helps search engines discover your pages.
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencenick.com — via MarkMonitor Inc., 29 years, 9 months oldPASS
171 days
December 4, 2026
74 days
Issued by Let's Encrypt
29 years, 9 months
Registered December 5, 1996
Not enabled
Protects against DNS spoofing
Unknown
2600:1f18:297:ba24:b508:76de:f4a:df34
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice