Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.DHTTP Probe TimingActionTotal 2526 ms — DNS, TCP, TLS, TTFB, content transfer breakdownFIX
Connection waterfall
DCDN & DeliveryActionNo CDN detectedFIX
Consider using a CDN to improve global delivery speed and reduce origin load.
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations82 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records1 A records, 101 ms lookupPASS
| A | 192.0.66.32 |
| AAAA | — |
| CNAME | — |
| NS | ns-1469.awsdns-55.org, ns-112.awsdns-14.com, ns-1696.awsdns-20.co.uk, ns-670.awsdns-19.net |
| MX | 10 mxa-00596a01.gslb.pphosted.com 10 mxb-00596a01.gslb.pphosted.com |
| TXT | ZOOM_verify_59WiJX6USMK92Hbu6-iuEg gc-ai-domain-verification-pqnv2r=6l7d3qRIy8sKfMz0EsSBxqr80 google-site-verification=Ut_6-La1_H3SIW8cw3Jxn5gBHjCOb1mEm5wEciI90j8 k=rsa; p=MIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQDiTxvTgpRaUPa3Zsawin7pRP+CPIij6s1... globalsign-domain-verification=E1A5DBF2B0DE3B53A5674C61CAB23AD2 pinterest-site-verification=8ee9ddd73c0b33e9c9606a95d1763cc7 yahoo-verification-key=ZGc2aNHEalcpUmqoYUCKock6uR7n971BQPyq+avH5js= google-site-verification=TfuBznU2bqij21_J2S6N2IDNQta9zajEFCIxJuh033J 64392d9425e042418ac52d053c1ecb2f google-site-verification=S57vRF8jMqWVb1wbslt1vZqTKLBQPRLeihUQGU4LQL4 google-site-verification=5uYHzCPszHHLF2QyFiup1p177WJxzsWoUNaUCs_fhkQ amazonses:nZi4yMmejKgD3iT0h5S+LGrgaQGq6NVUPnD4v+R9htc= globalsign-domain-verification=14BE65E00D7267440AC2843EDFF82780 atlassian-domain-verification=uNoIhBXurxzVlQa0FvK2t9Yld5byfvXbFRQaMToGvrieKjBdyl... openai-domain-verification=dv-zTDjYaeUtH0Z7a6WRNHJHPNH facebook-domain-verification=a5ak341y6mn6scu375wpuvy5h38u0 onetrust-domain-verification=e7aaac6a2eba4af5831f665fd4355b18 ValidationTokenValue=be3a705a-0d8d-4c88-91dc-0ebe1d8e2f6d amazonses:C+fSBo78zXZisXWUUbHRXRXY19xolN+ug+xevTtXL+k= google-site-verification=pkTc123LIT1uBNNTg9WvGeJjxI0rCnCzmcVYSeFyLFU google-site-verification=PN2Qi9bdkJ4SDeGCzwK6mosjk_cdEPkd-epRWHrqs7M globalsign-domain-verification=DC5FAF3AEB5DC469953A669244E3DABD figma-domain-verification=b411f1d2852c2c7e057a2d6d70fb22896f37ccc1412d1e1bb4f9da... google-site-verification=43S5hR4E09EYHuJ0EddR08WUtCjmPb3zJDOY1qaqieg apple-domain-verification=lPyM98oF1jmNh7Ts tollbit-domain-verification=80476469dd961d48a2f36d45785f7b4bf6823867c0b612c475a6... globalsign-domain-verification=015A85DB506CC703E147E2E1A8234FFA SPF v=spf1 include:%{ir}.%{v}.%{d}.spf.has.pphosted.com ~all google-site-verification=rqQNsAZmdVyYCBkD6XaUsf_6Aq8knJPcJ_AJm_15mSM adobe-idp-site-verification=7ef638bb68822798685f96e436bfc87a6f79319dd86369e447b8... apple-domain-verification=37Qe0gDvvRCGgED6VegwSRnviuX7KRbEhaVgN8IGXpQ ZOOM_verify_GgmxWj_4QZCCMGFMQbCp5Q knowbe4-site-verification=0694ce74005828dc4bb8b7299bfb6f61 |
| CAA | Lookup not available with standard resolver |
Multiple A records provide failover if one server goes down.
Single A record means a single point of failure — if that IP goes down, your site is unreachable until DNS TTL expires.
Learn more ▾ ▴
Add multiple A records for round-robin failover, or use a managed DNS provider with health-checked failover (Route 53, Cloudflare, NS1). Short TTL (60-300s) lets clients recover faster on outages.
Source: SRE practice / DNS architecture
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://nypost.com
7 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://nypost.com | 200 | 7 ms | HTTP/1.1 | nginx |
A+Crawlabilityrobots.txt present, sitemap with 0 URLsPASS
# NOTICE: Collection of content and other data on nypost.com through
# automated means is prohibited unless you have express written
# permission from NYP Holdings, Inc. and may only be conducted for the
# limited purpose contained in said permission.
#
# NYP Holdings, Inc. Terms of Use may be found at
# https://nypost.com/terms/
#
# If you would like to apply for permission to license the
# intellectual property and/or other materials of NYP Holdings, Inc.'s
# brands, please contact us at ip-permissions@nypost.com.
User-agent: *
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
Disallow: /wp-json/
Disallow: /wp-login.php
Disallow: /account/
Allow: /account/subscribe
User-agent: *
Disallow: /tag/credible/
Disallow: /personal-finance/
Disallow: /banking/
Disallow: /credit-cards/
Disallow: /loans/
Disallow: /personal-loans/
Disallow: /refinance-student-loans/
Disallow: /student-loans/
Disallow: /mortgages/
Disallow: /home-equity/
Disallow: /mortgage-rates/
Disallow: /mortgage-refinance/
User-agent: *
Disallow: /search/
Disallow: /horoscope/
Disallow: /*?x=
Disallow: /*?action=
Disallow: /*&action=
Disallow: /*?adid=
Disallow: /*&adid=
Disallow: /*?bitrate=
Disallow: /*&bitrate=
Disallow: /*?channel=
Disallow: /*&channel=
Disallow: /*?clipid=
Disallow: /*&clipid=
Disallow: /*?contentCollection=
Disallow: /*&contentCollection=
Disallow: /*?contentId=
Disallow: /*&contentId=
Disallow: /*?ei=
Disallow: /*&ei=
Disallow: /*?format=
Disallow: /*&format=
Disallow: /*?height=
Disallow: /*&height=
Disallow: /*?iframe=
Disallow: /*&iframe=
Disallow: /*?mediaId=
Disallow: /*&mediaId=
Disallow: /*?module=
Disallow: /*&module=
Disallow: /*?monthnum=
Disallow: /*&monthnum=
Disallow: /*?pgtype=
Disallow: /*&pgtype=
Disallow: /*?preview=
Disallow: /*&preview=
Disallow: /*?priority=
Disallow: /*&priority=
Disallow: /*?ref=
Disallow: /*&ref=
Disallow: /*?referrer=
Disallow: /*&referrer=
Disallow: /*?sa=
Disallow: /*&sa=
Disallow: /*?section=
Disallow: /*§ion=
Disallow: /*?share=
Disallow: /*&share=
Disallow: /*?TB_iframe=
Disallow: /*&TB_iframe=
Disallow: /*?TBL_Prod100Page=
Disallow: /*&TBL_Prod100Page=
Disallow: /*?theme_preview=
Disallow: /*&theme_preview=
Disallow: /*?usg=
Disallow: /*&usg=
Disallow: /*?ved=
Disallow: /*&ved=
Disallow: /*?version=
Disallow: /*&version=
Disallow: /*?VID=
Disallow: /*&VID=
Disallow: /*?vxBitrate=
Disallow: /*&vxBitrate=
Disallow: /*?vxChannel=
Disallow: /*&vxChannel=
Disallow: /*?vxClipId=
Disallow: /*&vxClipId=
Disallow: /*?vxSiteId=
Disallow: /*&vxSiteId=
Disallow: /*?width=
Disallow: /*&width=
Disallow: /*?year=
Disallow: /*&year=
Disallow: /*.xml?uuid=
Disallow: /*?post_type=feedback&p=
Disallow: /*?wptouch_preview_theme=
Disallow: /*>
Disallow: /?attachment_id=
Disallow: /affiliate/
Disallow: /ai_log/
Disallow: /*?*pg99.asia*
Disallow: /*&*pg99.asia*
Disallow: /*?*gg155.cn*
Disallow: /*&*gg155.cn*
Disallow: /*?*To66.Asia*
Disallow: /*&*To66.Asia*
User-agent: *
Disallow: /new-york-post-instagram-feed/
Disallow: /new-york-post-tiktok-feed/
Disallow: /alexa-new-york-post-instagram-feed/
Disallow: /alexa-new-york-post-tiktok-feed/
User-agent: Bytespider
Disallow: /
User-agent: CCBot
Disallow: /
User-agent: Claude-Web
Disallow: /
User-agent: ClaudeBot
Disallow: /
User-agent: FacebookBot
Disallow: /
User-agent: Google-Extended
Disallow: /
User-agent: MJ12bot
Disallow: /
User-agent: NewsNow
Disallow: /
User-agent: Perplexity-ai
Disallow: /
User-agent: PerplexityBot
Disallow: /
User-agent: PiplBot
Disallow: /
User-agent: anthropic-ai
Disallow: /
User-agent: cohere-ai
Disallow: /
User-agent: ia_archiver
Disallow: /
User-agent: magpie-crawler
Disallow: /
User-agent: news-please
Disallow: /
User-agent: omgili
Disallow: /
User-agent: omgilibot
Disallow: /
User-agent: meta-externalagent
Disallow: /
User-agent: meta-externalfetcher
Disallow: /
User-agent: A6-Indexer
Disallow: /
User-agent: AhrefsBot
Disallow: /
User-agent: anthropic-ai
Disallow: /
User-agent: Applebot-Extended
Disallow: /
User-agent: AwarioRssBot
Disallow: /
User-agent: AwarioSmartBot
Disallow: /
User-agent: BLP_bbot
Disallow: /
User-agent: claritybot
Disallow: /
User-agent: cohere-ai
Disallow: /
User-agent: DataForSeoBot
Disallow: /
User-agent: Diffbot
Disallow: /
User-agent: EasouSpider
Disallow: /
User-agent: ecoResearch
Disallow: /
User-agent: FriendlyCrawler
Disallow: /
User-agent: Genieo
Disallow: /
User-agent: ImagesiftBot
Disallow: /
User-agent: Meltwater
Disallow: /
User-agent: Meta-ExternalAgent
Disallow: /
User-agent: meta-externalagent
Disallow: /
User-agent: peer39_crawler
Disallow: /
User-agent: peer39_crawler/1.0
Disallow: /
User-agent: PetalBot
Disallow: /
User-agent: psbot
Disallow: /
User-agent: R6_CommentReader
Disallow: /
User-agent: Scrapy
Disallow: /
User-agent: Seekr
Disallow: /
User-agent: Spinn3r
Disallow: /
User-agent: TurnitinBot
Disallow: /
User-agent: WebVac
Disallow: /
User-agent: WebZip
Disallow: /
Disallow: /5850/
# Sitemap archive
Sitemap: https://nypost.com/sitemap-1865.xml
Sitemap: https://nypost.com/sitemap-1999.xml
Sitemap: https://nypost.com/sitemap-2000.xml
Sitemap: https://nypost.com/sitemap-2001.xml
Sitemap: https://nypost.com/sitemap-2002.xml
Sitemap: https://nypost.com/sitemap-2003.xml
Sitemap: https://nypost.com/sitemap-2004.xml
Sitemap: https://nypost.com/sitemap-2005.xml
Sitemap: https://nypost.com/sitemap-2006.xml
Sitemap: https://nypost.com/sitemap-2007.xml
Sitemap: https://nypost.com/sitemap-2008.xml
Sitemap: https://nypost.com/sitemap-2009.xml
Sitemap: https://nypost.com/sitemap-2010.xml
Sitemap: https://nypost.com/sitemap-2011.xml
Sitemap: https://nypost.com/sitemap-2012.xml
Sitemap: https://nypost.com/sitemap-2013.xml
Sitemap: https://nypost.com/sitemap-2014.xml
Sitemap: https://nypost.com/sitemap-2015.xml
Sitemap: https://nypost.com/sitemap-2016.xml
Sitemap: https://nypost.com/sitemap-2017.xml
Sitemap: https://nypost.com/sitemap-2018.xml
Sitemap: https://nypost.com/sitemap-2019.xml
Sitemap: https://nypost.com/sitemap-2020.xml
Sitemap: https://nypost.com/sitemap-2021.xml
Sitemap: https://nypost.com/sitemap-2022.xml
Sitemap: https://nypost.com/sitemap-2023.xml
Sitemap: https://nypost.com/sitemap-2024.xml
Sitemap: https://nypost.com/sitemap-2025.xml
Sitemap: https://nypost.com/sitemap-2026.xml
User-agent: FontReport
Allow: /
# Sitemaps
Sitemap: https://nypost.com/news-sitemap.xml
# Additional sitemaps
Sitemap: https://nypost.com/sitemap-nypost-edition.xml
Sitemap: https://nypost.com/sitemap-nypost-section.xml
Sitemap: https://nypost.com/sitemap-nypost-post_tag.xml
Sitemap: https://nypost.com/sitemap-nypost-authors.xml
Sitemap: https://nypost.com/sitemap-nypost-pages.xml
Sitemap: https://nypost.com/sitemap-nypost-sportstat.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencenypost.com — via MarkMonitor Inc., 29 years, 11 months old, hosted on WordPress.com (Automattic)PASS
104 days
September 28, 2026
82 days
Issued by Let's Encrypt
29 years, 11 months
Registered September 29, 1996
Not enabled
Protects against DNS spoofing
WordPress.com (Automattic)
ASN AS2635
192.0.66.32
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice