Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.FRedirect ChainAction3 redirect(s), 1299 ms totalFIX
https://popsockets.com
192 ms · HTTP/1.1
https://www.popsockets.com/
286 ms · HTTP/1.1
https://www.popsockets.com/on/demandware...
127 ms · HTTP/1.1
https://www.popsockets.com/fr_FR/home?gl...
694 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://popsockets.com | 301 | 192 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.popsockets.com/ | 302 | 286 ms | HTTP/1.1 | cloudflare |
| 3 | https://www.popsockets.com/on/demandware... | 301 | 127 ms | HTTP/1.1 | cloudflare |
| 4 | https://www.popsockets.com/fr_FR/home?gl... | 200 | 694 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
Each redirect adds latency. Try to minimize the chain to 1 hop.
Redirect chain — each hop adds latency; combine into one redirect where possible.
Source: Google Search Central / web.dev
If permanent, use 301 instead.
302 (Found) is for genuinely temporary redirects — if this redirect is permanent, switch to 301 to preserve SEO equity.
Learn more ▾ ▴
Search engines treat 302 as temporary, keeping the original URL indexed and not transferring full link equity to the destination. Use 301 (Moved Permanently) for permanent redirects (HTTP→HTTPS, www-vs-non-www, URL restructures).
Source: Google Search Central
CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations192 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Prefer TLS 1.3 — TLS 1.2 is acceptable but TLS 1.3 removes RSA key exchange and improves latency
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 85 ms lookupPASS
| A | 104.17.68.195, 104.17.67.195 |
| AAAA | — |
| CNAME | — |
| NS | ns35.domaincontrol.com, ns36.domaincontrol.com |
| MX | 0 popsockets-com.mail.protection.outlook.com |
| TXT | klaviyo-site-verification=WC9S9N MS=ms83438802 rm_verify=56d3ef8e16 google-site-verification=UleViP11t7OuV-kvrgTerxPX7yujfGnn4BYibKEIZH4 klaviyo-site-verification=SJrk2r facebook-domain-verification=74hqng7bfutsljs6gtovgrcubtmzrf google-site-verification=23yWaMIHajQ7WgN9gGwZPlIidDxbwSSlq-gn7d1ecwY klaviyo-site-verification=VRLjBk google-site-verification=buNhmaxTP-LkjqBzJIhjzYn4cRQXe_g5FPVHK2PERKQ klaviyo-site-verification=TB6tdW klaviyo-site-verification=SGh8vA klaviyo-site-verification=V2Biqu ms-domain-verification=6c16a4cb-2959-4f20-9188-d2df15ae05a9 google-site-verification=-L5yw0szpnS3tCbEd9XMirtUrHG1Xtivc2Ia7FXPUnk google-site-verification=cKz60wWCwrQRCiQUvv1829XmWpRzPyarPbrKOmJVyAM google-site-verification=i9_0O6vfIkwBf4Sb0AQo5flRkN5k903gYssNNk35xxs google-site-verification=19eCDWbDX-Dtl11S26I6IlMoZkCg3tb1rGW68_SkW5o MS=0A5A0E967D5DD7659A9C50102221D742F044B6C4 klaviyo-site-verification=SbNgwi amazon-business-verification=5ccf4714cf126d057d03df18900be95b2b0a379ea9d33024418... pinterest-site-verification=4a3a068803b60646df07ca8faf6a8830 klaviyo-site-verification=TWQJvG klaviyo-site-verification=QZgs7V v=verifydomain MS=1896804 SPF v=spf1 ip4:205.182.163.3 include:_spf.google.com include:spf.protection.outlook.... docusign=e850f8ba-ed00-4920-b1a2-4198eb9fdd6f atlassian-domain-verification=XPaW9cGGiWVaYuftRMYi0HE/QSR1quhCxvrOxSVvQxgh8MlTkX... klaviyo-site-verification=UdhmnP apple-domain-verification=Cy8oSumVrnzG9c83 klaviyo-site-verification=WG2mKC klaviyo-site-verification=Yzj426 google-site-verification=Jr1WvHI0Em9Rh7__U6l_tBHut6HRnYi75NLPbZqIxH0 klaviyo-site-verification=RsnPmq MS=ms71165352 klaviyo-site-verification=RYELzB |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Crawlabilityrobots.txt present, sitemap with 1 URLsPASS
User-agent: Pingdom
Disallow: /
User-agent: Googlebot-image
Allow: /
User-agent: *
# Prevent indexing of raw search refinements, price ranges, sorting rules
Disallow: /*prefn*
Disallow: /*prefv*
Disallow: /*pmin=*
Disallow: /*pmax=*
Disallow: /*srule=*
# Prevent indexing of un-aliased storefront URLs
Disallow: /*demandware.store*
# Prevent indexing of checkout and cart sessions
Disallow: /cart*
Disallow: /checkout*
Allow: /
# Taxonomy Sitemaps
Sitemap: https://www.popsockets.com/sitemap_index.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencepopsockets.com — via GoDaddy.com, LLC, 14 years, 10 months old, hosted on CloudflarePASS
293 days
April 5, 2027
192 days
Issued by Sectigo Limited
14 years, 10 months
Registered August 20, 2011
Not enabled
Protects against DNS spoofing
Cloudflare
ASN AS13335
104.17.67.195
GoDaddy.com, LLC
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033