Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.CIPv6 ReadinessActionNo IPv6 supportREVIEW
IPv6 support is increasingly important for global accessibility. About 40% of internet users have IPv6 connectivity.
No AAAA records — same impact as 'no IPv6 (AAAA) records'; IPv6-preferring clients pay extra latency falling back to IPv4.
Source: Google IPv6 stats
BTLS Certificate Expiry & Recommendations50 days until leaf cert expires — 4 issues to addressREVIEW
Certificate validity
Recommended actions
- Add includeSubDomains to the HSTS directive
- Add the preload directive and submit to hstspreload.org once max-age + includeSubDomains are in place
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
A+DNS Records2 A records, 97 ms lookupPASS
| A | 172.64.150.213, 104.18.37.43 |
| AAAA | — |
| CNAME | — |
| NS | kara.ns.cloudflare.com, jim.ns.cloudflare.com |
| MX | 1 aspmx.l.google.com 5 alt2.aspmx.l.google.com 10 aspmx3.googlemail.com 10 aspmx2.googlemail.com |
| TXT | _nrmjrlkwyszgkqbmfx81licw2kmxzow docker-verification=3273bf3c-471f-4ac7-a2f4-df07ad1b8d48 canva-site-verification=_WIxJdNmxl6VqSBYyDjUCA google-site-verification=B-Btjk-77YDTHz9oAG-Mh0DO2Vm-rTeJQN5KGYxsFus google-site-verification=M6hOtehJSoyxeogONWn71iYsV-R45rZh3IYATuc1roc 1fnhf0prfq7z2044j8r9x3sk9zf8g633 c4fmy14y8y7dtbnwtpw1cmr1503g64c4 apple-domain-verification=eZxVv8GkPbj1emuV g9wc23jgjsscsxqxz3h5trypft90rjd4 adobe-idp-site-verification=1ddcce3ad118fce5e72e9e3800b13b44a6dcadd28796cfc1b8bd... t7935hqjxrbsg6lhvxpymqwhzx3wz32t jamf-site-verification=Fd2Vp7x-bxVmqwiUtnW8AA MS=ms46413913 wrr2q64mqr7jrxqjzt6qflq2d89d391s cnjvqz73kch4r7hkz8fgxs4198vxbbjl miro-verification=a53d6fe59bd5411e3df40b35f894611817d07e6d drift-domain-verification=a3cdeb0f82279fd70b4bad1f5a8350e515feca6d93aef93c6e0fcd... cursor-domain-verification-qapwwg=q7ruwFAUovUbr3VxoCRxzDBzh 6y4l59sk7n7wbbhsdggz91kf6wts19dm google-site-verification=5trLJFGk1-V6eA1Ywp8nCR59bbivFFlugRn7CQj3vAw SPF v=spf1 ip4:104.18.36.22 ip4:149.72.22.42 ip4:66.102.0.0/20 ip4:74.125.0.0/16 ip4... google-site-verification=IEo383bwWgfkCwftM0janzuymSRM46MJ3kKMpAQ8xu8 insomnia-validation=92e0cc29397b41f0ba8bbf3767bf71a07ba2763175e1574b8257f93459f3... parsec-domain-verification=td_35c3hwTUWMNyoi44MRaKrojoo6w zapier-domain-verification-challenge=33cb2c31-3d2e-49fb-b101-3b33d8c47021 docusign=986c4e3e-cb44-497b-9ae3-556c71766145 pendo-domain-verification=da8ec78f-8fd2-4428-a442-9ce65ff01aaa facebook-domain-verification=6yaak3k1wnwbbc1nsmjv9eht3c58vt 679876c3-ae88-483e-aa5c-f1d0da5b19c9 docusign=1749d088-e0ca-4612-b2fd-6ee7acecd61f 1password-site-verification=NRXXKB5TT5CUJFLNMPYKGDJGOI |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
A+Redirect ChainNo redirects — direct accessPASS
https://wpengine.com
674 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://wpengine.com | 200 | 674 ms | HTTP/1.1 | cloudflare |
A+Crawlabilityrobots.txt present, sitemap with 12 URLsPASS
# Routed from 4.0
# Apply to all bots
crawl-delay: 5
User-agent: *
# Block the admin area but allow ajax callbacks
Disallow: /wp-admin/
Allow: /wp-admin/admin-ajax.php
# WEB-3507 Rationale unknown
Disallow: */*/audio/
Disallow: /site.webmanifest
# WEB-5082 Google has a number of junk URLs to both of these paths
Disallow: /solution-center/tag/
# Prevent builder calendar filters to be crawled
Disallow: /*/2023-
Disallow: /*/day/
Disallow: /*eventDisplay
# To optimize crawl budget for SEO
Disallow: /*/?__hstc=
Disallow: /*/?utm_
Disallow: /*/?nabe=
Disallow: /*/?print
Disallow: /*/?wtime=
Disallow: /*/?coupon=
Disallow: /*/?wvideo=
Disallow: /*/?_hsenc=
Disallow: /*/?local-download=
Disallow: /*/?_ga=
Disallow: /*/?es_p=
Disallow: /*/?w_agcid=
Disallow: /*/?kaid=
Disallow: /*/?tribe-bar-date=
Disallow: /*/?amp=
Disallow: /*/?fl_rand_seed=
Disallow: /*/?clientId=
Disallow: /*/?budget=
Disallow: /*/?ss-track=
Disallow: /*/?language=
Disallow: /*/?inf_contact_key=
Disallow: /*/?ref=
Disallow: /*/?s=
Disallow: /*/?sa=
Disallow: /*/?a=
Disallow: /*/?p=
Disallow: /*/?_gl=
Disallow: /*/?cid=
Disallow: /*/?o=
# Block 404s coming from other sites (added 6 Nov 24)
Disallow: /page/
# Link to Yoast sitemaps
Sitemap: https://wpengine.com/sitemap_index.xml
Sitemap: https://wpengine.com/builders/sitemap_index.xml
Sitemap: https://wpengine.com/sitemap-au.xml
Sitemap: https://wpengine.com/sitemap-ca.xml
Sitemap: https://wpengine.com/sitemap-dk.xml
Sitemap: https://wpengine.com/sitemap-fi.xml
Sitemap: https://wpengine.com/sitemap-fr.xml
Sitemap: https://wpengine.com/sitemap-gb.xml
Sitemap: https://wpengine.com/sitemap-ie.xml
Sitemap: https://wpengine.com/sitemap-nl.xml
Sitemap: https://wpengine.com/sitemap-us.xml
Sitemap: https://wpengine.com/case-studies/case-studies-sitemap.xml
Sitemap: https://wpengine.com/solution-center/page-sitemap.xml
Sitemap: https://wpengine.com/solution-center/solution-sitemap.xml
Sitemap: https://wpengine.com/support/support-sitemap.xml
Sitemap: https://wpengine.com/resources/sitemap_index.xml
- https://wpengine.com/post-sitemap.xml
- https://wpengine.com/post-sitemap2.xml
- https://wpengine.com/page-sitemap.xml
- https://wpengine.com/event-sitemap.xml
- https://wpengine.com/press_release-sitem...
- https://wpengine.com/audience-sitemap.xm...
- https://wpengine.com/blog-category-sitem...
- https://wpengine.com/buyer-stage-sitemap...
- https://wpengine.com/company-and-culture...
- https://wpengine.com/location-sitemap.xm...
- https://wpengine.com/persona-sitemap.xml
- https://wpengine.com/author-sitemap.xml
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
Preferred variant: non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencewpengine.com — via MarkMonitor Inc., 16 years, 4 months old, hosted on CloudflarePASS
268 days
March 10, 2027
50 days
Issued by Google Trust Services
16 years, 4 months
Registered March 10, 2010
Not enabled
Protects against DNS spoofing
Cloudflare
ASN AS13335
172.64.150.213
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice