Infrastructure
· 9 checks — DNS, redirects, IPv6, crawlability, URL variants, and domain intelligence rolled into one auditable list.BTLS Certificate Expiry & Recommendations63 days until leaf cert expires — 3 issues to addressREVIEW
Certificate validity
Recommended actions
- Enable HSTS: Strict-Transport-Security: max-age=31536000; includeSubDomains
- Enable DNSSEC on your domain for DNS spoofing protection
- Enable OCSP stapling on your TLS server to remove a CA roundtrip and protect user privacy
BCDN & DeliveryCloudflareREVIEW
A+DNS Records2 A records, 90 ms lookupPASS
| A | 104.16.117.43, 104.16.118.43 |
| AAAA | 2606:4700::6810:762b, 2606:4700::6810:752b |
| CNAME | — |
| NS | rita.ns.cloudflare.com, tim.ns.cloudflare.com |
| MX | 10 mxb-0042bc01.gslb.pphosted.com 10 mxa-0042bc01.gslb.pphosted.com 50 us-smtp-inbound-1.mimecast.com 60 us-smtp-inbound-2.mimecast.com |
| TXT | asv=1d6c4fb60f2790b5d26fed0bb12bd115 hubspot-developer-verification=MWI1YTkyNDctODZmNi00MTBhLWE5MTYtNDBhMWEzZTQ2ODg3 asv=2d91cb2d6544d7a3891d743d45d5cc45 google-site-verification=gg10WGEg16Cp7M5hcqsTRxE0K_f34PWizql6mjRUOPg _n4k3s4c3lnx9uq8loq8e4qrgizqenc4 pendo-domain-verification=155ca67e-9833-4698-b886-9215b2431dea MS=ms65324670 google-site-verification=Ck8kCbNGwHAEOnj9O7xMBPG0WBXl1bTju9N2mvtpYWo google-site-verification=o9iKGrOMdBp_NYSpUvDUa4okJHX8lafcD0rCjFoyBTU _elastic_domain_challenge=6e1e719d7eb9dfeb13b9f6e7f64414e005d1a4da36c43074b06c0c... atlassian-domain-verification=nLP991XRIVfjHgLMjm0qm2oeZMikTd77NgfuPXxrIBqkkkTZgr... google-site-verification=-ukM4y3JvL3Toa2D44DXo_b5u7wwUhaaVYfFzPHzP5I google-site-verification=6mXTBuDHk-2Du-x2_EucW6isU05nrWXQne3jF5QsGU8 _qkt0vyeudqdmyimlu1sicmvr5yhojvo jamf-site-verification=6RDl4wTo2zo5foO4qIdvUQ 33904d6d-5e21-4a18-8e46-b170ae80b68e docusign=4e925286-966b-4869-81ec-23fbbe116a16 ecostruxure-it-verification=63b73ded-c9a0-43d5-a4bc-13bc4b86cdac 7s5ys3r5gsrzsm1lxdhgmp6903dfypp0 SPF v=spf1 include:_u.zoominfo.com._spf.smart.ondmarc.com -all facebook-domain-verification=8xqew8kv8q2qml8urdur3wijr5ginf brevo-code:3fc323c894e26fcbb4611b5486a7dba7 hubspot-developer-verification=NDNjNmJlZDYtNGVhOS00MGQxLWFlYjMtODkxZDY2NDc2NmY0 wiz-domain-verification=8df7ec58ab5c882d7d7bad1df1200d77f97a5c7f898ea1ef0904511e... airtable-verification=7d5c4bb1083aed6e27cd99985c49ac81 0ed1fe018a83a1a25394024dadbc718d52c026f8eb zapier-domain-verification-challenge=db195766-a847-4db2-b88a-459d5695aa90 MS=ms33572304 hUHXNRkPrDG/vT7H4SJCG2xTF9fMTKMhfuP72fEgCsrux2DijrADGxZIfaNs6lR/5qzfiHU+CyR6mSxG... verification=b384fc086e99452bad93e15dfbe59451 google-site-verification=460JvyZeIw91-DWG0ZEsnAGMxMiSPVug2qJcXevHCDE google-site-verification=Ykk1G2OZGjvrWYGXMqhUO9ADxZAa2u7wl2jM7-VRI8I postman-domain-verification=8eea31cc5b7cfbfff163d605845f51d65296766bb351bc622935... yahoo-verification-key=1mwvI3bkKwq2edAI3E6IBXFKZaucTzMI9n4ynwwKxC4= MS=ms38951267 google-site-verification=lBWYr74utT4FeN7oUCykhwiW1woGDhS7S0A4M7isQhA cisco-ci-domain-verification=75cb9074f645f91ce729c4564e1e073eaa626bf0466be6b5e80... smartsheet-site-validation=oCkvv_UFOL0zilzID65xfuiYGFuME7lx box-domain-verification=03a9187e13251fb31e146271331be39f6465c7691b6c597729582302... segment-site-verification=90RRtjxCS6RhpBwQXWa4KZwBygYQCOBT google-site-verification:m4g1eOID25e-EuZCXCXyalWrcskGHtkDMI3A4-0qjC0 google-site-verification=gA2P07VwyAI8D1HzwOO0Q7gVOnctkRTliJ8FxgWyjK8 |
| CAA | Lookup not available with standard resolver |
CAA record lookup requires a specialized DNS resolver. This check will be available in a future update.
Informational: CAA (Certification Authority Authorization) records weren't checked in this scan.
ARedirect Chain1 redirect(s), 340 ms totalPASS
https://zoominfo.com
59 ms · HTTP/1.1
https://www.zoominfo.com/
281 ms · HTTP/1.1 FINAL
| # | URL | Status | Time | Protocol | Server |
|---|---|---|---|---|---|
| 1 | https://zoominfo.com | 301 | 59 ms | HTTP/1.1 | cloudflare |
| 2 | https://www.zoominfo.com/ | 200 | 281 ms | HTTP/1.1 | cloudflare |
See the visual redirect chain in the HTTP Probe tab →
A+IPv6 ReadinessIPv6 reachable (17 ms)PASS
A+Crawlabilityrobots.txt present, sitemap with 22 URLsPASS
# /robots.txt file for /www.zoominfo.com
# /business sitemap
Sitemap: https://www.zoominfo.com/cws/general-sitemap.xml
# General Disallow Rules
User-agent: *
Disallow: /access
Disallow: /blog/api
Disallow: /verifyRegister
Disallow: /verifyRegisterConfirm
Disallow: /clearRegister
Disallow: /resendVerification
Disallow: /accountWelcome
Disallow: /account
Disallow: /myAccount
Disallow: /needVerify
Disallow: /myaccount
Disallow: /profile
Disallow: /profileReferences
Disallow: /claim
Disallow: /update/edit-person-profile
Disallow: /update/create-person-profile
Disallow: /update/remove-person-profile
Disallow: /update/edit-company-profile
Disallow: /update/create-company-profile
Disallow: /update/remove/verification-failure
Disallow: /update/request-access
Disallow: /update/company
Disallow: /blank
Disallow: /ie6
Disallow: /siteStatus
Disallow: /appExpired
Disallow: /appSuspended
Disallow: /notAuthorized
Disallow: /logout
Disallow: /resetPassword
Disallow: /changePassword
Disallow: /securityCode
Disallow: /common
Disallow: /CachedPageLoading
Disallow: /embeddedcontent
Disallow: /business/administrator
Disallow: /usercenter
Disallow: /blog/tag/
Disallow: /CachedPageHeader
Disallow: /search/company
Disallow: /s/css
Disallow: /s/common/css
Disallow: /anura
Disallow: /api
Disallow: /people_directory
Disallow: /directories-api
Disallow: /newsroom/press-releases/press-releases-*
Disallow: /newsroom/press-releases/*/feed
Disallow: /about/m/newsletters/*
Disallow: /c/company-name
Disallow: /pic/company-name
Disallow: /directories/transition
Disallow: /pixel
Disallow: /workers/data-layer.worker
Disallow: /about/search-cs
Allow: /c/undefined
# Bing Disallow Rules
User-agent: Bingbot
Disallow: /about/*query=*
# AI Bots Group - unified disallow rules
User-agent: AI2Bot
User-agent: Apple-Extended
User-agent: Bytespider
User-agent: CCBot
User-agent: ClaudeBot
User-agent: cohere-training-data-crawler
User-agent: Diffbot
User-agent: FacebookBot
User-agent: Google-Extended
User-agent: GPTBot
User-agent: Kangaroo Bot
User-agent: Meta-ExternalAgent
User-agent: Omgili
User-agent: PanguBot
User-agent: Timpibot
User-agent: Webzio-Extended
User-agent: ChatGPT-User
User-agent: DuckAssistBot
User-agent: Meta-ExternalFetcher
User-agent: Operator
User-agent: Applebot
User-agent: OAI-SearchBot
User-agent: PerplexityBot
User-agent: YouBot
Disallow: /p
Disallow: /c
Disallow: /pic
Disallow: /s/search
Disallow: /people-search
Disallow: /companies-search
Disallow: /people
Disallow: /people_directory
Disallow: /tech
Disallow: /sales-leads
Disallow: /lead-generation-tools
Disallow: /zoominfo-chrome-ext
# Full block bots
User-agent: Yandex
User-agent: dotbot
User-agent: rogerbot
User-agent: moget
User-agent: ichiro
User-agent: NaverBot
User-agent: Yeti
User-agent: Baiduspider
User-agent: Baiduspider-video
User-agent: Baiduspider-image
User-agent: sogou spider
User-agent: YoudaoBot
User-agent: MJ12bot
User-agent: DJEcoBot
User-agent: Amazonbot
User-agent: PetalBot
User-agent: AwarioSmartBot
User-agent: AwarioRssBot
User-agent: LinkedInBot
User-agent: FreshpingBot
User-agent: Pingdombot
User-agent: coccocbot-web
User-agent: coccocbot-image
User-agent: sethbot
User-agent: UptimeRobot
User-agent: Mail.RU_Bot
User-agent: heritrix
Disallow: /
# Zoominfo bots
User-agent: NextGenSearchBot
User-agent: ZoomBot
User-agent: ZoominfoBot
Disallow: /p
Disallow: /c
Disallow: /pic
Disallow: /top-lists
Disallow: /s/search
Disallow: /people-search
Disallow: /companies-search
Disallow: /people
Disallow: /people_directory
Disallow: /financial
Disallow: /tech
Disallow: /sales-leads
Disallow: /lead-generation-tools
Disallow: /zoominfo-chrome-ext
# Bots with Crawl-delay
User-agent: Bingbot
User-agent: DataForSeoBot
Crawl-delay: 1
- https://www.zoominfo.com/cws/sitemaps/ac...
- https://www.zoominfo.com/cws/sitemaps/ca...
- https://www.zoominfo.com/cws/sitemaps/ca...
- https://www.zoominfo.com/cws/sitemaps/co...
- https://www.zoominfo.com/cws/sitemaps/ev...
- https://www.zoominfo.com/cws/sitemaps/fa...
- https://www.zoominfo.com/cws/sitemaps/fe...
- https://www.zoominfo.com/cws/sitemaps/le...
- https://www.zoominfo.com/cws/sitemaps/le...
- https://www.zoominfo.com/cws/sitemaps/li...
- https://www.zoominfo.com/cws/sitemaps/ne...
- https://www.zoominfo.com/cws/sitemaps/of...
- https://www.zoominfo.com/cws/sitemaps/pa...
- https://www.zoominfo.com/cws/sitemaps/pl...
- https://www.zoominfo.com/cws/sitemaps/pl...
- https://www.zoominfo.com/cws/sitemaps/pr...
- https://www.zoominfo.com/cws/sitemaps/re...
- https://www.zoominfo.com/cws/sitemaps/re...
- https://www.zoominfo.com/cws/sitemaps/so...
- https://www.zoominfo.com/cws/sitemaps/te...
- https://www.zoominfo.com/cws/sitemaps/to...
- https://www.zoominfo.com/cws/sitemaps/tr...
A+URL Variantswww/non-www, trailing slash, HTTP→HTTPSPASS
www / non-www
HTTP → HTTPS
Consistent
A+Domain Intelligencezoominfo.com — via MarkMonitor Inc., 22 years, 10 months oldPASS
959 days
January 30, 2029
63 days
Issued by Let's Encrypt
22 years, 10 months
Registered October 16, 2003
Not enabled
Protects against DNS spoofing
Unknown
2606:4700::6810:752b
MarkMonitor Inc.
Expiry timeline
Recommended actions
- Enable DNSSEC to protect visitors from DNS spoofing
- Enable registrar lock (clientTransferProhibited) to block unauthorized domain transfers
DNSSEC protects against DNS spoofing attacks. While not required, enabling DNSSEC adds an additional layer of security. Contact your DNS provider to enable it.
Without DNSSEC, an attacker who can poison your DNS can hijack your domain — and SSL certs alone don't stop them.
Learn more ▾ ▴
DNSSEC adds cryptographic signatures to DNS records, preventing forged responses from poisoning resolver caches. Without it, an attacker who controls the network path can redirect your domain to a malicious server before any HTTPS handshake happens. Most modern registrars (Cloudflare, Google Domains, Route 53) enable it with one toggle.
Source: ICANN / RFC 4033
The domain can be transferred without an unlock step. Enable registrar lock (clientTransferProhibited) in your registrar's control panel to protect against unauthorized or accidental transfers.
Without registrar lock, an attacker who phishes your registrar credentials can transfer the domain in minutes — total brand hijack.
Learn more ▾ ▴
Registrar lock (clientTransferProhibited, clientUpdateProhibited, clientDeleteProhibited) requires extra verification before any transfer/update/delete. Every major registrar offers it free. Combined with 2FA on your registrar account, it's the strongest defense against domain hijacking.
Source: ICANN / domain-security best practice