Domain intelligence
Security Report for
A closer look at this domain’s security, infrastructure, and public records. Findings first, with the evidence behind every result.
Explore the reportWebsite Security
HTTPS, browser protections, DNS controls and known threats
Important protections are missing
Several public security settings need attention. Start with the highest-value fixes below.
Secure connection
Weak35/40
Browser protections
Weak0/30
Domain protection
Weak0/15
Known threats
Strong15/15
Fix these first
- 1
Content security policy
0/10To earn 10/10, send an enforced Content-Security-Policy header with script-src or default-src limited to 'self' and exact required hosts. Start in report-only mode, fix violations, then enforce the policy; report-only alone earns partial points.
- 2
DNSSEC
0/8To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.
- 3
Certificate authority restriction
0/7To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.
Strongest results
-
HTTPS response
15/15HTTPS returned status 404.
-
Valid TLS certificate
10/10The TLS certificate is valid for this domain.
-
Known malware reports
6/6No active malware-distribution URL was reported.
All 15 security checks
Every result is shown, with what it means and how to fix it.
HTTPS response
HTTPS returned status 404.
Valid TLS certificate
The TLS certificate is valid for this domain.
HTTP redirects to HTTPS
HTTP redirects to HTTPS.
Modern TLS
TLSv1.3 was negotiated.
Strict transport security
Strict-Transport-Security is missing.
To earn 5/5, send Strict-Transport-Security: max-age=15552000 or a larger max-age on HTTPS responses; 31536000 is a common one-year value.
Content security policy
Content-Security-Policy is missing.
To earn 10/10, send an enforced Content-Security-Policy header with script-src or default-src limited to 'self' and exact required hosts. Start in report-only mode, fix violations, then enforce the policy; report-only alone earns partial points.
Frame protection
No enforced frame restriction was found.
To earn 5/5, add frame-ancestors 'none' (or 'self' if same-site framing is required) to the enforced Content-Security-Policy. X-Frame-Options: DENY or SAMEORIGIN is also accepted.
Content type protection
X-Content-Type-Options: nosniff is missing.
To earn 5/5, send X-Content-Type-Options: nosniff on the homepage response.
Referrer policy
Referrer-Policy is missing.
To earn 5/5, send Referrer-Policy: strict-origin-when-cross-origin. no-referrer, same-origin, and strict-origin also receive full points.
Browser permissions policy
Permissions-Policy is missing.
To earn 5/5, disable all three tested capabilities: Permissions-Policy: camera=(), microphone=(), geolocation=(). Add separate directives for capabilities the site intentionally allows.
DNSSEC
DNSSEC validation data was not found.
To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.
Certificate authority restriction
No CAA record was found.
To earn 7/7, publish at least one CAA issue record for the CA you use, for example: CAA 0 issue "letsencrypt.org". Replace the CA name if another provider issues your certificate.
Known malware reports
No active malware-distribution URL was reported.
Threat-blocking DNS
3 threat-protection resolvers returned the domain.
Domain blocklists
The domain did not match the checked domain blocklists.
This dated automated check does not verify the business, its content, or every page. The score describes the configuration observed during this scan.
Badges and embed code
Embed code
<a href="https://requestguard.com/domain/prodregistryv2.org/">
<img src="https://requestguard.com/domain/prodregistryv2.org/badges/security.svg" alt="Website security grade for prodregistryv2.org" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> Embed code
<a href="https://requestguard.com/domain/prodregistryv2.org/#infrastructure">
<img src="https://requestguard.com/domain/prodregistryv2.org/badges/location.svg" alt="Network location for prodregistryv2.org" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> Embed code
<a href="https://requestguard.com/domain/prodregistryv2.org/">
<img src="https://requestguard.com/domain/prodregistryv2.org/badges/trust.svg" alt="Trust badge for prodregistryv2.org" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> Embed code
<a href="https://requestguard.com/domain/prodregistryv2.org/#whois">
<img src="https://requestguard.com/domain/prodregistryv2.org/badges/domain-rating.svg" alt="Domain Rating for prodregistryv2.org" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a> API requests require a workspace key and a plan with Lookups access.
The hosted badge updates after a manual scan. A downloaded badge stays static and avoids contacting RequestGuard on page views.
Search visibility
Homepage signals that can affect crawling and indexing
Obstacles found
The crawler found technical obstacles that may prevent access or indexing. Start with the flagged checks below.
6 homepage checks · Unscored
Observed request
Automated crawler access
The homepage returned HTTP 404, which says that the page is missing.
Serve the intended homepage with HTTP 200, then request validation in Google Search Console.
Indexing directives
No Google noindex directive was found in the response headers or sampled HTML.
robots.txt homepage rule
robots.txt returned HTTP 404. Google treats this as no crawl restrictions because the response is not 429.
Canonical URL
No HTML canonical link was found. This is not a block, but it leaves the preferred URL less explicit.
Add one absolute, self-referencing canonical URL to the homepage.
Search-readable HTML
The sampled homepage response used HTTP 404, so indexable page content was not available.
Return the public homepage content with HTTP 200.
Sitemap discovery
No XML sitemap declaration or conventional /sitemap.xml response was found. A sitemap is optional, but it helps discovery for new sites.
Publish an XML sitemap and declare it in robots.txt or submit it in Google Search Console.
This is not a Google index lookup. RequestGuard tests public signals with an identified automated crawler. Only URL Inspection for a verified Google Search Console property can confirm Google's last crawl, selected canonical, and indexing decision.
Open Google's URL Inspection guideCached result
Public exposure
Sensitive files and public administrative interfaces
Not checked—run a website scan.
Checks 100 common paths and up to 50 technology-specific paths. Opening this report does not start exposure checks.
These are bounded, unauthenticated crawler observations, not a penetration test. A public login is not automatically a vulnerability. Secret values are discarded. Findings do not affect your security score.
Server Infrastructure
Resolved addresses, networks, and hosting providers
DNS Records
A, AAAA, MX, and resolving certificate hostnames, with other record types on demand
Email & DNS Security
MX, SPF, DMARC, DNSSEC, and CAA posture
WHOIS & Registrar
Registration details via RDAP
Registered 2.4 years ago
Registration history and published ownership records. Domain age and Domain Rating are context, not a security verdict.
Registrar
Markmonitor Inc.
Registration dates
Domain age
2.4 years
Created
Apr 19, 2024
Updated
Sep 20, 2026
Expires
Apr 19, 2028
Registrant
Privacy protectedIdentity is hidden by a privacy service — standard practice under GDPR and similar laws, not on its own a sign of anything suspicious.
Some of the data in this object has been removed.
Domain status
Registry status codes — green means the owner locked out unauthorized changes
Checked
Reputation & DNS filtering
Resolver behavior, domain datasets, and server-IP evidence
Resolver summary
No match found in 3 checked threat-protection resolvers.
Checked . No-match results apply only to the sources that returned comparable evidence.
Resolver filtering records provider behavior. It does not by itself prove that a domain is malicious.
Resolver matrix
Five public filtering policies compared with neutral DNS
Threat protection
Malware and phishing policy
Ads & tracking
Mixed privacy and security policy
Family / content
Content and security policy
Reputation datasets
URL and domain-list evidence, separate from resolver policy
Reported malware-distribution URLs
URLhaus metadata; this is not a direct SURBL query
URLhaus metadata; this is not a direct Spamhaus DBL query
Server-IP DNSBL checks & threat feeds
34.128.128.0
DNSBL and network-feed matches do not determine the domain verdict. Shared hosting, reverse proxies, and CDNs can put unrelated domains on the same address.
Barracuda
b.barracudacentral.org
SpamCop
bl.spamcop.net
UCEPROTECT L1
dnsbl-1.uceprotect.net
DroneBL
dnsbl.dronebl.org
NextDNS and other custom profiles are not tested because their result depends on enabled lists, security settings, and parental controls. Check the provider log for the exact rule.
Cached result