Skip to content
RequestGuard Domain Intelligence
Pricing

Domain intelligence

Security Report for whatsapp.com

A closer look at this domain’s security, infrastructure, and public records. Findings first, with the evidence behind every result.

Explore the report
Website security grade B 87/100

Website Security

HTTPS, browser protections, DNS controls and known threats

Grade B #4 of 73

Good website security

The main protections are in place, with a few settings left to improve.

B87/100

Secure connection

Strong

40/40

Browser protections

Weak

25/30

Domain protection

Weak

7/15

Known threats

Strong

15/15

Fix these first

  1. 1

    DNSSEC

    0/8

    To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.

  2. 2

    Referrer policy

    0/5

    To earn 5/5, send Referrer-Policy: strict-origin-when-cross-origin. no-referrer, same-origin, and strict-origin also receive full points.

Strongest results

  • HTTPS response

    15/15

    HTTPS returned status 200.

  • Valid TLS certificate

    10/10

    The TLS certificate is valid for this domain.

  • Content security policy

    10/10

    An enforced Content-Security-Policy limits script sources.

All 15 security checks

Every result is shown, with what it means and how to fix it.

Working

HTTPS response

HTTPS returned status 200.

15/15
Working

Valid TLS certificate

The TLS certificate is valid for this domain.

10/10
Working

HTTP redirects to HTTPS

HTTP redirects to HTTPS.

5/5
Working

Modern TLS

TLSv1.3 was negotiated.

5/5
Working

Strict transport security

Strict-Transport-Security covers at least 180 days.

5/5
Working

Content security policy

An enforced Content-Security-Policy limits script sources.

10/10
Working

Frame protection

The response limits which sites may frame it.

5/5
Working

Content type protection

Content type sniffing is disabled.

5/5
Needs attention

Referrer policy

Referrer-Policy is missing.

To earn 5/5, send Referrer-Policy: strict-origin-when-cross-origin. no-referrer, same-origin, and strict-origin also receive full points.

0/5
Working

Browser permissions policy

Common sensitive browser capabilities are disabled by default.

5/5
Needs attention

DNSSEC

DNSSEC validation data was not found.

To earn 8/8, enable DNSSEC at the DNS provider and publish its DS record through the registrar; then confirm the delegation validates without errors.

0/8
Working

Certificate authority restriction

CAA records restrict certificate issuance.

7/7
Working

Known malware reports

No active malware-distribution URL was reported.

6/6
Working

Threat-blocking DNS

3 threat-protection resolvers returned the domain.

5/5
Working

Domain blocklists

The domain did not match the checked domain blocklists.

4/4

This dated automated check does not verify the business, its content, or every page. The score describes the configuration observed during this scan.

Badges and embed code
Embed code
<a href="https://requestguard.com/domain/whatsapp.com/">
  <img src="https://requestguard.com/domain/whatsapp.com/badges/security.svg" alt="Website security grade for whatsapp.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/whatsapp.com/#infrastructure">
  <img src="https://requestguard.com/domain/whatsapp.com/badges/location.svg" alt="Network location for whatsapp.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/whatsapp.com/">
  <img src="https://requestguard.com/domain/whatsapp.com/badges/trust.svg" alt="Trust badge for whatsapp.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Embed code
<a href="https://requestguard.com/domain/whatsapp.com/#whois">
  <img src="https://requestguard.com/domain/whatsapp.com/badges/domain-rating.svg" alt="Domain Rating for whatsapp.com" width="160" height="44" loading="lazy" decoding="async" fetchpriority="low">
</a>
Use these results through the API

API requests require a workspace key and a plan with Lookups access.

The hosted badge updates after a manual scan. A downloaded badge stays static and avoids contacting RequestGuard on page views.

Search visibility

Homepage signals that can affect crawling and indexing

Needs review

Needs review

Some homepage signals need a closer look. Review the recommendations below.

6 homepage checks · Unscored

Observed request

https://www.whatsapp.com/

Clear

Automated crawler access

The identified crawler received HTTP 200 for the homepage.

Review

Indexing directives

No noindex directive was found in the captured part of the response, but the HTML exceeded the scan limit.

Keep robots metadata in the document head and confirm the rendered page with Google Search Console URL Inspection.

Clear

robots.txt homepage rule

No robots.txt rule blocking Googlebot from the homepage was found.

Clear

Canonical URL

The canonical URL stays on whatsapp.com and matches the homepage path.

Clear

Search-readable HTML

The initial HTML contains a title and visible page content.

Clear

Sitemap discovery

robots.txt declares 1 sitemap.

This is not a Google index lookup. RequestGuard tests public signals with an identified automated crawler. Only URL Inspection for a verified Google Search Console property can confirm Google's last crawl, selected canonical, and indexing decision.

Open Google's URL Inspection guide

Cached result

Public exposure

Sensitive files and public administrative interfaces

Unscored

Not checked—run a website scan.

Checks 100 common paths and up to 50 technology-specific paths. Opening this report does not start exposure checks.

These are bounded, unauthenticated crawler observations, not a penetration test. A public login is not automatically a vulnerability. Secret values are discarded. Findings do not affect your security score.

Server Infrastructure

Resolved addresses, networks, and hosting providers

Loading infrastructure evidence

DNS Records

A, AAAA, MX, and resolving certificate hostnames, with other record types on demand

Loading DNS records

Email & DNS Security

MX, SPF, DMARC, DNSSEC, and CAA posture

Loading email and DNS posture

WHOIS & Registrar

Registration details via RDAP

RDAP

Registered 18.1 years ago

Registration history and published ownership records. Domain age and Domain Rating are context, not a security verdict.

Registrar

RegistrarSafe, LLC

Abuse: abusecomplaints@registrarsafe.com

Registration dates

Domain age

18.1 years

Created

Sep 4, 2008

Updated

Sep 20, 2026

Expires

Sep 4, 2034

Registrant

Name Domain Admin
Organization WhatsApp LLC
Email domain@fb.com
Phone +1.4089405686
Location US Menlo Park, CA, US

Domain status

Registry status codes — green means the owner locked out unauthorized changes

Delete locked Transfer locked Update locked Registry delete lock Registry transfer lock Registry update lock

Checked

Reputation & DNS filtering

Resolver behavior, domain datasets, and server-IP evidence

No threat match

Resolver summary

No match found in 3 checked threat-protection resolvers.

Checked . No-match results apply only to the sources that returned comparable evidence.

Resolver filtering records provider behavior. It does not by itself prove that a domain is malicious.

Resolver matrix

Five public filtering policies compared with neutral DNS

5 comparable · 0 unavailable

Threat protection

Malware and phishing policy

Ads & tracking

Mixed privacy and security policy

Family / content

Content and security policy

Reputation datasets

URL and domain-list evidence, separate from resolver policy

0 of 1 active matches
URLhaus No match

Reported malware-distribution URLs

SURBL (via URLhaus) Unavailable

URLhaus metadata; this is not a direct SURBL query

Spamhaus DBL (via URLhaus) Unavailable

URLhaus metadata; this is not a direct Spamhaus DBL query

Server-IP DNSBL checks & threat feeds IE 57.144.111.32

DNSBL and network-feed matches do not determine the domain verdict. Shared hosting, reverse proxies, and CDNs can put unrelated domains on the same address.

0 of 4 matched, 6 unavailable

Barracuda

b.barracudacentral.org

No match

SpamCop

bl.spamcop.net

No match

UCEPROTECT L1

dnsbl-1.uceprotect.net

No match

DroneBL

dnsbl.dronebl.org

No match

X4B VPN ranges

raw.githubusercontent.com

Feed file is unavailable

Unavailable

X4B datacenter ranges

raw.githubusercontent.com

Feed file is unavailable

Unavailable

Tor exit nodes

check.torproject.org

Feed file is unavailable

Unavailable

Team Cymru fullbogons IPv4

team-cymru.org

Feed file is unavailable

Unavailable

Spamhaus DROP IPv4

www.spamhaus.org

Feed file is unavailable

Unavailable

Feodo Tracker C2

feodotracker.abuse.ch

Feed file is unavailable

Unavailable

NextDNS and other custom profiles are not tested because their result depends on enabled lists, security settings, and parental controls. Check the provider log for the exact rule.

Cached result