arsmate.com — domain analysis
arsmate.com is a live website built on Nuxt, registered in 2019, served from Toronto, Canada. It has a valid HTTPS certificate, 6 of 6 common security headers.
Does arsmate.com publish the usual trust pages?
All four of the pages a established business normally publishes were found:
about, contact, privacy and terms.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does arsmate.com compare with other domains analysed here?
Measured against the 79 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 82% of them (median 378ms) |
|---|---|
| Security headers | More than 98% of them |
| Domain age | Older than 20% of them |
Related domains in this index
Analysed domains sharing the same network (AS13335 Cloudflare, Inc.):
- autotalli.com
- barba365.com
- buzbeast.com
- cimri.com
- enuygun.com
- fry99.com
- globalfollowers.com
- golden.com
Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.
Analysed domains built on a similar stack:
Other analysed domains served from the same country:
When was arsmate.com registered?
arsmate.com was registered on 7 May 2019, which makes it about 7 years old.
The registrar of record is NameCheap, Inc..
Registration runs until 7 May 2027.
The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.
| Registered | 7 May 2019 |
|---|---|
| Expires | 7 May 2027 |
| Registrar | NameCheap, Inc. |
| Registry status | client transfer prohibited |
Where is arsmate.com hosted?
The first address resolves to infrastructure in Toronto, Canada.
The network is operated by Cloudflare, Inc. (AS13335 Cloudflare, Inc.).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is arsmate.com running on?
arsmate.com exposes 3 identifiable technologies: Nuxt, X-Powered-By: Nuxt, Cloudflare.
The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.
Cloudflare sits in front of the origin, so the server header, IP addresses and response timing describe the edge rather than the machine actually running the site.
- Nuxt
- X-Powered-By: Nuxt
- Cloudflare
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 109ms to first byte this response is fast for a homepage measured from a single European location.
At 5KB the HTML is unusually small, which typically means the page builds itself client-side after load.
The HTML is compressed with gzip.
| Server header | cloudflare |
|---|---|
| Compression | gzip |
| Page size | 5,457 bytes |
| Declared language | not declared |
| Mobile viewport | declared |
What does the homepage say about itself?
The title is only 7 characters, which is short enough that it probably is not describing the page so much as naming it.
There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.
No H1 heading was found, so the page offers no single top-level statement of what it is.
The html element declares no lang attribute, which removes a signal both screen readers and translation tools rely on.
| Title | Arsmate (7 chars) |
|---|---|
| Meta description | — none — (0 chars) |
| H1 | — none — (0 on the page) |
| Canonical | not set |
| Open Graph title | not set |
| Headings / images | 0 H2s, 0 images (0 without alt text) |
Is arsmate.com served over a valid certificate?
The HTTPS certificate is issued by Google Trust Services and is
valid until 2026-11-16, which is 42 days from the date of this check. It covers
1 hostname.
- arsmate.com
The certificate has 42 days left to run.
It covers 1 hostname, so it was issued for this site specifically.
Which security headers does it set?
All 6 headers checked are set, which is uncommon and indicates someone configured them deliberately.
| Header | Set | Value |
|---|---|---|
| HSTS | yes | max-age=31536000; includeSubDomains; preload |
| Content Security Policy | yes | default-src 'self'; script-src 'self' 'unsafe-inline' 'unsafe-eval' blob: https://unpkg.com https://cdn.jsdelivr.net htt |
| X-Content-Type-Options | yes | nosniff |
| X-Frame-Options | yes | DENY |
| Referrer-Policy | yes | strict-origin-when-cross-origin |
| Permissions-Policy | yes | camera=(self), microphone=(self), geolocation=() |
How is DNS configured for arsmate.com?
| IP addresses | 172.66.147.198, 104.20.47.1, 2606:4700:10::ac42:93c6, 2606:4700:10::6814:2f01 |
|---|---|
| Reverse DNS | 172.66.147.198, 104.20.47.1 |
| Name servers | mack.ns.cloudflare.com, elisabeth.ns.cloudflare.com |
| Mail (MX) | ALT1.ASPMX.L.GOOGLE.com (pri 5), ALT2.ASPMX.L.GOOGLE.com (pri 5), ASPMX.L.GOOGLE.com (pri 1), ALT3.ASPMX.L.GOOGLE.com (pri 10), ALT4.ASPMX.L.GOOGLE.com (pri 10) |
| SPF | v=spf1 a mx a:mailer.arsmate.com -all |
| TXT records | 2 |
arsmate.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.
Mail is handled by 5 exchangers.
An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.
Reverse DNS resolves to 172.66.147.198, 104.20.47.1, which usually names the hosting provider.
Who runs DNS and mail for arsmate.com?
DNS is operated by Cloudflare rather than self-hosted name servers.
Mail is handled by Google Workspace.
The domain publishes AAAA records and accepts connections over IPv6.
What else is worth noting about arsmate.com?
1 of 2 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.
The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.
Can arsmate.com be spoofed in email?
DMARC is published with p=none, which monitors but does not act. Forged mail is still delivered; the owner just gets reports about it.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What does robots.txt allow?
robots.txt is 183 bytes and names
2 user-agent groups.
It does not blanket-disallow general crawlers.
No sitemap is declared in robots.txt.
AI crawler policy
robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.
What structured data does the homepage publish?
No JSON-LD or microdata was found on the homepage.
What does arsmate.com load from third parties?
The homepage pulls resources from 4 third-party hosts (challenges.cloudflare.com, fonts.googleapis.com, fonts.gstatic.com, static.cloudflareinsights.com). Each one sees the visitor IP and user agent on every page load.
No cookies are set on first load.
Does arsmate.com settle on one address?
Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.
The www address redirects to https://arsmate.com/, so the site settles on one canonical hostname.
How easily can arsmate.com be crawled?
No readable sitemap was found, so crawlers have to discover every page by following links.
A deliberately invalid URL returns HTTP 200 rather than 404. That is a soft 404: every mistyped or stale link becomes an indexable page, which inflates the site with duplicates.
What tracking does arsmate.com run?
No analytics or advertising trackers were detected on the homepage of arsmate.com, which is unusual for a commercial site.
How does arsmate.com look when shared?
No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.
How are images, fonts and scripts handled?
Fonts are loaded from Google Fonts, which means every page view also contacts Google. Self-hosting removes that dependency.
The page pulls 2 external stylesheets and 3 external scripts, with 1 carrying defer or async.
Responses carry Cloudflare edge headers, so content is served from a CDN rather than straight from the origin.
Is arsmate.com accessible and current?
The page uses 0 landmark elements and 0 ARIA attributes.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
Can search engines index arsmate.com?
Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.
No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.
Visible text is only 1.1% of the HTML, which indicates the page is assembled in the browser rather than served as content.
How is arsmate.com delivered?
No Cache-Control header is sent for the HTML, so caching behaviour is left to browser defaults.
Frequently asked questions
Does arsmate.com set the usual HTTP security headers?
Yes — all 6 headers checked are present.
Does arsmate.com allow AI crawlers?
robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.
What is arsmate.com built with?
The homepage exposes these fingerprints: Nuxt, X-Powered-By: Nuxt, Cloudflare. A site behind a CDN or rendered server-side may use more than it reveals.
Where does this data come from?
Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own arsmate.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 4 October 2026.
Analyse another domain →
⚠ নিরাপদ থাকুন
জানি একটি স্বাধীন গাইড, কোনো সরকারি ওয়েবসাইট নয়। প্রকৃত কাজটি শুধু অফিসিয়াল পোর্টালেই করুন। যিনি ফোন, মেসেজ বা "সহায়তা"র নামে আপনার NID নম্বর, OTP, পাসওয়ার্ড বা কার্ডের তথ্য চান — কাউকে তা দেবেন না; কোনো প্রকৃত সংস্থা এসব চায় না।
জানি একটি স্বাধীন গাইড এবং কোনো সরকারি সংস্থার সাথে সম্পৃক্ত নয়। ফি, লিংক ও ধাপ পরিবর্তন হতে পারে — কাজ করার আগে সবসময় অফিসিয়াল পোর্টালে নিশ্চিত করে নিন। এটি সাধারণ তথ্য, আইনি বা আর্থিক পরামর্শ নয়।