swoosh.com — domain analysis
swoosh.com is a live website built on Next.js, registered in 1994, served from Frankfurt am Main, Germany. It has a valid HTTPS certificate, 3 of 6 common security headers.
What is swoosh.com about?
The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:
- welcome ×2
- swoosh ×2
Does swoosh.com publish the usual trust pages?
All four of the pages a established business normally publishes were found:
about, contact, privacy and terms.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does swoosh.com compare with other domains analysed here?
Measured against the 79 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 37% of them (median 378ms) |
|---|---|
| Security headers | More than 58% of them |
| Domain age | Older than 87% of them |
Related domains in this index
Analysed domains sharing the same network (AS16509 Amazon.com, Inc.):
Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.
Analysed domains built on a similar stack:
Other analysed domains served from the same country:
When was swoosh.com registered?
swoosh.com was registered on 17 November 1994, which makes it about 31 years old.
A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.
The registrar of record is MarkMonitor Inc..
Registration expires in 41 days (16 November 2026), which is close enough that a missed renewal would take the site offline.
The domain carries 3 registry locks, which blocks unauthorised transfer or deletion.
| Registered | 17 November 1994 |
|---|---|
| Expires | 16 November 2026 |
| Registrar | MarkMonitor Inc. |
| Registry status | client delete prohibited, client transfer prohibited, client update prohibited |
Where is swoosh.com hosted?
The first address resolves to infrastructure in Frankfurt am Main, Germany.
The network is operated by AWS CloudFront (GLOBAL) (AS16509 Amazon.com, Inc.).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is swoosh.com running on?
swoosh.com exposes 3 identifiable technologies: Next.js, React, X-Powered-By: Express.
The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.
- Next.js
- React
- X-Powered-By: Express
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 534ms to first byte this response is unremarkable for a homepage measured from a single European location.
The HTML weighs 86KB, which is ordinary for a homepage.
The HTML is compressed with gzip.
| Server header | unified-edge-router |
|---|---|
| Compression | gzip |
| Page size | 88,566 bytes |
| Declared language | en-US |
| Mobile viewport | declared |
What does the homepage say about itself?
The title is 21 characters, inside the range that displays without truncation.
There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.
All 1 images on the homepage have alt attributes.
| Title | Welcome to Swoosh.com (21 chars) |
|---|---|
| Meta description | — none — (0 chars) |
| H1 | Welcome to Swoosh.com (1 on the page) |
| Canonical | not set |
| Open Graph title | not set |
| Headings / images | 0 H2s, 1 images (0 without alt text) |
Is swoosh.com served over a valid certificate?
The HTTPS certificate is issued by Amazon and is
valid until 2026-11-24, which is 50 days from the date of this check. It covers
18 hostnames.
- *.considered-design.com
- *.runnxn.com
- *.nikecommunityimpact.org
- *.nikeconsidereddesign.com
- considered-design.com
- *.nikecommunityimpact.com
- nikecommunityimpact.org
- nikeattheheights.com
- nikeconsidereddesign.com
- nikepress.com
- *.nikeattheheights.com
- *.nikeplanet.com
The certificate has 50 days left to run.
Which security headers does it set?
3 of 6 are set (HSTS, Content Security Policy, X-Frame-Options). Absent: X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
| Header | Set | Value |
|---|---|---|
| HSTS | yes | max-age=2628000 ; includeSubDomains |
| Content Security Policy | yes | frame-ancestors 'self' *.nike.com *.nikecloud.com *.nikedev.com |
| X-Content-Type-Options | no | — |
| X-Frame-Options | yes | sameorigin |
| Referrer-Policy | no | — |
| Permissions-Policy | no | — |
How is DNS configured for swoosh.com?
| IP addresses | 108.138.7.42, 108.138.7.72, 108.138.7.10, 108.138.7.3 |
|---|---|
| Reverse DNS | server-108-138-7-42.fra56.r.cloudfront.net, server-108-138-7-72.fra56.r.cloudfront.net |
| Name servers | ns-v2.nike.com, ns-v3.nike.com, ns-v4.nike.com, ns-v1.nike.com |
| Mail (MX) | swoosh-com.mail.protection.outlook.com (pri 0) |
| SPF | v=spf1 +mx -all |
| TXT records | 3 |
swoosh.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.
Mail is handled by 1 exchanger.
An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.
Reverse DNS resolves to server-108-138-7-42.fra56.r.cloudfront.net, server-108-138-7-72.fra56.r.cloudfront.net, which usually names the hosting provider.
Who runs DNS and mail for swoosh.com?
Mail is handled by Microsoft 365.
No AAAA records are published, so the site is reachable over IPv4 only.
What else is worth noting about swoosh.com?
11 of 11 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.
The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.
The page title and the H1 are identical. That is not an error, but it usually means one of the two is not doing any work.
Can swoosh.com be spoofed in email?
No DMARC record is published, so there is no instruction telling receiving servers what to do with mail that fails authentication. In practice that means forged mail from this domain is likely to be delivered.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What does robots.txt allow?
No robots.txt was served. Crawlers treat a missing file as permission to crawl
everything, so this is an open crawl policy by default rather than a blocked one.
What structured data does the homepage publish?
No JSON-LD or microdata was found on the homepage.
What does swoosh.com load from third parties?
The homepage pulls resources from 1 third-party host (nike.com). Each one sees the visitor IP and user agent on every page load.
11 cookies are set before any interaction (geoloc, rc, tp, tz, la). 7 lack the Secure flag.
The page links or refers to GitHub.
| Cookie | Secure | HttpOnly | SameSite |
|---|---|---|---|
| geoloc | no | no | none/unset |
| rc | no | no | none/unset |
| tp | no | no | none/unset |
| tz | no | no | none/unset |
| la | no | no | none/unset |
| lo | no | no | none/unset |
| AKA_A2 | yes | yes | none/unset |
| ni_d | yes | no | none/unset |
| AKA_A2 | yes | yes | none/unset |
| AKA_A2 | yes | yes | none/unset |
| ak_bmsc | no | yes | none/unset |
Does swoosh.com settle on one address?
Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.
The www address redirects to https://www.nike.com/swoosh/route, so the site settles on one canonical hostname.
How easily can swoosh.com be crawled?
No readable sitemap was found, so crawlers have to discover every page by following links.
A deliberately invalid URL returns HTTP 200 rather than 404. That is a soft 404: every mistyped or stale link becomes an indexable page, which inflates the site with duplicates.
What tracking does swoosh.com run?
No analytics or advertising trackers were detected on the homepage of swoosh.com, which is unusual for a commercial site.
How does swoosh.com look when shared?
No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.
How are images, fonts and scripts handled?
1 image on the homepage, 0 of them lazy-loaded (0%).
All image references use JPEG, PNG or GIF. WebP or AVIF typically cut image weight substantially at the same visual quality.
No srcset attributes are used, so every device is served the same image size regardless of screen.
The page pulls 1 external stylesheet and 20 external scripts, with 10 carrying defer or async.
Responses carry Akamai edge headers, so content is served from a CDN rather than straight from the origin.
Is swoosh.com accessible and current?
The page uses 1 landmark element and 1 ARIA attribute.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
The visible copyright notice reads 2024, 2 years behind the current year, which usually indicates the site is not actively maintained.
Can search engines index swoosh.com?
Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.
No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.
The homepage carries 2 internal and 0 external links across 0 outside hosts.
Visible text is only 0.6% of the HTML, which indicates the page is assembled in the browser rather than served as content.
The heading outline skips 1 level, which breaks the document structure screen readers navigate by.
How is swoosh.com delivered?
The HTML is served with Cache-Control: max-age=120.
No favicon is declared in the markup.
Frequently asked questions
Does swoosh.com set the usual HTTP security headers?
It sets 3 of 6. The ones not present are: X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
Does swoosh.com allow AI crawlers?
No robots.txt is served, so nothing is disallowed and AI crawlers are free to read the site.
What is swoosh.com built with?
The homepage exposes these fingerprints: Next.js, React, X-Powered-By: Express. A site behind a CDN or rendered server-side may use more than it reveals.
Where does this data come from?
Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own swoosh.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 5 October 2026.
Analyse another domain →
⚠ নিরাপদ থাকুন
জানি একটি স্বাধীন গাইড, কোনো সরকারি ওয়েবসাইট নয়। প্রকৃত কাজটি শুধু অফিসিয়াল পোর্টালেই করুন। যিনি ফোন, মেসেজ বা "সহায়তা"র নামে আপনার NID নম্বর, OTP, পাসওয়ার্ড বা কার্ডের তথ্য চান — কাউকে তা দেবেন না; কোনো প্রকৃত সংস্থা এসব চায় না।
জানি একটি স্বাধীন গাইড এবং কোনো সরকারি সংস্থার সাথে সম্পৃক্ত নয়। ফি, লিংক ও ধাপ পরিবর্তন হতে পারে — কাজ করার আগে সবসময় অফিসিয়াল পোর্টালে নিশ্চিত করে নিন। এটি সাধারণ তথ্য, আইনি বা আর্থিক পরামর্শ নয়।