✓ স্বাধীন — এটি কোনো সরকারি ওয়েবসাইট নয় ✓ প্রতিটি ধাপ অফিসিয়াল পোর্টালে যাচাই করা ✓ আমরা কখনো আপনার NID, OTP বা পাসওয়ার্ড চাই না

tiktok.com — domain analysis

tiktok.com is a live website, registered in 1996, served from Frankfurt am Main, Germany. It has a valid HTTPS certificate, 5 of 6 common security headers.

200HTTP status
402msResponse time
5Words on the homepage
5/6Security headers set

Does tiktok.com publish the usual trust pages?

Found: privacy, terms. Not found at the usual addresses:
about, contact.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does tiktok.com compare with other domains analysed here?

Measured against the 79 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 48% of them
(median 378ms)
Security headers More than 90% of them
Domain age Older than 79% of them

Related domains in this index

Analysed domains sharing the same network (AS20940 Akamai International B.V.):

Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.

Other analysed domains served from the same country:

When was tiktok.com registered?

tiktok.com was registered on 21 July 1996, which makes it about 30 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is Gandi SAS.

Registration runs until 20 July 2027.

The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.

Registered 21 July 1996
Expires 20 July 2027
Registrar Gandi SAS
Registry status client transfer prohibited

Where is tiktok.com hosted?

The first address resolves to infrastructure in Frankfurt am Main, Germany.

The network is operated by Akamai Technologies (AS20940 Akamai International B.V.).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is tiktok.com running on?

tiktok.com exposes 1 identifiable technology: X-Powered-By: Goofy Node.

  • X-Powered-By: Goofy Node

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 402ms to first byte this response is unremarkable for a homepage measured from a single European location.

The HTML weighs 367KB, which is ordinary for a homepage.

The HTML is compressed with gzip.

Server header nginx
Compression gzip
Page size 375,999 bytes
Declared language en
Mobile viewport declared

What does the homepage say about itself?

The title is 22 characters, inside the range that displays without truncation.

There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.

No H1 heading was found, so the page offers no single top-level statement of what it is.

All 1 images on the homepage have alt attributes.

Title TikTok – Make Your Day (22 chars)
Meta description — none — (0 chars)
H1 — none — (0 on the page)
Canonical not set
Open Graph title not set
Headings / images 0 H2s, 1 images (0 without alt text)

Is tiktok.com served over a valid certificate?

The HTTPS certificate is issued by DigiCert Inc and is
valid until 2026-12-03, which is 59 days from the date of this check. It covers
2 hostnames.

  • *.tiktok.com
  • tiktok.com

The certificate has 59 days left to run.

It covers 2 hostnames, so it was issued for this site specifically.

Which security headers does it set?

5 of 6 are set (HSTS, Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy). Absent: Permissions-Policy.

Header Set Value
HSTS yes max-age=31536000; includeSubdomains
Content Security Policy yes report-uri https://mon-i18n.tiktokv.com/monitor_browser/collect/batch/security/?bid=tiktok_pns&ev_type=csp&p=4RqH3SYgEDj
X-Content-Type-Options yes nosniff
X-Frame-Options yes SAMEORIGIN
Referrer-Policy yes strict-origin-when-cross-origin
Permissions-Policy no —

How is DNS configured for tiktok.com?

IP addresses 23.36.162.221, 23.36.162.207, 23.36.162.199, 23.36.162.219
Reverse DNS a23-36-162-221.deploy.static.akamaitechnologies.com, a23-36-162-207.deploy.static.akamaitechnologies.com
Name servers a9-66.akam.net, a1-97.akam.net, a6-65.akam.net, a13-67.akam.net, a18-64.akam.net, a12-66.akam.net
Mail (MX) mx1.tiktok.com (pri 10), mx2.tiktok.com (pri 20), mx3.tiktok.com (pri 30)
SPF v=spf1 include:_spf.google.com include:mail.zendesk.com include:spf.bytedance.com include:mail.stibee.com -all
TXT records 24

tiktok.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.

Mail is handled by 3 exchangers.

An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.

Reverse DNS resolves to a23-36-162-221.deploy.static.akamaitechnologies.com, a23-36-162-207.deploy.static.akamaitechnologies.com, which usually names the hosting provider.

Who runs DNS and mail for tiktok.com?

DNS is operated by Akamai rather than self-hosted name servers.

Mail exchangers point at hosts that do not match any major provider, which usually means self-hosted or niche-provider mail.

No AAAA records are published, so the site is reachable over IPv4 only.

What else is worth noting about tiktok.com?

2 of 2 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.

1 email address appears in the homepage markup, where address-harvesting crawlers will find it.

The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.

Can tiktok.com be spoofed in email?

DMARC is set to reject, the strictest setting: mail that fails authentication is refused outright. This is the configuration that actually stops domain spoofing.

No CAA records are published, so any certificate authority may issue a certificate for this domain.

The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.

What else does tiktok.com publish?

An ads.txt file is published with 7 entries, which means the site sells programmatic advertising and has declared who may resell its inventory.

An app-ads.txt file is also published, which indicates mobile app inventory alongside the website.

What does robots.txt allow?

robots.txt is 1,567 bytes and names
27 user-agent groups.

It does not blanket-disallow general crawlers.

No sitemap is declared in robots.txt.

AI crawler policy

Crawler Policy
gptbot allowed
claudebot allowed
perplexitybot allowed
google-extended allowed
ccbot allowed
applebot-extended allowed
bytespider blocked
anthropic-ai allowed

No sitemap is declared in robots.txt, so crawlers must discover pages by following links.

AI crawler policy is selective: bytespider blocked, gptbot, claudebot, perplexitybot, google-extended, ccbot, applebot-extended, anthropic-ai allowed.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does tiktok.com load from third parties?

The homepage pulls resources from 1 third-party host (sf16-website-login.neutral.tiktokcdn-eu.com). Each one sees the visitor IP and user agent on every page load.

3 cookies are set before any interaction (ttwid, tt_csrf_token, tt_chain_token).

Cookie Secure HttpOnly SameSite
ttwid yes yes none/unset
tt_csrf_token yes yes lax
tt_chain_token yes yes none/unset

Does tiktok.com settle on one address?

Both tiktok.com and www.tiktok.com answer with 200 and neither redirects to the other. Search engines therefore see two complete copies of the site, and link equity is split between them unless a canonical tag resolves it.

How easily can tiktok.com be crawled?

No readable sitemap was found, so crawlers have to discover every page by following links.

A deliberately invalid URL returns HTTP 200 rather than 404. That is a soft 404: every mistyped or stale link becomes an indexable page, which inflates the site with duplicates.

What tracking does tiktok.com run?

No analytics or advertising trackers were detected on the homepage of tiktok.com, which is unusual for a commercial site.

How does tiktok.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

1 image on the homepage, 0 of them lazy-loaded (0%).

Modern image formats are in use (17 WebP/AVIF references).

No srcset attributes are used, so every device is served the same image size regardless of screen.

The page pulls 0 external stylesheets and 62 external scripts, with 60 carrying defer or async.

Responses carry edge cache edge headers, so content is served from a CDN rather than straight from the origin.

Is tiktok.com accessible and current?

The page uses 0 landmark elements and 1 ARIA attribute.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index tiktok.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

Visible text is only 0% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is tiktok.com delivered?

The HTML is served with Cache-Control: max-age=0, no-cache, no-store.

A web app manifest is declared, so the site is installable as a progressive web app.

No favicon is declared in the markup.

Frequently asked questions

Does tiktok.com set the usual HTTP security headers?

It sets 5 of 6. The ones not present are: Permissions-Policy.

Does tiktok.com allow AI crawlers?

No — robots.txt blocks bytespider.

What is tiktok.com built with?

The homepage exposes these fingerprints: X-Powered-By: Goofy Node. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own tiktok.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 5 October 2026.
Analyse another domain →

⚠ নিরাপদ থাকুন

জানি একটি স্বাধীন গাইড, কোনো সরকারি ওয়েবসাইট নয়। প্রকৃত কাজটি শুধু অফিসিয়াল পোর্টালেই করুন। যিনি ফোন, মেসেজ বা "সহায়তা"র নামে আপনার NID নম্বর, OTP, পাসওয়ার্ড বা কার্ডের তথ্য চান — কাউকে তা দেবেন না; কোনো প্রকৃত সংস্থা এসব চায় না।

জানি একটি স্বাধীন গাইড এবং কোনো সরকারি সংস্থার সাথে সম্পৃক্ত নয়। ফি, লিংক ও ধাপ পরিবর্তন হতে পারে — কাজ করার আগে সবসময় অফিসিয়াল পোর্টালে নিশ্চিত করে নিন। এটি সাধারণ তথ্য, আইনি বা আর্থিক পরামর্শ নয়।