Skip to content

cashapp.com — domain analysis

By techvantor com Published 1 min read

cashapp.com is a live website, registered in 2004, served from Gouda, The Netherlands. It has a valid HTTPS certificate, 0 of 6 common security headers, 1 tracking script.

200HTTP status
58msResponse time
0Words on the homepage
0/6Security headers set

Does cashapp.com publish the usual trust pages?

None of about, contact, privacy or terms could be found at their usual addresses.
That is common for small or single-purpose sites, and it is also what a disposable
site looks like, so it is worth noting rather than concluding from.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does cashapp.com compare with other domains analysed here?

Measured against the 13 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 85% of them
(median 406ms)
Security headers More than 0% of them
Domain age Older than 77% of them

Related domains in this index

Analysed domains built on a similar stack:

When was cashapp.com registered?

cashapp.com was registered on 16 April 2004, which makes it about 22 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is Metaregistrar BV.

Registration runs until 16 April 2027.

Registered 16 April 2004
Expires 16 April 2027
Registrar Metaregistrar BV
Registry status active

Where is cashapp.com hosted?

The first address resolves to infrastructure in Gouda, The Netherlands.

The network is operated by Metaregistrar B.V (AS42585 Metaregistrar B.V.).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is cashapp.com running on?

cashapp.com exposes 2 identifiable technologies: Google Analytics, X-Powered-By: PleskLin.

Visitor tracking is present (Google Analytics), so this homepage is not cookie-free.

  • Google Analytics
  • X-Powered-By: PleskLin

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 58ms to first byte this response is fast for a homepage measured from a single European location.

No compression is applied to the HTML. Enabling gzip or brotli usually cuts transfer size by around two thirds at no cost to the server.

Server header nginx
Compression none
Page size 457 bytes
Declared language nl
Mobile viewport not declared

What does the homepage say about itself?

The homepage has no title element at all, which leaves search engines to invent one from the page content.

There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.

No H1 heading was found, so the page offers no single top-level statement of what it is.

No viewport meta tag is declared, so mobile browsers will render the page at desktop width and scale it down.

Title — none — (0 chars)
Meta description — none — (0 chars)
H1 — none — (0 on the page)
Canonical not set
Open Graph title not set
Headings / images 0 H2s, 0 images (0 without alt text)

Is cashapp.com served over a valid certificate?

The HTTPS certificate is issued by Let's Encrypt and is
valid until 2026-11-17, which is 43 days from the date of this check. It covers
2 hostnames.

  • cashapp.com
  • www.cashapp.com

The certificate has 43 days left to run.

It covers 2 hostnames, so it was issued for this site specifically.

Let's Encrypt certificates are free and run on 90-day terms, so this site is almost certainly renewing automatically.

Which security headers does it set?

None of the 6 headers checked are set. That is the default state of most servers rather than evidence of a problem, but it means the browser is given no instructions it could otherwise act on.

Without HSTS, a browser that has never visited before will try HTTP first, which is the window a network attacker needs.

With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.

Header Set Value
HSTS no —
Content Security Policy no —
X-Content-Type-Options no —
X-Frame-Options no —
Referrer-Policy no —
Permissions-Policy no —

How is DNS configured for cashapp.com?

IP addresses 194.213.127.100, 2a01:448:4005::100
Reverse DNS server140.mijndomeinhosting.nl, server140.mijndomeinhosting.nl
Name servers nsn1.mijndomein.nl, nsn2.mijndomein.nl
Mail (MX) mx1.mijndomein.nl (pri 5), mx2.mijndomein.nl (pri 6)
SPF v=spf1 a mx include:spf.mijndomeinhosting.nl ~all
TXT records 1

cashapp.com resolves to 2 addresses, which indicates load balancing or a CDN rather than a single origin server.

Mail is handled by 2 exchangers.

An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.

Reverse DNS resolves to server140.mijndomeinhosting.nl, server140.mijndomeinhosting.nl, which usually names the hosting provider.

Who runs DNS and mail for cashapp.com?

Mail exchangers point at hosts that do not match any major provider, which usually means self-hosted or niche-provider mail.

The domain publishes AAAA records and accepts connections over IPv6.

What else is worth noting about cashapp.com?

1 of 1 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.

The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.

Can cashapp.com be spoofed in email?

DMARC is published with p=none, which monitors but does not act. Forged mail is still delivered; the owner just gets reports about it.

No CAA records are published, so any certificate authority may issue a certificate for this domain.

The zone is DNSSEC-signed, so resolvers can verify the DNS answers have not been tampered with in transit.

What else does cashapp.com publish?

A security.txt file is published, giving security researchers a documented way to report vulnerabilities. Very few sites bother.

What does robots.txt allow?

No robots.txt was served. Crawlers treat a missing file as permission to crawl
everything, so this is an open crawl policy by default rather than a blocked one.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does cashapp.com load from third parties?

The homepage pulls resources from 1 third-party host (googletagmanager.com). Each one sees the visitor IP and user agent on every page load.

No cookies are set on first load.

Does cashapp.com settle on one address?

Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.

Both cashapp.com and www.cashapp.com answer with 200 and neither redirects to the other. Search engines therefore see two complete copies of the site, and link equity is split between them unless a canonical tag resolves it.

How easily can cashapp.com be crawled?

No readable sitemap was found, so crawlers have to discover every page by following links.

A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.

What tracking does cashapp.com run?

1 tracking script detected: Google Analytics.

No consent management platform was detected alongside them. Where GDPR or the ePrivacy Directive applies, analytics and advertising scripts generally need consent before they load.

How does cashapp.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

The page pulls 0 external stylesheets and 1 external script, with 1 carrying defer or async.

No preconnect hints are declared despite third-party scripts being present, so each new origin pays a full connection setup before it can deliver anything.

Is cashapp.com accessible and current?

The page uses 0 landmark elements and 0 ARIA attributes.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index cashapp.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

Visible text is only 0% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is cashapp.com delivered?

No Cache-Control header is sent for the HTML, so caching behaviour is left to browser defaults.

No favicon is declared in the markup.

The TLS certificate also covers 1 subdomain: www.cashapp.com.

  • www.cashapp.com

Frequently asked questions

Does cashapp.com set the usual HTTP security headers?

It sets 0 of 6. The ones not present are: HSTS, Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.

Does cashapp.com allow AI crawlers?

No robots.txt is served, so nothing is disallowed and AI crawlers are free to read the site.

What is cashapp.com built with?

The homepage exposes these fingerprints: Google Analytics, X-Powered-By: PleskLin. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own cashapp.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 4 October 2026.
Analyse another domain →