Skip to content

capital.com — domain analysis

By techvantor com Published 1 min read

capital.com describes itself as "Trade CFDs with our award-winning online trading platform. Discover investment opportunities on leading markets & access trading tools & indicators.". It is built on Next.js, registered in 1991, served from London, United Kingdom. It has a valid HTTPS certificate, 1 of 6 common security headers.

200HTTP status
255msResponse time
1,566Words on the homepage
1/6Security headers set

What is capital.com about?

The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:

  • children ×48
  • null ×35
  • props ×28
  • classname ×28
  • instruments ×15
  • market ×15
  • usdusd ×8
  • jpygbp ×8
  • usdaud ×8
  • l111 ×7

Does capital.com publish the usual trust pages?

All four of the pages a established business normally publishes were found:
about, contact, privacy and terms.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does capital.com compare with other domains analysed here?

Measured against the 13 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 54% of them
(median 406ms)
Security headers More than 64% of them
Domain age Older than 92% of them

Related domains in this index

Analysed domains built on a similar stack:

When was capital.com registered?

capital.com was registered on 14 May 1991, which makes it about 35 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is Network Solutions, LLC.

Registration runs until 13 December 2033.

The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.

Registered 14 May 1991
Expires 13 December 2033
Registrar Network Solutions, LLC
Registry status client transfer prohibited

Where is capital.com hosted?

The first address resolves to infrastructure in London, United Kingdom.

The network is operated by Incapsula Inc (AS19551 Incapsula Inc).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is capital.com running on?

capital.com exposes 1 identifiable technology: Next.js.

The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.

  • Next.js

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 255ms to first byte this response is unremarkable for a homepage measured from a single European location.

The HTML alone is 608KB before images, stylesheets or scripts are counted, which is heavy for a document that browsers must parse before anything renders.

The HTML is compressed with gzip.

Server header not disclosed
Compression gzip
Page size 622,592 bytes
Declared language en
Mobile viewport declared

What does the homepage say about itself?

The title is 63 characters, inside the range that displays without truncation.

A meta description of 148 characters is present.

All 106 images on the homepage have alt attributes.

Title Online Trading with Our Award-winning Platform | Capital.com EU (63 chars)
Meta description Trade CFDs with our award-winning online trading platform. Discover investment opportunities on leading markets & access trading tools & indicators. (148 chars)
H1 In a market built for noise, we build for better decisions (1 on the page)
Canonical https://capital.com/en-eu
Open Graph title Online Trading with Our Award-winning Platform | Capital.com EU
Headings / images 14 H2s, 106 images (0 without alt text)

Is capital.com served over a valid certificate?

The HTTPS certificate is issued by DigiCert Inc and is
valid until 2027-01-25, which is 113 days from the date of this check. It covers
2 hostnames.

  • capital.com
  • www.capital.com

The certificate has 113 days left to run.

It covers 2 hostnames, so it was issued for this site specifically.

Which security headers does it set?

1 of 6 are set (HSTS). Absent: Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.

With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.

Header Set Value
HSTS yes max-age=31536000; includeSubDomains
Content Security Policy no —
X-Content-Type-Options no —
X-Frame-Options no —
Referrer-Policy no —
Permissions-Policy no —

How is DNS configured for capital.com?

IP addresses 45.60.76.121
Reverse DNS 45.60.76.121
Name servers jeff.ns.cloudflare.com, liz.ns.cloudflare.com
Mail (MX) alt3.aspmx.l.google.com (pri 10), alt4.aspmx.l.google.com (pri 10), alt1.aspmx.l.google.com (pri 5), alt2.aspmx.l.google.com (pri 5), aspmx.l.google.com (pri 1)
SPF v=spf1 include:_spf.sumsub.com include:amazonses.com include:mail.zendesk.com include:spf.mandrillapp.com include:_spf.google.com include:_spf.psm.knowbe4.com +mx -all
TXT records 43

capital.com resolves to a single address, so there is no DNS-level redundancy.

Mail is handled by 5 exchangers.

An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.

Reverse DNS resolves to 45.60.76.121, which usually names the hosting provider.

Who runs DNS and mail for capital.com?

DNS is operated by Cloudflare rather than self-hosted name servers.

Mail is handled by Google Workspace.

No AAAA records are published, so the site is reachable over IPv4 only.

What else is worth noting about capital.com?

34 of 34 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.

20 email addresses appear in the homepage markup, where address-harvesting crawlers will find them.

Can capital.com be spoofed in email?

DMARC is set to reject, the strictest setting: mail that fails authentication is refused outright. This is the configuration that actually stops domain spoofing.

No CAA records are published, so any certificate authority may issue a certificate for this domain.

The zone is DNSSEC-signed, so resolvers can verify the DNS answers have not been tampered with in transit.

What else does capital.com publish?

A security.txt file is published, giving security researchers a documented way to report vulnerabilities. Very few sites bother.

An app-ads.txt file is also published, which indicates mobile app inventory alongside the website.

What does robots.txt allow?

robots.txt is 699 bytes and names
2 user-agent groups.

It does not blanket-disallow general crawlers.

Sitemaps declared:

  • https://capital.com/sitemap.xml
  • https://capital.com/sitemap.xml

AI crawler policy

robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does capital.com load from third parties?

The homepage loads no resources from third-party hosts at all, which is rare and means visiting it tells no other company that you did.

3 cookies are set before any interaction (__cp_dc, __cp_rip, __cp_requestId).

The page links or refers to X/Twitter, LinkedIn, Facebook, Instagram, YouTube.

Cookie Secure HttpOnly SameSite
__cp_dc yes no none
__cp_rip yes no none
__cp_requestId yes no none

Does capital.com settle on one address?

The www address redirects to https://www.capital.com/en-int, so the site settles on one canonical hostname.

How easily can capital.com be crawled?

A sitemap index is served at https://capital.com/sitemap.xml listing 15 entries.

The most recent lastmod date is 2026-10-04.

A deliberately invalid URL returns HTTP 200 rather than 404. That is a soft 404: every mistyped or stale link becomes an indexable page, which inflates the site with duplicates.

What tracking does capital.com run?

No analytics or advertising trackers were detected on the homepage of capital.com, which is unusual for a commercial site.

How does capital.com look when shared?

All five social preview tags are present, so links shared to social platforms and chat apps will render with a title, description and image.

The page declares 60 hreflang alternates (en-gb, en-gg, en-je, en-im, en-gi, ar-ae, en-ae, en-au, ar, de-ch, de, en), so it targets more than one language or region.

How are images, fonts and scripts handled?

106 images on the homepage, 101 of them lazy-loaded (95%).

Modern image formats are in use (93 WebP/AVIF references).

The page pulls 19 external stylesheets and 34 external scripts, with 33 carrying defer or async.

Is capital.com accessible and current?

The page uses 3 landmark elements and 13 ARIA attributes.

There are 1 form inputs but only 0 label elements, so some fields may be unlabelled for screen readers.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index capital.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

The homepage carries 568 internal and 20 external links across 5 outside hosts.

Visible text is only 2.3% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is capital.com delivered?

The HTML is served with Cache-Control: max-age=0 ,must-revalidate.

A web app manifest is declared, so the site is installable as a progressive web app.

The TLS certificate also covers 1 subdomain: www.capital.com.

  • www.capital.com

Frequently asked questions

Does capital.com set the usual HTTP security headers?

It sets 1 of 6. The ones not present are: Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.

Does capital.com allow AI crawlers?

robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.

What is capital.com built with?

The homepage exposes these fingerprints: Next.js. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own capital.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 4 October 2026.
Analyse another domain →