cruises.com — domain analysis
cruises.com is a live website, registered in 1997, served from New York, United States. It has a valid HTTPS certificate, 2 of 6 common security headers.
Does cruises.com publish the usual trust pages?
None of about, contact, privacy or terms could be found at their usual addresses.
That is common for small or single-purpose sites, and it is also what a disposable
site looks like, so it is worth noting rather than concluding from.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does cruises.com compare with other domains analysed here?
Measured against the 12 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 58% of them (median 535ms) |
|---|---|
| Security headers | More than 56% of them |
| Domain age | Older than 82% of them |
Related domains in this index
Other analysed domains served from the same country:
When was cruises.com registered?
cruises.com was registered on 24 April 1997, which makes it about 29 years old.
A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.
The registrar of record is GoDaddy Corporate Domains, LLC.
Registration runs until 25 April 2028.
The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.
| Registered | 24 April 1997 |
|---|---|
| Expires | 25 April 2028 |
| Registrar | GoDaddy Corporate Domains, LLC |
| Registry status | client transfer prohibited |
Where is cruises.com hosted?
The first address resolves to infrastructure in New York, United States.
The network is operated by Incapsula Inc (AS19551 Incapsula Inc).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is cruises.com running on?
No platform, framework or analytics fingerprints were found in the homepage markup of cruises.com. That usually means hand-written HTML, an uncommon stack, or a page assembled entirely at the edge.
No recognisable platform, framework or analytics fingerprints were found in the homepage markup.
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 494ms to first byte this response is unremarkable for a homepage measured from a single European location.
No compression is applied to the HTML. Enabling gzip or brotli usually cuts transfer size by around two thirds at no cost to the server.
| Server header | not disclosed |
|---|---|
| Compression | none |
| Page size | 212 bytes |
| Declared language | not declared |
| Mobile viewport | not declared |
What does the homepage say about itself?
The homepage has no title element at all, which leaves search engines to invent one from the page content.
There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.
No H1 heading was found, so the page offers no single top-level statement of what it is.
No viewport meta tag is declared, so mobile browsers will render the page at desktop width and scale it down.
The html element declares no lang attribute, which removes a signal both screen readers and translation tools rely on.
| Title | — none — (0 chars) |
|---|---|
| Meta description | — none — (0 chars) |
| H1 | — none — (0 on the page) |
| Canonical | not set |
| Open Graph title | not set |
| Headings / images | 0 H2s, 0 images (0 without alt text) |
Is cruises.com served over a valid certificate?
The HTTPS certificate is issued by DigiCert Inc and is
valid until 2026-12-07, which is 64 days from the date of this check. It covers
2 hostnames.
- *.cruises.com
- cruises.com
The certificate has 64 days left to run.
It covers 2 hostnames, so it was issued for this site specifically.
Which security headers does it set?
2 of 6 are set (HSTS, X-Content-Type-Options). Absent: Content Security Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy.
With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.
| Header | Set | Value |
|---|---|---|
| HSTS | yes | max-age=31536000; includeSubDomains; preload |
| Content Security Policy | no | — |
| X-Content-Type-Options | yes | nosniff |
| X-Frame-Options | no | — |
| Referrer-Policy | no | — |
| Permissions-Policy | no | — |
How is DNS configured for cruises.com?
| IP addresses | 45.60.121.26, 45.60.131.26 |
|---|---|
| Reverse DNS | 45.60.121.26, 45.60.131.26 |
| Name servers | ns6.savvis.net, ns1.savvis.net, ns6a.savvis.net, ns2.savvis.net, ns5.savvis.net, ns4.savvis.net, ns3.savvis.net |
| Mail (MX) | mail.wth.com (pri 10) |
| SPF | v=spf1 redirect=wth.com |
| TXT records | 12 |
cruises.com resolves to 2 addresses, which indicates load balancing or a CDN rather than a single origin server.
Mail is handled by 1 exchanger.
An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.
Reverse DNS resolves to 45.60.121.26, 45.60.131.26, which usually names the hosting provider.
Who runs DNS and mail for cruises.com?
Mail exchangers point at hosts that do not match any major provider, which usually means self-hosted or niche-provider mail.
No AAAA records are published, so the site is reachable over IPv4 only.
Can cruises.com be spoofed in email?
DMARC is set to quarantine, so mail failing authentication is sent to spam rather than the inbox.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What does robots.txt allow?
robots.txt is 3,096 bytes and names
24 user-agent groups.
It does not blanket-disallow general crawlers.
No sitemap is declared in robots.txt.
AI crawler policy
| Crawler | Policy |
|---|---|
| gptbot | allowed |
| claudebot | allowed |
| perplexitybot | allowed |
| google-extended | allowed |
| applebot-extended | allowed |
| bytespider | allowed |
| anthropic-ai | allowed |
No sitemap is declared in robots.txt, so crawlers must discover pages by following links.
Named AI crawlers are explicitly allowed (gptbot, claudebot, perplexitybot, google-extended, applebot-extended, bytespider, anthropic-ai).
What structured data does the homepage publish?
No JSON-LD or microdata was found on the homepage.
What does cruises.com load from third parties?
The homepage loads no resources from third-party hosts at all, which is rare and means visiting it tells no other company that you did.
2 cookies are set before any interaction (visid_incap_2082994, incap_ses_1849_2082994).
| Cookie | Secure | HttpOnly | SameSite |
|---|---|---|---|
| visid_incap_2082994 | yes | yes | none |
| incap_ses_1849_2082994 | yes | no | none |
Does cruises.com settle on one address?
Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.
Both cruises.com and www.cruises.com answer with 200 and neither redirects to the other. Search engines therefore see two complete copies of the site, and link equity is split between them unless a canonical tag resolves it.
How easily can cruises.com be crawled?
No readable sitemap was found, so crawlers have to discover every page by following links.
A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.
What tracking does cruises.com run?
No analytics or advertising trackers were detected on the homepage of cruises.com, which is unusual for a commercial site.
How does cruises.com look when shared?
No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.
How are images, fonts and scripts handled?
The page pulls 0 external stylesheets and 1 external script, with 0 carrying defer or async.
Is cruises.com accessible and current?
The page uses 0 landmark elements and 0 ARIA attributes.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
The page does not open with the HTML5 doctype, which can put browsers into quirks mode.
Can search engines index cruises.com?
The homepage carries a noindex directive, so it is asking search engines to keep it out of results entirely.
No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.
Visible text is only 0% of the HTML, which indicates the page is assembled in the browser rather than served as content.
How is cruises.com delivered?
The HTML is served with Cache-Control: no-cache, no-store.
No favicon is declared in the markup.
Frequently asked questions
Does cruises.com set the usual HTTP security headers?
It sets 2 of 6. The ones not present are: Content Security Policy, X-Frame-Options, Referrer-Policy, Permissions-Policy.
Does cruises.com allow AI crawlers?
robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.
Where does this data come from?
Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own cruises.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 4 October 2026.
Analyse another domain →