Skip to content

derma.com — domain analysis

By TechQuiller com Published 1 min read

derma.com is a live website, registered in 1999, served from Ashburn, United States. It has a valid HTTPS certificate, 3 of 6 common security headers, 1 tracking script.

200HTTP status
843msResponse time
30Words on the homepage
3/6Security headers set

What is derma.com about?

The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:

  • derma ×2

Does derma.com publish the usual trust pages?

None of about, contact, privacy or terms could be found at their usual addresses.
That is common for small or single-purpose sites, and it is also what a disposable
site looks like, so it is worth noting rather than concluding from.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does derma.com compare with other domains analysed here?

Measured against the 12 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 17% of them
(median 535ms)
Security headers More than 67% of them
Domain age Older than 64% of them

Related domains in this index

Analysed domains sharing the same network (AS14618 Amazon.com, Inc.):

Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.

Analysed domains built on a similar stack:

Other analysed domains served from the same country:

When was derma.com registered?

derma.com was registered on 29 March 1999, which makes it about 27 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is NameCheap, Inc..

Registration runs until 29 March 2031.

The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.

Registered 29 March 1999
Expires 29 March 2031
Registrar NameCheap, Inc.
Registry status client transfer prohibited

Where is derma.com hosted?

The first address resolves to infrastructure in Ashburn, United States.

The network is operated by AWS EC2 (us-east-1) (AS14618 Amazon.com, Inc.).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is derma.com running on?

derma.com exposes 1 identifiable technology: Google Analytics.

Visitor tracking is present (Google Analytics), so this homepage is not cookie-free.

  • Google Analytics

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 843ms to first byte this response is slow for a homepage measured from a single European location.

At 8KB the HTML is unusually small, which typically means the page builds itself client-side after load.

The HTML is compressed with gzip.

Server header Caddy, nginx/1.24.0 (Ubuntu)
Compression gzip
Page size 8,625 bytes
Declared language not declared
Mobile viewport declared

What does the homepage say about itself?

The title is only 9 characters, which is short enough that it probably is not describing the page so much as naming it.

There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.

1 of 1 images carry no alt attribute, which leaves them unreadable to screen readers and uninterpretable to image search.

The html element declares no lang attribute, which removes a signal both screen readers and translation tools rely on.

Title derma.com (9 chars)
Meta description — none — (0 chars)
H1 derma.com

(adjective)
 

1.
Relating to the skin and its care or treatment. (1 on the page)

Canonical not set
Open Graph title not set
Headings / images 0 H2s, 1 images (1 without alt text)

Is derma.com served over a valid certificate?

The HTTPS certificate is issued by Let's Encrypt and is
valid until 2026-11-10, which is 37 days from the date of this check. It covers
1 hostname.

  • derma.com

The certificate has 37 days left to run.

It covers 1 hostname, so it was issued for this site specifically.

Let's Encrypt certificates are free and run on 90-day terms, so this site is almost certainly renewing automatically.

Which security headers does it set?

3 of 6 are set (X-Content-Type-Options, X-Frame-Options, Referrer-Policy). Absent: HSTS, Content Security Policy, Permissions-Policy.

Without HSTS, a browser that has never visited before will try HTTP first, which is the window a network attacker needs.

With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.

Header Set Value
HSTS no —
Content Security Policy no —
X-Content-Type-Options yes nosniff
X-Frame-Options yes SAMEORIGIN
Referrer-Policy yes strict-origin-when-cross-origin
Permissions-Policy no —

How is DNS configured for derma.com?

IP addresses 54.235.96.128
Reverse DNS ec2-54-235-96-128.compute-1.amazonaws.com
Name servers ns2.digimedia.com, ns1.digimedia.com
Mail (MX) 0.0.0.0 (pri 1000)
SPF v=spf1 -all
TXT records 1

derma.com resolves to a single address, so there is no DNS-level redundancy.

Mail is handled by 1 exchanger.

An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.

Reverse DNS resolves to ec2-54-235-96-128.compute-1.amazonaws.com, which usually names the hosting provider.

Who runs DNS and mail for derma.com?

Mail exchangers point at hosts that do not match any major provider, which usually means self-hosted or niche-provider mail.

No AAAA records are published, so the site is reachable over IPv4 only.

What else is worth noting about derma.com?

1 of 1 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.

Can derma.com be spoofed in email?

DMARC is set to reject, the strictest setting: mail that fails authentication is refused outright. This is the configuration that actually stops domain spoofing.

No CAA records are published, so any certificate authority may issue a certificate for this domain.

The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.

What does robots.txt allow?

No robots.txt was served. Crawlers treat a missing file as permission to crawl
everything, so this is an open crawl policy by default rather than a blocked one.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does derma.com load from third parties?

The homepage pulls resources from 3 third-party hosts (fonts.googleapis.com, fonts.gstatic.com, googletagmanager.com). Each one sees the visitor IP and user agent on every page load.

1 cookie is set before any interaction (_digiadmin20241_session). 1 lacks the Secure flag.

1 resource is referenced over plain HTTP on an HTTPS page, which browsers block or flag as mixed content.

The page links or refers to X/Twitter.

Cookie Secure HttpOnly SameSite
_digiadmin20241_session no yes lax

Does derma.com settle on one address?

Both derma.com and www.derma.com answer with 200 and neither redirects to the other. Search engines therefore see two complete copies of the site, and link equity is split between them unless a canonical tag resolves it.

How easily can derma.com be crawled?

No readable sitemap was found, so crawlers have to discover every page by following links.

A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.

What tracking does derma.com run?

1 tracking script detected: Google Analytics.

No consent management platform was detected alongside them. Where GDPR or the ePrivacy Directive applies, analytics and advertising scripts generally need consent before they load.

How does derma.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

1 image on the homepage, 0 of them lazy-loaded (0%).

All image references use JPEG, PNG or GIF. WebP or AVIF typically cut image weight substantially at the same visual quality.

No srcset attributes are used, so every device is served the same image size regardless of screen.

Fonts are loaded from Google Fonts, which means every page view also contacts Google. Self-hosting removes that dependency.

The page pulls 2 external stylesheets and 3 external scripts, with 1 carrying defer or async.

No preconnect hints are declared despite third-party scripts being present, so each new origin pays a full connection setup before it can deliver anything.

Is derma.com accessible and current?

The page uses 3 landmark elements and 0 ARIA attributes.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index derma.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

The homepage carries 1 internal and 4 external links across 1 outside host.

Visible text is only 2.5% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is derma.com delivered?

The HTML is served with Cache-Control: max-age=0, private, must-revalidate.

No favicon is declared in the markup.

Frequently asked questions

Does derma.com set the usual HTTP security headers?

It sets 3 of 6. The ones not present are: HSTS, Content Security Policy, Permissions-Policy.

Does derma.com allow AI crawlers?

No robots.txt is served, so nothing is disallowed and AI crawlers are free to read the site.

What is derma.com built with?

The homepage exposes these fingerprints: Google Analytics. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own derma.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 4 October 2026.
Analyse another domain →