▸NewsGiga

theunsentproject.com — domain analysis

theunsentproject.com describes itself as "The Unsent Project is a collection of unsent text messages to first loves. Search for your name or read submissions in the archive.". It is built on Next.js, registered in 2016, served from Helsinki, Finland. It has a valid HTTPS certificate, 4 of 6 common security headers, 1 tracking script.

200HTTP status
333msResponse time
64Words on the homepage
4/6Security headers set

What is theunsentproject.com about?

The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:

  • unsent ×5
  • project ×2

Does theunsentproject.com publish the usual trust pages?

Found: about, terms. Not found at the usual addresses:
contact, privacy.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does theunsentproject.com compare with other domains analysed here?

Measured against the 81 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 64% of them
(median 455ms)
Security headers More than 89% of them
Domain age Older than 37% of them

Related domains in this index

Analysed domains sharing the same network (AS16509 Amazon.com, Inc.):

Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.

Analysed domains built on a similar stack:

When was theunsentproject.com registered?

theunsentproject.com was registered on 29 July 2016, which makes it about 10 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is GoDaddy.com, LLC.

Registration runs until 29 July 2027.

The domain carries 4 registry locks, which blocks unauthorised transfer or deletion.

Registered 29 July 2016
Expires 29 July 2027
Registrar GoDaddy.com, LLC
Registry status client delete prohibited, client renew prohibited, client transfer prohibited, client update prohibited

Where is theunsentproject.com hosted?

The first address resolves to infrastructure in Helsinki, Finland.

The network is operated by AWS CloudFront (GLOBAL) (AS16509 Amazon.com, Inc.).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is theunsentproject.com running on?

theunsentproject.com exposes 2 identifiable technologies: Next.js, Google Analytics.

The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.

Visitor tracking is present (Google Analytics), so this homepage is not cookie-free.

  • Next.js
  • Google Analytics

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 333ms to first byte this response is unremarkable for a homepage measured from a single European location.

At 11KB the HTML is unusually small, which typically means the page builds itself client-side after load.

The HTML is compressed with gzip.

Server header AmazonS3
Compression gzip
Page size 10,884 bytes
Declared language not declared
Mobile viewport declared

What does the homepage say about itself?

The title is 43 characters, inside the range that displays without truncation.

A meta description of 131 characters is present.

All 4 images on the homepage have alt attributes.

The html element declares no lang attribute, which removes a signal both screen readers and translation tools rely on.

Title Unsent Project Archive – The Unsent Project (43 chars)
Meta description The Unsent Project is a collection of unsent text messages to first loves. Search for your name or read submissions in the archive. (131 chars)
H1 A Collection Of Unsent Text Messages To First Loves (1 on the page)
Canonical not set
Open Graph title not set
Headings / images 2 H2s, 4 images (0 without alt text)

Is theunsentproject.com served over a valid certificate?

The HTTPS certificate is issued by Amazon and is
valid until 2027-04-11, which is 188 days from the date of this check. It covers
2 hostnames.

  • *.theunsentproject.com
  • theunsentproject.com

The certificate has 188 days left to run.

It covers 2 hostnames, so it was issued for this site specifically.

Which security headers does it set?

4 of 6 are set (HSTS, X-Content-Type-Options, X-Frame-Options, Referrer-Policy). Absent: Content Security Policy, Permissions-Policy.

With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.

Header Set Value
HSTS yes max-age=31536000; includeSubDomains; preload
Content Security Policy no —
X-Content-Type-Options yes nosniff
X-Frame-Options yes DENY
Referrer-Policy yes strict-origin-when-cross-origin
Permissions-Policy no —

How is DNS configured for theunsentproject.com?

IP addresses 52.85.154.56, 52.85.154.36, 52.85.154.110, 52.85.154.75, 2600:9000:2045:b000:9:7603:d1c0:93a1, 2600:9000:2045:5600:9:7603:d1c0:93a1, 2600:9000:2045:e200:9:7603:d1c0:93a1, 2600:9000:2045:4400:9:7603:d1c0:93a1, 2600:9000:2045:7000:9:7603:d1c0:93a1, 2600:9000:2045:3600:9:7603:d1c0:93a1, 2600:9000:2045:6c00:9:7603:d1c0:93a1, 2600:9000:2045:5200:9:7603:d1c0:93a1
Reverse DNS server-52-85-154-56.hel51.r.cloudfront.net, server-52-85-154-36.hel51.r.cloudfront.net
Name servers ns-1284.awsdns-32.org, ns-1781.awsdns-30.co.uk, ns-358.awsdns-44.com, ns-694.awsdns-22.net
Mail (MX) theunsentproject-com.mail.protection.outlook.com (pri 0)
SPF v=spf1 include:secureserver.net -all
TXT records 2

theunsentproject.com resolves to 12 addresses, which indicates load balancing or a CDN rather than a single origin server.

Mail is handled by 1 exchanger.

An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.

Reverse DNS resolves to server-52-85-154-56.hel51.r.cloudfront.net, server-52-85-154-36.hel51.r.cloudfront.net, which usually names the hosting provider.

Who runs DNS and mail for theunsentproject.com?

DNS is operated by Amazon Route 53 rather than self-hosted name servers.

Mail is handled by Microsoft 365.

The domain publishes AAAA records and accepts connections over IPv6.

What else is worth noting about theunsentproject.com?

3 of 3 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.

2 email addresses appear in the homepage markup, where address-harvesting crawlers will find them.

Can theunsentproject.com be spoofed in email?

DMARC is published with p=none, which monitors but does not act. Forged mail is still delivered; the owner just gets reports about it.

CAA records restrict certificate issuance to 4 named authorities (issue pki.goog, issue sectigo.com, issue amazon.com, issue letsencrypt.org), so no other CA should be able to issue for this domain.

The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.

What else does theunsentproject.com publish?

An ads.txt file is published with 1 entries, which means the site sells programmatic advertising and has declared who may resell its inventory.

What does robots.txt allow?

No robots.txt was served. Crawlers treat a missing file as permission to crawl
everything, so this is an open crawl policy by default rather than a blocked one.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does theunsentproject.com load from third parties?

The homepage pulls resources from 2 third-party hosts (googletagmanager.com, pagead2.googlesyndication.com). Each one sees the visitor IP and user agent on every page load.

No cookies are set on first load.

The page links or refers to Instagram.

Does theunsentproject.com settle on one address?

Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.

The www address redirects to https://theunsentproject.com/, so the site settles on one canonical hostname.

How easily can theunsentproject.com be crawled?

No readable sitemap was found, so crawlers have to discover every page by following links.

A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.

What tracking does theunsentproject.com run?

1 tracking script detected: Google Analytics.

No consent management platform was detected alongside them. Where GDPR or the ePrivacy Directive applies, analytics and advertising scripts generally need consent before they load.

How does theunsentproject.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

4 images on the homepage, 4 of them lazy-loaded (100%).

All image references use JPEG, PNG or GIF. WebP or AVIF typically cut image weight substantially at the same visual quality.

No srcset attributes are used, so every device is served the same image size regardless of screen.

The page pulls 1 external stylesheet and 17 external scripts, with 17 carrying defer or async.

No preconnect hints are declared despite third-party scripts being present, so each new origin pays a full connection setup before it can deliver anything.

Responses carry Amazon CloudFront and edge cache edge headers, so content is served from a CDN rather than straight from the origin.

Is theunsentproject.com accessible and current?

The page uses 2 landmark elements and 6 ARIA attributes.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index theunsentproject.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

The homepage carries 8 internal and 3 external links across 2 outside hosts.

Visible text is only 4.2% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is theunsentproject.com delivered?

The HTML is served with Cache-Control: public, max-age=0, must-revalidate.

HTTP/3 is advertised via alt-svc, so modern browsers will upgrade to QUIC after the first visit.

No favicon is declared in the markup.

Frequently asked questions

Does theunsentproject.com set the usual HTTP security headers?

It sets 4 of 6. The ones not present are: Content Security Policy, Permissions-Policy.

Does theunsentproject.com allow AI crawlers?

No robots.txt is served, so nothing is disallowed and AI crawlers are free to read the site.

What is theunsentproject.com built with?

The homepage exposes these fingerprints: Next.js, Google Analytics. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own theunsentproject.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 5 October 2026.
Analyse another domain →