moonpig.com — domain analysis
moonpig.com describes itself as "Please select which country you want to send your order to". It is built on Next.js, registered in 1999, served from New York, United States. It has a valid HTTPS certificate, 2 of 6 common security headers, 3 tracking scripts.
Does moonpig.com publish the usual trust pages?
None of about, contact, privacy or terms could be found at their usual addresses.
That is common for small or single-purpose sites, and it is also what a disposable
site looks like, so it is worth noting rather than concluding from.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does moonpig.com compare with other domains analysed here?
Measured against the 81 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 38% of them (median 455ms) |
|---|---|
| Security headers | More than 77% of them |
| Domain age | Older than 70% of them |
Related domains in this index
Analysed domains sharing the same network (AS16509 Amazon.com, Inc.):
- asort.com
- avoda.com
- bollyshare.com
- creatorset.com
- fotomac.com.tr
- gmanetwork.com
- marketwatch.com
- moodx.com
Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.
Analysed domains built on a similar stack:
Other analysed domains served from the same country:
- avtub.com
- bodmo.com
- flimyfly.com
- grupoasmedan.com
- khols.com
- noon.com
- rottendot.com
- sketchmetademolab.com
When was moonpig.com registered?
moonpig.com was registered on 4 October 1999, which makes it about 27 years old.
A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.
The registrar of record is Amazon Registrar, Inc..
Registration runs until 23 March 2031.
The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.
| Registered | 4 October 1999 |
|---|---|
| Expires | 23 March 2031 |
| Registrar | Amazon Registrar, Inc. |
| Registry status | client transfer prohibited |
Where is moonpig.com hosted?
The first address resolves to infrastructure in New York, United States.
The network is operated by AWS CloudFront (GLOBAL) (AS16509 Amazon.com, Inc.).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is moonpig.com running on?
moonpig.com exposes 3 identifiable technologies: Next.js, Cloudflare, Google Analytics.
The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.
Cloudflare sits in front of the origin, so the server header, IP addresses and response timing describe the edge rather than the machine actually running the site.
Visitor tracking is present (Google Analytics), so this homepage is not cookie-free.
- Next.js
- Cloudflare
- Google Analytics
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 709ms to first byte this response is slow for a homepage measured from a single European location.
The HTML weighs 93KB, which is ordinary for a homepage.
The HTML is compressed with gzip.
| Server header | cloudflare |
|---|---|
| Compression | gzip |
| Page size | 95,439 bytes |
| Declared language | en-GB |
| Mobile viewport | declared |
What does the homepage say about itself?
The title is 27 characters, inside the range that displays without truncation.
A meta description of 58 characters is present.
No H1 heading was found, so the page offers no single top-level statement of what it is.
| Title | Country Selection | Moonpig (27 chars) |
|---|---|
| Meta description | Please select which country you want to send your order to (58 chars) |
| H1 | — none — (0 on the page) |
| Canonical | https://www.moonpig.com/ |
| Open Graph title | not set |
| Headings / images | 1 H2s, 0 images (0 without alt text) |
Is moonpig.com served over a valid certificate?
The HTTPS certificate is issued by Amazon and is
valid until 2027-03-17, which is 163 days from the date of this check. It covers
55 hostnames.
- moonpig.careers
- www.moonpig.biz
- www.moonpig.co
- moonpig.co.uk
- moonpigcards.com
- themoonpigfoundation.com
- moonpig.com.au
- www.moonpiglet.com
- www.buyacard.co.uk
- moonpigs.com
- moonpig.co
- www.moonpig.de
The certificate has 163 days left to run.
It covers 55 hostnames, which is characteristic of a shared or platform-issued certificate rather than one bought for this domain alone.
Which security headers does it set?
2 of 6 are set (HSTS, X-Frame-Options). Absent: Content Security Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.
| Header | Set | Value |
|---|---|---|
| HSTS | yes | max-age=31536000; includeSubDomains |
| Content Security Policy | no | — |
| X-Content-Type-Options | no | — |
| X-Frame-Options | yes | deny |
| Referrer-Policy | no | — |
| Permissions-Policy | no | — |
How is DNS configured for moonpig.com?
| IP addresses | 13.33.235.89, 13.33.235.65, 13.33.235.69, 13.33.235.15 |
|---|---|
| Reverse DNS | server-13-33-235-89.hel51.r.cloudfront.net, server-13-33-235-65.hel51.r.cloudfront.net |
| Name servers | ns-1459.awsdns-54.org, ns-2025.awsdns-61.co.uk, ns-241.awsdns-30.com, ns-878.awsdns-45.net |
| Mail (MX) | alt1.aspmx.l.google.com (pri 5), alt2.aspmx.l.google.com (pri 5), aspmx.l.google.com (pri 1), alt3.aspmx.l.google.com (pri 10), alt4.aspmx.l.google.com (pri 10) |
| SPF | v=spf1 ip4:155.56.208.100/30 ip4:157.133.97.216/30 ip4:169.145.66.70/31 ip4:169.145.66.72/31 include:_spf.google.com include:amazonses.com include:aspmx.sailthru.com include:_spf.elasticemail.com include:spf.protection.outlook.com -all |
| TXT records | 23 |
moonpig.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.
Mail is handled by 5 exchangers.
An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.
Reverse DNS resolves to server-13-33-235-89.hel51.r.cloudfront.net, server-13-33-235-65.hel51.r.cloudfront.net, which usually names the hosting provider.
Who runs DNS and mail for moonpig.com?
DNS is operated by Amazon Route 53 rather than self-hosted name servers.
Mail is handled by Google Workspace.
No AAAA records are published, so the site is reachable over IPv4 only.
What else is worth noting about moonpig.com?
3 of 3 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.
Can moonpig.com be spoofed in email?
DMARC is set to reject, the strictest setting: mail that fails authentication is refused outright. This is the configuration that actually stops domain spoofing.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What else does moonpig.com publish?
A security.txt file is published, giving security researchers a documented way to report vulnerabilities. Very few sites bother.
What does robots.txt allow?
robots.txt is 3,981 bytes and names
3 user-agent groups.
It does not blanket-disallow general crawlers.
Sitemaps declared:
- https://www.moonpig.com/.well-known/sitemap/hreflang-sitemap-index.xml
AI crawler policy
robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.
What structured data does the homepage publish?
No JSON-LD or microdata was found on the homepage.
What does moonpig.com load from third parties?
The homepage pulls resources from 3 third-party hosts (accounts.google.com, cdn.cookielaw.org, cdn.speedcurve.com). Each one sees the visitor IP and user agent on every page load.
3 cookies are set before any interaction (mnpg_session_id, mnpg_web_uid, __cf_bm). 2 lack the Secure flag.
The page links or refers to LinkedIn, Facebook, YouTube.
| Cookie | Secure | HttpOnly | SameSite |
|---|---|---|---|
| mnpg_session_id | no | no | none/unset |
| mnpg_web_uid | no | no | none/unset |
| __cf_bm | yes | yes | none |
Does moonpig.com settle on one address?
Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.
Both moonpig.com and www.moonpig.com answer with 200 and neither redirects to the other. Search engines therefore see two complete copies of the site, and link equity is split between them unless a canonical tag resolves it.
How easily can moonpig.com be crawled?
A sitemap index is served at https://www.moonpig.com/.well-known/sitemap/hreflang-sitemap-index.xml listing 133 entries.
The most recent lastmod date is 2026-10-04.
A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.
What tracking does moonpig.com run?
3 tracking scripts detected: Google Analytics, LinkedIn Insight, Microsoft Clarity.
A consent platform is in place (OneTrust), so in the EU and UK these should only fire after the visitor agrees.
How does moonpig.com look when shared?
1 of 5 social preview tags are set. Missing: og:title, og:description, og:type, twitter:card.
How are images, fonts and scripts handled?
The page pulls 0 external stylesheets and 11 external scripts, with 10 carrying defer or async.
No preconnect hints are declared despite third-party scripts being present, so each new origin pays a full connection setup before it can deliver anything.
Responses carry Cloudflare and Amazon CloudFront and edge cache edge headers, so content is served from a CDN rather than straight from the origin.
Is moonpig.com accessible and current?
The page uses 0 landmark elements and 11 ARIA attributes.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
Can search engines index moonpig.com?
Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.
The homepage carries 6 internal and 0 external links across 0 outside hosts.
Visible text is only 0.2% of the HTML, which indicates the page is assembled in the browser rather than served as content.
How is moonpig.com delivered?
The HTML is served with Cache-Control: private, max-age=0.
HTTP/3 is advertised via alt-svc, so modern browsers will upgrade to QUIC after the first visit.
Frequently asked questions
Does moonpig.com set the usual HTTP security headers?
It sets 2 of 6. The ones not present are: Content Security Policy, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
Does moonpig.com allow AI crawlers?
robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.
What is moonpig.com built with?
The homepage exposes these fingerprints: Next.js, Cloudflare, Google Analytics. A site behind a CDN or rendered server-side may use more than it reveals.
Where does this data come from?
Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own moonpig.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 5 October 2026.
Analyse another domain →