▸NewsGiga

nelly.com — domain analysis

nelly.com describes itself as "Tervetuloa NELLYlle – löydä trendikkäät naisten vaatteet, kengät, mekot, farkut ja asusteet arkeen, juhlaan ja viikonloppuun. Ilmainen toimitus yli 49,95 €!". It is built on Next.js, registered in 1997, served from Toronto, Canada. It has a valid HTTPS certificate, 1 of 6 common security headers.

200HTTP status
150msResponse time
453Words on the homepage
1/6Security headers set

What is nelly.com about?

The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:

  • nelly ×4
  • naisten ×4
  • vaatteet ×4
  • keng ×4
  • muotia ×3
  • trendikk ×3
  • tutustu ×3
  • nellylt ×3
  • rentoihin ×3
  • valitse ×3

Does nelly.com publish the usual trust pages?

Found: privacy. Not found at the usual addresses:
about, contact, terms.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does nelly.com compare with other domains analysed here?

Measured against the 81 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 80% of them
(median 455ms)
Security headers More than 54% of them
Domain age Older than 80% of them

Related domains in this index

Analysed domains sharing the same network (AS13335 Cloudflare, Inc.):

Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.

Analysed domains built on a similar stack:

Other analysed domains served from the same country:

When was nelly.com registered?

nelly.com was registered on 25 June 1997, which makes it about 29 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is MarkMonitor Inc..

Registration runs until 24 June 2027.

The domain carries 3 registry locks, which blocks unauthorised transfer or deletion.

Registered 25 June 1997
Expires 24 June 2027
Registrar MarkMonitor Inc.
Registry status client delete prohibited, client transfer prohibited, client update prohibited

Where is nelly.com hosted?

The first address resolves to infrastructure in Toronto, Canada.

The network is operated by Cloudflare, Inc. (AS13335 Cloudflare, Inc.).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is nelly.com running on?

nelly.com exposes 3 identifiable technologies: Next.js, Cloudflare, X-Powered-By: Next.js.

The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.

Cloudflare sits in front of the origin, so the server header, IP addresses and response timing describe the edge rather than the machine actually running the site.

  • Next.js
  • Cloudflare
  • X-Powered-By: Next.js

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 150ms to first byte this response is fast for a homepage measured from a single European location.

The HTML weighs 239KB, which is ordinary for a homepage.

The HTML is compressed with gzip.

Server header cloudflare
Compression gzip
Page size 245,195 bytes
Declared language fi-FI
Mobile viewport declared

What does the homepage say about itself?

The title is 40 characters, inside the range that displays without truncation.

A meta description of 156 characters is present.

There are 2 H1 headings. One is conventional; several dilute the signal about what the page is primarily about.

All 32 images on the homepage have alt attributes.

Title NELLY | Naisten muoti – vaatteet, kengät (40 chars)
Meta description Tervetuloa NELLYlle – löydä trendikkäät naisten vaatteet, kengät, mekot, farkut ja asusteet arkeen, juhlaan ja viikonloppuun. Ilmainen toimitus yli 49,95 €! (156 chars)
H1 Jopa 70% (2 on the page)
Canonical not set
Open Graph title not set
Headings / images 10 H2s, 32 images (0 without alt text)

Is nelly.com served over a valid certificate?

The HTTPS certificate is issued by Google Trust Services and is
valid until 2026-11-30, which is 56 days from the date of this check. It covers
2 hostnames.

  • nelly.com
  • *.nelly.com

The certificate has 56 days left to run.

It covers 2 hostnames, so it was issued for this site specifically.

Which security headers does it set?

1 of 6 are set (HSTS). Absent: Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.

With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.

Header Set Value
HSTS yes max-age=63072000
Content Security Policy no —
X-Content-Type-Options no —
X-Frame-Options no —
Referrer-Policy no —
Permissions-Policy no —

How is DNS configured for nelly.com?

IP addresses 104.18.23.58, 104.18.22.58, 2606:4700::6812:163a, 2606:4700::6812:173a
Reverse DNS 104.18.23.58, 104.18.22.58
Name servers rob.ns.cloudflare.com, liz.ns.cloudflare.com
Mail (MX) nelly-com.mail.protection.outlook.com (pri 10)
SPF v=spf1 ip4:84.19.151.92 ip4:52.18.36.202 ip4:194.132.117.0/24 ip4:167.89.9.68 include:emaileuc.freshservice.com include:mail.zendesk.com include:spf.protection.outlook.com include:_spf.anpdm.com include:sendgrid.net include:spf-a.telia.com include:spf.mandrillapp.com -all
TXT records 14

nelly.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.

Mail is handled by 1 exchanger.

An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.

Reverse DNS resolves to 104.18.23.58, 104.18.22.58, which usually names the hosting provider.

Who runs DNS and mail for nelly.com?

DNS is operated by Cloudflare rather than self-hosted name servers.

Mail is handled by Microsoft 365.

The domain publishes AAAA records and accepts connections over IPv6.

What else is worth noting about nelly.com?

All 1 externally hosted scripts carry subresource integrity hashes, so a compromised CDN could not silently swap them.

The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.

Can nelly.com be spoofed in email?

DMARC is published with p=none, which monitors but does not act. Forged mail is still delivered; the owner just gets reports about it.

No CAA records are published, so any certificate authority may issue a certificate for this domain.

The zone is DNSSEC-signed, so resolvers can verify the DNS answers have not been tampered with in transit.

What does robots.txt allow?

robots.txt is 799 bytes and names
1 user-agent group.

It does not blanket-disallow general crawlers.

Sitemaps declared:

  • https://nelly.com/se/sitemap.xml
  • https://nelly.com/no/sitemap.xml
  • https://nelly.com/dk/sitemap.xml
  • https://nelly.com/fi/sitemap.xml
  • https://nelly.com/nl/sitemap.xml
  • https://nelly.com/be/sitemap.xml
  • https://nelly.com/fr/sitemap.xml
  • https://nelly.com/pl/sitemap.xml

AI crawler policy

robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does nelly.com load from third parties?

The homepage pulls resources from 8 third-party hosts (cdn-sitegainer.com, cert.tryggehandel.net, consent.cookiebot.com, js.testfreaks.com, modules.ecomid.com, static.cloudflareinsights.com). Each one sees the visitor IP and user agent on every page load.

No cookies are set on first load.

The page links or refers to Facebook, Instagram, YouTube.

Does nelly.com settle on one address?

Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.

The www address redirects to https://nelly.com/, so the site settles on one canonical hostname.

How easily can nelly.com be crawled?

A sitemap index is served at https://nelly.com/se/sitemap.xml listing 4 entries.

A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.

What tracking does nelly.com run?

No analytics or advertising trackers were detected on the homepage of nelly.com, which is unusual for a commercial site.

How does nelly.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

32 images on the homepage, 32 of them lazy-loaded (100%).

Modern image formats are in use (2 WebP/AVIF references).

The page pulls 1 external stylesheet and 40 external scripts, with 38 carrying defer or async.

Responses carry Cloudflare and Vercel edge headers, so content is served from a CDN rather than straight from the origin.

Is nelly.com accessible and current?

The page uses 4 landmark elements and 77 ARIA attributes.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index nelly.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

The homepage carries 62 internal and 5 external links across 5 outside hosts.

Visible text is only 1.5% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is nelly.com delivered?

The HTML is served with Cache-Control: public, max-age=0, must-revalidate.

HTTP/3 is advertised via alt-svc, so modern browsers will upgrade to QUIC after the first visit.

Frequently asked questions

Does nelly.com set the usual HTTP security headers?

It sets 1 of 6. The ones not present are: Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.

Does nelly.com allow AI crawlers?

robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.

What is nelly.com built with?

The homepage exposes these fingerprints: Next.js, Cloudflare, X-Powered-By: Next.js. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own nelly.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 5 October 2026.
Analyse another domain →