bolia.com describes itself as "Discover our universe of New Scandinavian Design – a fusion of creativity, exquisite craftsmanship and timeless materials. Explore the collection.". It was registered in 2000, served from Toronto, Canada. It has a valid HTTPS certificate, 2 of 6 common security headers, 1 tracking script.
Does bolia.com publish the usual trust pages?
None of about, contact, privacy or terms could be found at their usual addresses.
That is common for small or single-purpose sites, and it is also what a disposable
site looks like, so it is worth noting rather than concluding from.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does bolia.com compare with other domains analysed here?
Measured against the 74 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 59% of them (median 463ms) |
|---|---|
| Security headers | More than 58% of them |
| Domain age | Older than 70% of them |
Related domains in this index
Analysed domains sharing the same network (AS13335 Cloudflare, Inc.):
- 27b.com
- aavod.com
- beenverified.com
- crunchlabs.com
- despegar.com.mx
- emojicombos.com
- fvip.com
- giftcardnest.com
Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.
Analysed domains built on a similar stack:
Other analysed domains served from the same country:
When was bolia.com registered?
bolia.com was registered on 30 March 2000, which makes it about 26 years old.
A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.
The registrar of record is EuroDNS S.A..
Registration runs until 30 March 2027.
The domain carries 4 registry locks, which blocks unauthorised transfer or deletion.
| Registered | 30 March 2000 |
|---|---|
| Expires | 30 March 2027 |
| Registrar | EuroDNS S.A. |
| Registry status | client transfer prohibited, server delete prohibited, server transfer prohibited, server update prohibited |
Where is bolia.com hosted?
The first address resolves to infrastructure in Toronto, Canada.
The network is operated by Cloudflare, Inc. (AS13335 Cloudflare, Inc.).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is bolia.com running on?
bolia.com exposes 3 identifiable technologies: Cloudflare, Google Tag Manager, X-Powered-By: ASP.NET.
Cloudflare sits in front of the origin, so the server header, IP addresses and response timing describe the edge rather than the machine actually running the site.
Visitor tracking is present (Google Tag Manager), so this homepage is not cookie-free.
- Cloudflare
- Google Tag Manager
- X-Powered-By: ASP.NET
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 374ms to first byte this response is unremarkable for a homepage measured from a single European location.
The HTML weighs 116KB, which is ordinary for a homepage.
The HTML is compressed with gzip.
| Server header | cloudflare |
|---|---|
| Compression | gzip |
| Page size | 119,141 bytes |
| Declared language | en |
| Mobile viewport | declared |
What does the homepage say about itself?
The title is 31 characters, inside the range that displays without truncation.
A meta description of 146 characters is present.
No H1 heading was found, so the page offers no single top-level statement of what it is.
1 of 1 images carry no alt attribute, which leaves them unreadable to screen readers and uninterpretable to image search.
| Title | BOLIA | New Scandinavian Design (31 chars) |
|---|---|
| Meta description | Discover our universe of New Scandinavian Design – a fusion of creativity, exquisite craftsmanship and timeless materials. Explore the collection. (146 chars) |
| H1 | — none — (0 on the page) |
| Canonical | https://www.bolia.com/ |
| Open Graph title | not set |
| Headings / images | 0 H2s, 1 images (1 without alt text) |
Is bolia.com served over a valid certificate?
The HTTPS certificate is issued by Google Trust Services and is
valid until 2026-12-17, which is 73 days from the date of this check. It covers
1 hostname.
- bolia.com
The certificate has 73 days left to run.
It covers 1 hostname, so it was issued for this site specifically.
Which security headers does it set?
2 of 6 are set (Content Security Policy, X-Frame-Options). Absent: HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
Without HSTS, a browser that has never visited before will try HTTP first, which is the window a network attacker needs.
| Header | Set | Value |
|---|---|---|
| HSTS | no | — |
| Content Security Policy | yes | default-src 'self' https://*.cookieinformation.com https://assets.bolia.com; connect-src 'self' data: https |
| X-Content-Type-Options | no | — |
| X-Frame-Options | yes | SAMEORIGIN |
| Referrer-Policy | no | — |
| Permissions-Policy | no | — |
How is DNS configured for bolia.com?
| IP addresses | 104.20.27.179, 172.66.158.71, 2606:4700:10::ac42:9e47, 2606:4700:10::6814:1bb3 |
|---|---|
| Reverse DNS | 104.20.27.179, 172.66.158.71 |
| Name servers | ns2.eurodns.com, ns3.eurodns.com, ns4.eurodns.com, ns1.eurodns.com |
| Mail (MX) | bolia-com.mail.protection.outlook.com (pri 10) |
| SPF | v=spf1 include:_bolia_com.spf-protect.com -all |
| TXT records | 17 |
bolia.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.
Mail is handled by 1 exchanger.
An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.
Reverse DNS resolves to 104.20.27.179, 172.66.158.71, which usually names the hosting provider.
Who runs DNS and mail for bolia.com?
Mail is handled by Microsoft 365.
The domain publishes AAAA records and accepts connections over IPv6.
What else is worth noting about bolia.com?
3 of 3 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.
The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.
Can bolia.com be spoofed in email?
DMARC is set to reject, the strictest setting: mail that fails authentication is refused outright. This is the configuration that actually stops domain spoofing.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What does robots.txt allow?
robots.txt is 2,627 bytes and names
1 user-agent group.
It does not blanket-disallow general crawlers.
Sitemaps declared:
- https://www.bolia.com/sitemapindex.xml
AI crawler policy
robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.
What structured data does the homepage publish?
- Organization
The homepage publishes 1 structured data type: Organization.
What does bolia.com load from third parties?
The homepage pulls resources from 5 third-party hosts (az416426.vo.msecnd.net, f.vimeocdn.com, googletagmanager.com, policy.app.cookieinformation.com, widget.trustpilot.com). Each one sees the visitor IP and user agent on every page load.
3 cookies are set before any interaction (.ASPXANONYMOUS, EPi:StateMarker, EPi:StartUrlKey).
| Cookie | Secure | HttpOnly | SameSite |
|---|---|---|---|
| .ASPXANONYMOUS | yes | yes | none/unset |
| EPi:StateMarker | yes | no | none/unset |
| EPi:StartUrlKey | yes | no | none/unset |
Does bolia.com settle on one address?
Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.
Both bolia.com and www.bolia.com answer with 200 and neither redirects to the other. Search engines therefore see two complete copies of the site, and link equity is split between them unless a canonical tag resolves it.
How easily can bolia.com be crawled?
A sitemap index is served at https://www.bolia.com/sitemapindex.xml listing 20 entries.
A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.
What tracking does bolia.com run?
1 tracking script detected: Google Tag Manager.
No consent management platform was detected alongside them. Where GDPR or the ePrivacy Directive applies, analytics and advertising scripts generally need consent before they load.
How does bolia.com look when shared?
No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.
How are images, fonts and scripts handled?
1 image on the homepage, 0 of them lazy-loaded (0%).
All image references use JPEG, PNG or GIF. WebP or AVIF typically cut image weight substantially at the same visual quality.
No srcset attributes are used, so every device is served the same image size regardless of screen.
The page pulls 1 external stylesheet and 4 external scripts, with 2 carrying defer or async.
Responses carry Cloudflare edge headers, so content is served from a CDN rather than straight from the origin.
Is bolia.com accessible and current?
The page uses 0 landmark elements and 0 ARIA attributes.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
Can search engines index bolia.com?
Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.
Visible text is only 0% of the HTML, which indicates the page is assembled in the browser rather than served as content.
How is bolia.com delivered?
The HTML is served with Cache-Control: no-cache, no-store.
A web app manifest is declared, so the site is installable as a progressive web app.
Frequently asked questions
Does bolia.com set the usual HTTP security headers?
It sets 2 of 6. The ones not present are: HSTS, X-Content-Type-Options, Referrer-Policy, Permissions-Policy.
Does bolia.com allow AI crawlers?
robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.
What is bolia.com built with?
The homepage exposes these fingerprints: Cloudflare, Google Tag Manager, X-Powered-By: ASP.NET. A site behind a CDN or rendered server-side may use more than it reveals.
Where does this data come from?
Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own bolia.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 4 October 2026.
Analyse another domain →