Home › Guides › emojicombos.com — domain analysis
Guide

emojicombos.com — domain analysis

✎ Independent, reader-supported guide — information, not financial advice. Crypto card terms change often; confirm current details with the issuer.

emojicombos.com describes itself as "A database of emoji combinations!". It was registered in 2020, served from Toronto, Canada. It has a valid HTTPS certificate, 1 of 6 common security headers, 1 tracking script.

200HTTP status
65msResponse time
78Words on the homepage
1/6Security headers set

What is emojicombos.com about?

The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:

  • emoji ×4
  • combos ×2
  • search ×2
  • maker ×2

Does emojicombos.com publish the usual trust pages?

All four of the pages a established business normally publishes were found:
about, contact, privacy and terms.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does emojicombos.com compare with other domains analysed here?

Measured against the 74 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 92% of them
(median 463ms)
Security headers More than 35% of them
Domain age Older than 31% of them

Related domains in this index

Analysed domains sharing the same network (AS13335 Cloudflare, Inc.):

Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.

Analysed domains built on a similar stack:

Other analysed domains served from the same country:

When was emojicombos.com registered?

emojicombos.com was registered on 26 July 2020, which makes it about 6 years old.

The registrar of record is NameCheap, Inc..

Registration runs until 26 July 2027.

The domain carries 1 registry lock, which blocks unauthorised transfer or deletion.

Registered 26 July 2020
Expires 26 July 2027
Registrar NameCheap, Inc.
Registry status client transfer prohibited

Where is emojicombos.com hosted?

The first address resolves to infrastructure in Toronto, Canada.

The network is operated by Cloudflare, Inc. (AS13335 Cloudflare, Inc.).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is emojicombos.com running on?

emojicombos.com exposes 3 identifiable technologies: Google Analytics, X-Powered-By: Express, Cloudflare.

Cloudflare sits in front of the origin, so the server header, IP addresses and response timing describe the edge rather than the machine actually running the site.

Visitor tracking is present (Google Analytics), so this homepage is not cookie-free.

  • Google Analytics
  • X-Powered-By: Express
  • Cloudflare

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 65ms to first byte this response is fast for a homepage measured from a single European location.

At 5KB the HTML is unusually small, which typically means the page builds itself client-side after load.

The HTML is compressed with gzip.

Server header cloudflare
Compression gzip
Page size 5,480 bytes
Declared language en
Mobile viewport declared

What does the homepage say about itself?

The title is only 12 characters, which is short enough that it probably is not describing the page so much as naming it.

A meta description of 33 characters is present.

Title Emoji Combos (12 chars)
Meta description A database of emoji combinations! (33 chars)
H1 Emoji Combosbeta (1 on the page)
Canonical not set
Open Graph title not set
Headings / images 0 H2s, 0 images (0 without alt text)

Is emojicombos.com served over a valid certificate?

The HTTPS certificate is issued by Google Trust Services and is
valid until 2026-12-16, which is 72 days from the date of this check. It covers
2 hostnames.

  • emojicombos.com
  • *.emojicombos.com

The certificate has 72 days left to run.

It covers 2 hostnames, so it was issued for this site specifically.

Which security headers does it set?

1 of 6 are set (Permissions-Policy). Absent: HSTS, Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy.

Without HSTS, a browser that has never visited before will try HTTP first, which is the window a network attacker needs.

With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.

Header Set Value
HSTS no —
Content Security Policy no —
X-Content-Type-Options no —
X-Frame-Options no —
Referrer-Policy no —
Permissions-Policy yes local-network=(), loopback-network=(), local-network-access=()

How is DNS configured for emojicombos.com?

IP addresses 172.67.185.227, 104.21.51.207, 2606:4700:3031::ac43:b9e3, 2606:4700:3033::6815:33cf
Reverse DNS 172.67.185.227, 104.21.51.207
Name servers dara.ns.cloudflare.com, cash.ns.cloudflare.com
Mail (MX) no mail records
SPF not published
TXT records 0

emojicombos.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.

No MX records are published, so this domain does not receive mail at its apex. Mail sent to it will bounce.

No SPF record is published. Receiving servers therefore have no published rule for who may send mail as this domain, which makes spoofing it materially easier.

Reverse DNS resolves to 172.67.185.227, 104.21.51.207, which usually names the hosting provider.

Who runs DNS and mail for emojicombos.com?

DNS is operated by Cloudflare rather than self-hosted name servers.

The domain publishes AAAA records and accepts connections over IPv6.

What else is worth noting about emojicombos.com?

2 of 2 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.

The server discloses software detail in x-powered-by, which tells an attacker what to target without them having to probe for it.

Can emojicombos.com be spoofed in email?

No DMARC record is published, so there is no instruction telling receiving servers what to do with mail that fails authentication. In practice that means forged mail from this domain is likely to be delivered.

No CAA records are published, so any certificate authority may issue a certificate for this domain.

The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.

What else does emojicombos.com publish?

An ads.txt file is published with 182 entries, which means the site sells programmatic advertising and has declared who may resell its inventory.

What does robots.txt allow?

No robots.txt was served. Crawlers treat a missing file as permission to crawl
everything, so this is an open crawl policy by default rather than a blocked one.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does emojicombos.com load from third parties?

The homepage pulls resources from 3 third-party hosts (fonts.googleapis.com, googletagmanager.com, pagead2.googlesyndication.com). Each one sees the visitor IP and user agent on every page load.

No cookies are set on first load.

Does emojicombos.com settle on one address?

Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.

The www hostname does not respond at all, so anyone typing www.emojicombos.com reaches nothing.

How easily can emojicombos.com be crawled?

No readable sitemap was found, so crawlers have to discover every page by following links.

A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.

What tracking does emojicombos.com run?

1 tracking script detected: Google Analytics.

No consent management platform was detected alongside them. Where GDPR or the ePrivacy Directive applies, analytics and advertising scripts generally need consent before they load.

How does emojicombos.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

Fonts are loaded from Google Fonts, which means every page view also contacts Google. Self-hosting removes that dependency.

The page pulls 1 external stylesheet and 2 external scripts, with 2 carrying defer or async.

No preconnect hints are declared despite third-party scripts being present, so each new origin pays a full connection setup before it can deliver anything.

Responses carry Cloudflare edge headers, so content is served from a CDN rather than straight from the origin.

Is emojicombos.com accessible and current?

The page uses 0 landmark elements and 0 ARIA attributes.

There are 2 form inputs but only 0 label elements, so some fields may be unlabelled for screen readers.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index emojicombos.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

The homepage carries 4 internal and 2 external links across 2 outside hosts.

Visible text makes up 7.7% of the HTML.

How is emojicombos.com delivered?

The HTML is served with Cache-Control: public, max-age=10800.

HTTP/3 is advertised via alt-svc, so modern browsers will upgrade to QUIC after the first visit.

A web app manifest is declared, so the site is installable as a progressive web app.

Frequently asked questions

Does emojicombos.com set the usual HTTP security headers?

It sets 1 of 6. The ones not present are: HSTS, Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy.

Does emojicombos.com allow AI crawlers?

No robots.txt is served, so nothing is disallowed and AI crawlers are free to read the site.

What is emojicombos.com built with?

The homepage exposes these fingerprints: Google Analytics, X-Powered-By: Express, Cloudflare. A site behind a CDN or rendered server-side may use more than it reveals.

Where does this data come from?

Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own emojicombos.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 5 October 2026.
Analyse another domain →

Related guides