Home › Guides › nordstromcard.com — domain analysis
Guide

nordstromcard.com — domain analysis

✎ Independent, reader-supported guide — information, not financial advice. Crypto card terms change often; confirm current details with the issuer.

nordstromcard.com is a live website, registered in 2001, served from Washington, United States. It has a valid HTTPS certificate, 5 of 6 common security headers.

200HTTP status
1919msResponse time
6Words on the homepage
5/6Security headers set

What is nordstromcard.com about?

The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:

  • nordstrom ×2
  • card ×2
  • services ×2

Does nordstromcard.com publish the usual trust pages?

All four of the pages a established business normally publishes were found:
about, contact, privacy and terms.

These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.

How does nordstromcard.com compare with other domains analysed here?

Measured against the 74 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.

Response time Faster than 5% of them
(median 463ms)
Security headers More than 89% of them
Domain age Older than 67% of them

Related domains in this index

Analysed domains sharing the same network (AS8075 Microsoft Corporation):

Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.

Other analysed domains served from the same country:

When was nordstromcard.com registered?

nordstromcard.com was registered on 7 November 2001, which makes it about 24 years old.

A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.

The registrar of record is MarkMonitor Inc..

Registration expires in 32 days (7 November 2026), which is close enough that a missed renewal would take the site offline.

The domain carries 3 registry locks, which blocks unauthorised transfer or deletion.

Registered 7 November 2001
Expires 7 November 2026
Registrar MarkMonitor Inc.
Registry status client delete prohibited, client transfer prohibited, client update prohibited

Where is nordstromcard.com hosted?

The first address resolves to infrastructure in Washington, United States.

The network is operated by Microsoft Corporation (AS8075 Microsoft Corporation).

Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.

What is nordstromcard.com running on?

No platform, framework or analytics fingerprints were found in the homepage markup of nordstromcard.com. That usually means hand-written HTML, an uncommon stack, or a page assembled entirely at the edge.

No recognisable platform, framework or analytics fingerprints were found in the homepage markup.

How does the homepage respond?

The server answered with HTTP 200 over
HTTPS.

At 1919ms to first byte this response is very slow for a homepage measured from a single European location.

At 6KB the HTML is unusually small, which typically means the page builds itself client-side after load.

The HTML is compressed with gzip.

Server header not disclosed
Compression gzip
Page size 6,368 bytes
Declared language en
Mobile viewport declared

What does the homepage say about itself?

The title is 23 characters, inside the range that displays without truncation.

There is no meta description, so the snippet shown in search results is assembled by the search engine from whatever text it considers relevant.

There are 2 H1 headings. One is conventional; several dilute the signal about what the page is primarily about.

Title Nordstrom Card Services (23 chars)
Meta description — none — (0 chars)
H1 Nordstrom Card Services (2 on the page)
Canonical not set
Open Graph title not set
Headings / images 0 H2s, 0 images (0 without alt text)

Is nordstromcard.com served over a valid certificate?

The HTTPS certificate is issued by SSL Corporation and is
valid until 2027-01-01, which is 88 days from the date of this check. It covers
1 hostname.

  • nordstromcard.com

The certificate has 88 days left to run.

It covers 1 hostname, so it was issued for this site specifically.

Which security headers does it set?

5 of 6 are set (HSTS, Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy). Absent: Permissions-Policy.

Header Set Value
HSTS yes max-age=31449600; includeSubDomains
Content Security Policy yes default-src 'self'; connect-src 'self' https://*.nordstromcard.com https://nordstromcard.com https://retail.prd.tdb.azur
X-Content-Type-Options yes nosniff
X-Frame-Options yes sameorigin
Referrer-Policy yes no-referrer
Permissions-Policy no —

How is DNS configured for nordstromcard.com?

IP addresses 150.171.110.49, 2603:1061:14:66::1
Reverse DNS 150.171.110.49, 2603:1061:14:66::1
Name servers —
Mail (MX) no mail records
SPF not published
TXT records 0

nordstromcard.com resolves to 2 addresses, which indicates load balancing or a CDN rather than a single origin server.

No MX records are published, so this domain does not receive mail at its apex. Mail sent to it will bounce.

No SPF record is published. Receiving servers therefore have no published rule for who may send mail as this domain, which makes spoofing it materially easier.

Reverse DNS resolves to 150.171.110.49, 2603:1061:14:66::1, which usually names the hosting provider.

Who runs DNS and mail for nordstromcard.com?

The domain publishes AAAA records and accepts connections over IPv6.

What else is worth noting about nordstromcard.com?

The page title and the H1 are identical. That is not an error, but it usually means one of the two is not doing any work.

Can nordstromcard.com be spoofed in email?

No DMARC record is published, so there is no instruction telling receiving servers what to do with mail that fails authentication. In practice that means forged mail from this domain is likely to be delivered.

CAA records restrict certificate issuance to 2 named authorities (afd-tdb-prd-a8gwdrc7a2b5bned.a02.azurefd.net., mr-a02.tm-azurefd.net.), so no other CA should be able to issue for this domain.

The zone is DNSSEC-signed, so resolvers can verify the DNS answers have not been tampered with in transit.

What does robots.txt allow?

robots.txt is 389 bytes and names
10 user-agent groups.

It does not blanket-disallow general crawlers.

No sitemap is declared in robots.txt.

AI crawler policy

Crawler Policy
gptbot blocked
claudebot blocked
perplexitybot blocked
ccbot blocked
anthropic-ai blocked

No sitemap is declared in robots.txt, so crawlers must discover pages by following links.

Every named AI crawler is blocked (gptbot, claudebot, perplexitybot, ccbot, anthropic-ai). This domain has opted out of AI training and AI answer surfaces wholesale.

What structured data does the homepage publish?

No JSON-LD or microdata was found on the homepage.

What does nordstromcard.com load from third parties?

The homepage loads no resources from third-party hosts at all, which is rare and means visiting it tells no other company that you did.

2 cookies are set before any interaction (ASLBSA, ASLBSACORS).

Cookie Secure HttpOnly SameSite
ASLBSA yes yes none/unset
ASLBSACORS yes yes none

Does nordstromcard.com settle on one address?

Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.

The www address redirects, so the site settles on one canonical hostname.

How easily can nordstromcard.com be crawled?

No readable sitemap was found, so crawlers have to discover every page by following links.

A deliberately invalid URL returns HTTP 200 rather than 404. That is a soft 404: every mistyped or stale link becomes an indexable page, which inflates the site with duplicates.

What tracking does nordstromcard.com run?

No analytics or advertising trackers were detected on the homepage of nordstromcard.com, which is unusual for a commercial site.

How does nordstromcard.com look when shared?

No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.

How are images, fonts and scripts handled?

The page pulls 0 external stylesheets and 3 external scripts, with 0 carrying defer or async.

Responses carry edge cache edge headers, so content is served from a CDN rather than straight from the origin.

Is nordstromcard.com accessible and current?

The page uses 2 landmark elements and 1 ARIA attribute.

No skip-to-content link was found, which keyboard users rely on to bypass navigation.

Can search engines index nordstromcard.com?

Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.

No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.

Visible text is only 0.7% of the HTML, which indicates the page is assembled in the browser rather than served as content.

How is nordstromcard.com delivered?

The HTML is served with Cache-Control: no-cache, no-store, max-age=0, must-revalidate, proxy-revalidate.

Frequently asked questions

Does nordstromcard.com set the usual HTTP security headers?

It sets 5 of 6. The ones not present are: Permissions-Policy.

Does nordstromcard.com allow AI crawlers?

No — robots.txt blocks gptbot, claudebot, perplexitybot, ccbot, anthropic-ai.

Where does this data come from?

Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.

Is any of this traffic or authority data?

No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.

I own nordstromcard.com and want this page removed.

Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.

Analysed 5 October 2026.
Analyse another domain →

Related guides