pepeta.com — domain analysis
pepeta.com describes itself as "Pepeta, Kenya". It was registered in 2004, served from Toronto, Canada. It has a valid HTTPS certificate, 1 of 6 common security headers.
Does pepeta.com publish the usual trust pages?
All four of the pages a established business normally publishes were found:
about, contact, privacy and terms.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does pepeta.com compare with other domains analysed here?
Measured against the 73 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 85% of them (median 423ms) |
|---|---|
| Security headers | More than 48% of them |
| Domain age | Older than 51% of them |
Related domains in this index
Analysed domains sharing the same network (AS13335 Cloudflare, Inc.):
Sharing a network means sharing a host or CDN. It implies nothing about a
relationship between the sites themselves.
Analysed domains built on a similar stack:
Other analysed domains served from the same country:
- altl.com
- babosas.com
- costcotireappointments.com
- kurladay.com
- linkapple.com
- mulher.com
- rugs.com
- sapphire.com
When was pepeta.com registered?
pepeta.com was registered on 6 July 2004, which makes it about 22 years old.
A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.
The registrar of record is GoDaddy.com, LLC.
Registration runs until 6 July 2028.
The domain carries 4 registry locks, which blocks unauthorised transfer or deletion.
| Registered | 6 July 2004 |
|---|---|
| Expires | 6 July 2028 |
| Registrar | GoDaddy.com, LLC |
| Registry status | client delete prohibited, client renew prohibited, client transfer prohibited, client update prohibited |
Where is pepeta.com hosted?
The first address resolves to infrastructure in Toronto, Canada.
The network is operated by Cloudflare, Inc. (AS13335 Cloudflare, Inc.).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is pepeta.com running on?
pepeta.com exposes 1 identifiable technology: Cloudflare.
Cloudflare sits in front of the origin, so the server header, IP addresses and response timing describe the edge rather than the machine actually running the site.
- Cloudflare
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 87ms to first byte this response is fast for a homepage measured from a single European location.
At 8KB the HTML is unusually small, which typically means the page builds itself client-side after load.
The HTML is compressed with gzip.
| Server header | cloudflare |
|---|---|
| Compression | gzip |
| Page size | 8,524 bytes |
| Declared language | en |
| Mobile viewport | declared |
What does the homepage say about itself?
The title is 40 characters, inside the range that displays without truncation.
A meta description of 13 characters is present.
No H1 heading was found, so the page offers no single top-level statement of what it is.
1 of 1 images carry no alt attribute, which leaves them unreadable to screen readers and uninterpretable to image search.
| Title | Pepeta | Best Online Casino & Sportsbook (40 chars) |
|---|---|
| Meta description | Pepeta, Kenya (13 chars) |
| H1 | — none — (0 on the page) |
| Canonical | not set |
| Open Graph title | not set |
| Headings / images | 0 H2s, 1 images (1 without alt text) |
Is pepeta.com served over a valid certificate?
The HTTPS certificate is issued by Google Trust Services and is
valid until 2026-11-14, which is 40 days from the date of this check. It covers
4 hostnames.
- pepeta.com
- *.international.pepeta.com
- *.ke.pepeta.com
- *.pepeta.com
The certificate has 40 days left to run.
Which security headers does it set?
1 of 6 are set (HSTS). Absent: Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.
With no Content Security Policy, any script that reaches the page — including one injected through a compromised third-party dependency — runs with full access to it.
| Header | Set | Value |
|---|---|---|
| HSTS | yes | max-age=31556926; includeSubDomains; preload |
| Content Security Policy | no | — |
| X-Content-Type-Options | no | — |
| X-Frame-Options | no | — |
| Referrer-Policy | no | — |
| Permissions-Policy | no | — |
How is DNS configured for pepeta.com?
| IP addresses | 104.18.11.235, 104.18.10.235, 2606:4700::6812:beb, 2606:4700::6812:aeb |
|---|---|
| Reverse DNS | 104.18.11.235, 104.18.10.235 |
| Name servers | melnicoff.ns.cloudflare.com, naomi.ns.cloudflare.com |
| Mail (MX) | no mail records |
| SPF | not published |
| TXT records | 2 |
pepeta.com resolves to 4 addresses, which indicates load balancing or a CDN rather than a single origin server.
No MX records are published, so this domain does not receive mail at its apex. Mail sent to it will bounce.
No SPF record is published. Receiving servers therefore have no published rule for who may send mail as this domain, which makes spoofing it materially easier.
Reverse DNS resolves to 104.18.11.235, 104.18.10.235, which usually names the hosting provider.
Who runs DNS and mail for pepeta.com?
DNS is operated by Cloudflare rather than self-hosted name servers.
The domain publishes AAAA records and accepts connections over IPv6.
What else is worth noting about pepeta.com?
All 1 externally hosted scripts carry subresource integrity hashes, so a compromised CDN could not silently swap them.
1 email address appears in the homepage markup, where address-harvesting crawlers will find it.
Can pepeta.com be spoofed in email?
No DMARC record is published, so there is no instruction telling receiving servers what to do with mail that fails authentication. In practice that means forged mail from this domain is likely to be delivered.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What does robots.txt allow?
robots.txt is 805 bytes and names
1 user-agent group.
It does not blanket-disallow general crawlers.
Sitemaps declared:
- https://pepeta.com/sitemap/sitemap.xml
- https://pepeta.com/sitemap/casino.xml
- https://pepeta.com/sitemap/pages.xml
- https://pepeta.com/sitemap/sports.xml
- https://pepeta.com/sitemap/crash-games.xml
- https://pepeta.com/sitemap/virtuals.xml
- https://pepeta.com/sitemap/promos.xml
- https://pepeta.com/sitemap/legal.xml
AI crawler policy
robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.
What structured data does the homepage publish?
- Corporation
- ImageObject
- ContactPoint
- OfferCatalog
- Offer
- Service
- Country
The homepage publishes 7 structured data types: Corporation, ImageObject, ContactPoint, OfferCatalog, Offer, Service, Country.
What does pepeta.com load from third parties?
The homepage pulls resources from 1 third-party host (static.cloudflareinsights.com). Each one sees the visitor IP and user agent on every page load.
1 cookie is set before any interaction (__cf_bm).
The page links or refers to X/Twitter, Facebook, Instagram, YouTube.
| Cookie | Secure | HttpOnly | SameSite |
|---|---|---|---|
| __cf_bm | yes | yes | none |
Does pepeta.com settle on one address?
Plain HTTP serves the site directly instead of redirecting to HTTPS. That leaves an unencrypted copy reachable and gives search engines two addresses for the same content.
The www address redirects to https://pepeta.com/, so the site settles on one canonical hostname.
How easily can pepeta.com be crawled?
A sitemap index is served at https://pepeta.com/sitemap/sitemap.xml listing 8 entries.
A deliberately invalid URL returns HTTP 200 rather than 404. That is a soft 404: every mistyped or stale link becomes an indexable page, which inflates the site with duplicates.
What tracking does pepeta.com run?
No analytics or advertising trackers were detected on the homepage of pepeta.com, which is unusual for a commercial site.
How does pepeta.com look when shared?
No Open Graph or Twitter Card tags are present. Links shared to social platforms will fall back to whatever the platform can scrape, usually just a bare URL.
How are images, fonts and scripts handled?
1 image on the homepage, 0 of them lazy-loaded (0%).
All image references use JPEG, PNG or GIF. WebP or AVIF typically cut image weight substantially at the same visual quality.
No srcset attributes are used, so every device is served the same image size regardless of screen.
The page pulls 2 external stylesheets and 2 external scripts, with 1 carrying defer or async.
Responses carry Cloudflare and Varnish/Fastly edge and edge cache edge headers, so content is served from a CDN rather than straight from the origin.
Is pepeta.com accessible and current?
The page uses 0 landmark elements and 0 ARIA attributes.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
Can search engines index pepeta.com?
Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.
No canonical URL is declared, which leaves duplicate addresses of this page to be resolved by the search engine.
The homepage carries 2 internal and 0 external links across 0 outside hosts.
Visible text is only 1% of the HTML, which indicates the page is assembled in the browser rather than served as content.
How is pepeta.com delivered?
The HTML is served with Cache-Control: max-age=3600.
A web app manifest is declared, so the site is installable as a progressive web app.
The TLS certificate also covers 2 subdomains: international.pepeta.com, ke.pepeta.com.
- international.pepeta.com
- ke.pepeta.com
Frequently asked questions
Does pepeta.com set the usual HTTP security headers?
It sets 1 of 6. The ones not present are: Content Security Policy, X-Content-Type-Options, X-Frame-Options, Referrer-Policy, Permissions-Policy.
Does pepeta.com allow AI crawlers?
robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.
What is pepeta.com built with?
The homepage exposes these fingerprints: Cloudflare. A site behind a CDN or rendered server-side may use more than it reveals.
Where does this data come from?
Every figure was measured by our own server on 5 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own pepeta.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 5 October 2026.
Analyse another domain →
Get launch updates from Aavot
One email when the official app ships. No spam, unsubscribe anytime.
Related reading
RAM vs Storage on a Phone: What’s the Difference?
RAM vs storage on a phone explained simply: what each one does, why they are different, how much you need, and which matters for speed.
What Is Bluetooth, and How Does It Work?
What is Bluetooth, explained simply: how wireless pairing works, its range and uses, battery impact, and how to use Bluetooth safely on Android.
What Is a Mobile Hotspot?
A mobile hotspot lets your phone share its internet with other devices. Learn how it works, when to use it, battery and data tips, and safety.