badoo.com — domain analysis
badoo.com describes itself as "Bei Badoo, der besten kostenlosen Online-Dating-App, kannst du auch ohne Match chatten, Leute in deiner Nähe kennenlernen und weltweit neue Freunde finden.". It is built on Next.js, registered in 2003, served from Prague, Czechia. It has a valid HTTPS certificate, 4 of 6 common security headers, 1 tracking script.
What is badoo.com about?
The words appearing most often on the homepage, excluding common filler, are
a rough indication of subject matter rather than a description of the business:
- opens ×5
- window ×5
- dich ×4
- deine ×4
- chatten ×3
- zuversicht ×3
- daten ×3
- unseren ×3
- badoo ×2
- helfen ×2
Does badoo.com publish the usual trust pages?
Found: privacy, terms. Not found at the usual addresses:
about, contact.
These were checked at conventional paths only, so a site using different URLs may
publish them elsewhere.
How does badoo.com compare with other domains analysed here?
Measured against the 11 domains in this index. This is a
small, self-selected sample — the domains people happened to look up — not a
representative sample of the web.
| Response time | Faster than 73% of them (median 236ms) |
|---|---|
| Security headers | More than 78% of them |
| Domain age | Older than 60% of them |
Related domains in this index
Analysed domains built on a similar stack:
When was badoo.com registered?
badoo.com was registered on 26 May 2003, which makes it about 23 years old.
A registration this old means the domain has been renewed repeatedly, which costs money every year and is not something abandoned or disposable projects tend to do.
The registrar of record is MarkMonitor Inc..
Registration runs until 26 May 2027.
The domain carries 3 registry locks, which blocks unauthorised transfer or deletion.
| Registered | 26 May 2003 |
|---|---|
| Expires | 26 May 2027 |
| Registrar | MarkMonitor Inc. |
| Registry status | client delete prohibited, client transfer prohibited, client update prohibited |
Where is badoo.com hosted?
The first address resolves to infrastructure in Prague, Czechia.
The network is operated by Public services (AS12678 Badoo Trading Limited).
Hosting location describes where the responding server sits, not where the business is. A CDN will report its nearest edge rather than the origin.
What is badoo.com running on?
badoo.com exposes 2 identifiable technologies: Next.js, Google Tag Manager.
The build output indicates a server-rendered JavaScript framework, which means the HTML served to crawlers is generated ahead of time rather than assembled in the browser.
Visitor tracking is present (Google Tag Manager), so this homepage is not cookie-free.
- Next.js
- Google Tag Manager
How does the homepage respond?
The server answered with HTTP 200 over
HTTPS.
At 140ms to first byte this response is fast for a homepage measured from a single European location.
The HTML weighs 85KB, which is ordinary for a homepage.
The HTML is compressed with gzip.
| Server header | nginx |
|---|---|
| Compression | gzip |
| Page size | 86,946 bytes |
| Declared language | de |
| Mobile viewport | declared |
What does the homepage say about itself?
The title runs to 86 characters, so search results will truncate it and the end of the sentence will not be read.
A meta description of 155 characters is present.
All 13 images on the homepage have alt attributes.
| Title | Beste kostenlose App und Website für Online-Dating – Freunde, chatten, flirten | Badoo (86 chars) |
|---|---|
| Meta description | Bei Badoo, der besten kostenlosen Online-Dating-App, kannst du auch ohne Match chatten, Leute in deiner Nähe kennenlernen und weltweit neue Freunde finden. (155 chars) |
| H1 | Dating mit Zuversicht. (1 on the page) |
| Canonical | https://badoo.com/ |
| Open Graph title | Beste kostenlose App und Website für Online-Dating – Freunde, chatten, flirten | Badoo |
| Headings / images | 7 H2s, 13 images (0 without alt text) |
Is badoo.com served over a valid certificate?
The HTTPS certificate is issued by Let's Encrypt and is
valid until 2026-11-08, which is 34 days from the date of this check. It covers
4 hostnames.
- *.badoo.app
- *.badoo.com
- badoo.app
- badoo.com
The certificate has 34 days left to run.
Let's Encrypt certificates are free and run on 90-day terms, so this site is almost certainly renewing automatically.
Which security headers does it set?
4 of 6 are set (HSTS, Content Security Policy, X-Content-Type-Options, Referrer-Policy). Absent: X-Frame-Options, Permissions-Policy.
| Header | Set | Value |
|---|---|---|
| HSTS | yes | max-age=300; includeSubDomains |
| Content Security Policy | yes | default-src 'self' https://consent.badoo.com; script-src 'self' 'unsafe-inline' 'report-sample' 'nonce-SL3fnQjrgAXv8dluu |
| X-Content-Type-Options | yes | nosniff |
| X-Frame-Options | no | — |
| Referrer-Policy | yes | strict-origin-when-cross-origin |
| Permissions-Policy | no | — |
How is DNS configured for badoo.com?
| IP addresses | 31.222.67.112 |
|---|---|
| Reverse DNS | 31.222.67.112 |
| Name servers | ns6.badoo.com, ns5.badoo.com, ns1.badoo.com, ns8.badoo.com, ns7.badoo.com, ns2.badoo.com, ns3.badoo.com, ns4.badoo.com |
| Mail (MX) | mailin1eu.monopost.com (pri 5), mailin1us.monopost.com (pri 5) |
| SPF | v=spf1 include:mail.zendesk.com ip4:31.222.64.0/20 ip4:159.253.176.0/21 -all |
| TXT records | 7 |
badoo.com resolves to a single address, so there is no DNS-level redundancy.
Mail is handled by 2 exchangers.
An SPF record is published, giving receiving servers a rule for which hosts may send as this domain.
Reverse DNS resolves to 31.222.67.112, which usually names the hosting provider.
Who runs DNS and mail for badoo.com?
Mail exchangers point at hosts that do not match any major provider, which usually means self-hosted or niche-provider mail.
No AAAA records are published, so the site is reachable over IPv4 only.
What else is worth noting about badoo.com?
2 of 2 externally hosted scripts carry no subresource integrity hash. If one of those hosts were compromised, the replacement script would run with full access to the page.
Can badoo.com be spoofed in email?
DMARC is set to reject, the strictest setting: mail that fails authentication is refused outright. This is the configuration that actually stops domain spoofing.
No CAA records are published, so any certificate authority may issue a certificate for this domain.
The zone is not DNSSEC-signed. That is still the norm for most domains, but it means DNS answers cannot be cryptographically verified.
What else does badoo.com publish?
A security.txt file is published, giving security researchers a documented way to report vulnerabilities. Very few sites bother.
An ads.txt file is published with 249 entries, which means the site sells programmatic advertising and has declared who may resell its inventory.
An app-ads.txt file is also published, which indicates mobile app inventory alongside the website.
What does robots.txt allow?
robots.txt is 1,781 bytes and names
8 user-agent groups.
It does not blanket-disallow general crawlers.
Sitemaps declared:
- https://badoo.com/sitemap.xml
- https://badoo.com/team/sitemap.general.xml
- https://badoo.com/the-blog/sitemap.xml
AI crawler policy
robots.txt names no AI crawlers specifically, so they fall under whatever rule
applies to User-agent: *.
What structured data does the homepage publish?
No JSON-LD or microdata was found on the homepage.
What does badoo.com load from third parties?
The homepage pulls resources from 2 third-party hosts (eu1.ecdn2.badoocdn.com, googletagmanager.com). Each one sees the visitor IP and user agent on every page load.
1 cookie is set before any interaction (device_id). 1 lacks the Secure flag.
The page links or refers to X/Twitter, LinkedIn, Facebook, Instagram.
| Cookie | Secure | HttpOnly | SameSite |
|---|---|---|---|
| device_id | no | no | none/unset |
Does badoo.com settle on one address?
Plain HTTP redirects to HTTPS, so visitors who type the bare address still land on the secure version.
The www address redirects to https://badoo.com/, so the site settles on one canonical hostname.
How easily can badoo.com be crawled?
A sitemap index is served at https://badoo.com/sitemap.xml listing 48 entries.
The most recent lastmod date is 2026-10-04.
A deliberately invalid URL correctly returns HTTP 404, so missing pages will not be indexed.
What tracking does badoo.com run?
1 tracking script detected: Google Tag Manager.
No consent management platform was detected alongside them. Where GDPR or the ePrivacy Directive applies, analytics and advertising scripts generally need consent before they load.
How does badoo.com look when shared?
All five social preview tags are present, so links shared to social platforms and chat apps will render with a title, description and image.
The page declares 48 hreflang alternates (en-us, en-gb, de, fr, es, it, pt, ru, zh, id, bs, ca), so it targets more than one language or region.
How are images, fonts and scripts handled?
13 images on the homepage, 10 of them lazy-loaded (77%).
All image references use JPEG, PNG or GIF. WebP or AVIF typically cut image weight substantially at the same visual quality.
The page pulls 1 external stylesheet and 14 external scripts, with 14 carrying defer or async.
No preconnect hints are declared despite third-party scripts being present, so each new origin pays a full connection setup before it can deliver anything.
Is badoo.com accessible and current?
The page uses 5 landmark elements and 39 ARIA attributes.
No skip-to-content link was found, which keyboard users rely on to bypass navigation.
The visible copyright notice reads 2006, 20 years behind the current year, which usually indicates the site is not actively maintained.
Can search engines index badoo.com?
Nothing on the homepage prevents indexing: no noindex is set in the robots meta tag or the X-Robots-Tag header.
The homepage carries 72 internal and 9 external links across 7 outside hosts.
Visible text is only 3.9% of the HTML, which indicates the page is assembled in the browser rather than served as content.
How is badoo.com delivered?
The HTML is served with Cache-Control: no-store, no-cache, must-revalidate, max-age=0, post-check=0, pre-check=0, private, private, no-cache, no-store, max-age=0, must-revalidate.
A web app manifest is declared, so the site is installable as a progressive web app.
Frequently asked questions
Does badoo.com set the usual HTTP security headers?
It sets 4 of 6. The ones not present are: X-Frame-Options, Permissions-Policy.
Does badoo.com allow AI crawlers?
robots.txt names no AI crawler specifically, so they fall under the wildcard rule, which does not disallow them.
What is badoo.com built with?
The homepage exposes these fingerprints: Next.js, Google Tag Manager. A site behind a CDN or rendered server-side may use more than it reveals.
Where does this data come from?
Every figure was measured by our own server on 4 October 2026: DNS lookups, one HTTPS request to the homepage, a TLS handshake and a request for robots.txt. No third-party SEO API is involved.
Is any of this traffic or authority data?
No. Traffic, authority and ranking figures cannot be measured by inspecting a domain, only modelled. Everything here is a direct observation.
I own badoo.com and want this page removed.
Ask through the contact page on this site, from an address at the domain, and the report will be taken down. It only ever shows what the domain already serves publicly.
Analysed 4 October 2026.
Analyse another domain →
⚠ Stay safe
Gabay is an independent guide, not a government website. Do the steps only on the official portal. Never share your ID number, PIN, OTP, password or card details with anyone who calls, messages or "helps" you — no genuine agency asks for them.
Gabay is an independent guide and is not affiliated with any government agency. Fees, links and steps can change — always confirm on the official portal before you act. This is general information, not legal or financial advice.