bolt.new

.new user

First seen 2026-05-18 · Last seen 2026-05-18 · ok HTTP/1.1 200 549 ms crawled 2026-05-18

US · 104.26.7.237 · AS13335 Cloudflare, Inc.

Reputation 94/100 dmarc monitor-only

sector tech type homepage

HTML metadata

Title
Bolt AI builder: Websites, apps & prototypes
Description
Build and scale high-performing websites & apps using your words. Join millions and start building today.
Language
en
Canonical
https://bolt.new

Open Graph

title
Bolt AI builder: Websites, apps & prototypes
site name
bolt.new
description
Build and scale high-performing websites & apps using your words. Join millions and start building today.

Technology

CDN
Cloudflare
CMS
Gatsby
Fonts
  • Google Fonts

Third-party hosts loaded (2)

  • fonts.googleapis.com×2
  • fonts.gstatic.com×1

Social

Registration

Registrar
CloudFlare, Inc.
Created
2024-07-09
Expires
2026-07-09 51 days left
Updated
2025-10-08
Name servers
  • igor.ns.cloudflare.com
  • zoe.ns.cloudflare.com

DNS records live

NS
  • igor.ns.cloudflare.com
  • zoe.ns.cloudflare.com
MX
  • 1 aspmx.l.google.com
  • 10 alt3.aspmx.l.google.com
  • 10 alt4.aspmx.l.google.com
  • 5 alt1.aspmx.l.google.com
  • 5 alt2.aspmx.l.google.com
TXT
  • google-site-verification=Wsk42_qZh5E-NOchFjDzFWwxeOLXDQvfgbj-zr3phEc
  • slack-domain-verification=WygKS53HVC89wD364pljsC62Cnnp58gNerpAjSII
  • google-site-verification=96wvmghdIe3MaW_yrNw-4cAmeWOUGVr9aeKeAVXd2H8

Email authentication partial

SPF
v=spf1 include:_spf.google.com include:45403856.spf03.hubspotemail.net -all
strict (-all)
DMARC
v=DMARC1; p=none; rua=mailto:eccae4a77eef461e9220ef9ead526bee@dmarc-reports.cloudflare.net;
policy: none (monitoring only)
DKIM
  • google: v=DKIM1; k=rsa; p=MIIBIjANBgkqhkiG9w0BAQEFAAOCAQ8AMIIBCgKCAQEAqdgxFsFcTDCjsvW76JC5Cl0ohe9Tgm7xdenKHVvsLHjebe61HsmWZCz0uHa6GrZiWhLmdELJpbqy5d…
selectors probed

Certificate (current)

WE1
from 2026-05-10 to 2026-08-08
Expires in 81 days

HTTP security headers

Header hygiene 50/100 Checked live page: https://bolt.new/

present
  • strict-transport-security
  • cross-origin-opener-policy
  • cross-origin-embedder-policy
findings
  • missing Content Security Policy
  • missing frame protection
  • missing content type protection
  • missing Referrer Policy
  • missing Permissions Policy
Header values
strict-transport-security
max-age=15552000
cross-origin-opener-policy
same-origin
cross-origin-embedder-policy
require-corp

Links to (7)