🌐

substack.com

CA
✓ HTTPS ✓ HTTP/2 ✓ Gzip 60.0% ⚡ 10154ms
substack.com Overview

Get a snapshot of substack.com's online performance, security posture, and technology profile.

substack.com Website Overview & Technology Report

79
Trust Score
Likely Safe
40
Security
Headers: 2/6
10154ms
Response
Slow
2
Technologies
Detected
🤖 AI Analysis

We performed a comprehensive analysis of substack.com on 2026-06-29. The website returned an HTTP 200 status code with a server response time of 10154ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 73 KB, and the site is served behind a CDN (Content Delivery Network). The website uses a secure HTTPS connection with a valid SSL certificate issued by Google Trust Services (DV type). The connection is encrypted using TLS 1.3 with the TLS_AES_256_GCM_SHA384 cipher suite and ECDSA-SHA256 signature algorithm. The certificate covers 2 domain(s) (Subject Alternative Names) and expires on 2026-08-22, which is 54 days from now. The security headers analysis reveals a score of 40/100 (below average). The following security headers are properly configured: Content-Security-Policy and Strict-Transport-Security (HSTS). However, the site is missing X-Frame-Options, X-Content-Type-Options, Referrer-Policy, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks. Our technology detection scan identified 2 technologies across 2 categories powering substack.com. The detected stack includes React and Vite. The UI is built with React. Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, substack.com receives an overall trust score of 79/100, classified as "Likely Safe".

Status Code200 OK
HTTP VersionHTTP/2
Servercloudflare
Page Size73 KB
Total Requests179
3rd Party Domains2
SSL CertificateGoogle Trust Services (DV) · 54 days left
TLS VersionTLS 1.3
IP Address172.64.150.56
substack.com Trust & Safety

Evaluate trustworthiness based on age, SSL, email authentication, security headers, and blacklist status across 8 threat databases.

substack.com Trust Score & Safety Analysis

79
Trust Score
40
Security
🤖 Trust Analysis

After conducting a thorough safety and legitimacy analysis, substack.com receives a trust score of 79/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases. The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, HSTS (HTTP Strict Transport Security) enforcement preventing protocol downgrade attacks, a valid SSL certificate issued by Google Trust Services with 54 days until expiration, SPF (Sender Policy Framework) email authentication preventing email spoofing, DMARC email authentication with a reject policy — the strongest available setting, and DKIM (DomainKeys Identified Mail) providing cryptographic email verification. Areas of concern include: no X-Frame-Options header, which could allow the site to be embedded in malicious iframes (clickjacking), missing Referrer-Policy, potentially leaking URL information to third parties, the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved. We checked substack.com against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.

HTTPS + HSTS
+12
SPF + DMARC + DKIM
+8
SSL Certificate
+7
Security Headers
−5

Security Headers

Content-Security-Policy✓ Set
HSTS✓ Set
X-Frame-Options✗ Missing
X-Content-Type-Options✗ Missing
Referrer-Policy✗ Missing
Permissions-Policy✗ Missing

Blacklist Checks 8/8 Clean ✓

Google Safe Browsing
Phishtank
Urlhaus
Openphish
Dnsfilter
Spamhaus Dbl
Surbl
Virustotal

Rankings & Estimates

Tranco Rank#468 worldwide

🔍 Analyze Your Own Website

Check your site's trust score, security headers, tech stack and 50+ metrics — completely free.

Analyze Now →
substack.com Technology Stack 2 detected

Discover every technology powering this website — from CMS and frameworks to analytics, payments, and marketing tools.

substack.com Technology Stack & Detected Technologies

🤖 Stack Analysis

Our technology detection engine scanned substack.com and identified 2 distinct technologies across 2 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records. UI Library: React — handles the user interface rendering and component management for substack.com. Build Tool: Vite — bundles and optimizes the JavaScript and CSS assets for substack.com.

⚛️ UI Library
React 95%
🔨 Build Tool
Vite 95%
substack.com Performance & Web Vitals

Response time, compression, CDN usage, Core Web Vitals, and environmental impact metrics for substack.com.

substack.com Performance & Web Vitals Report

🤖 Performance Analysis

substack.com delivers its homepage in 10154ms (server response time), which is considered slow by industry standards. The total page weight is 73 KB, and we detected 179 resource requests loading assets from 2 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain. The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections. Asset minification status: 0 out of 14 CSS files and 0 out of 151 JavaScript files are minified. Minifying the remaining 165 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality. The site is served through a Content Delivery Network (CDN), which caches static assets at edge servers around the world. This means visitors from different geographic regions receive content from the nearest edge server, significantly reducing latency. CDN usage is particularly important for websites with a global audience, as it can reduce page load times by 40-60% for distant visitors. From an environmental perspective, each page view of substack.com produces approximately 0.04g of CO₂, earning a carbon rating of A. This places the website among the cleanest on the web, demonstrating efficient use of server resources and optimized content delivery. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 73 KB is the primary factor in this calculation. Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for substack.com. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.

Response Time10154ms Slow
Page Size73 KB
CompressionGzip 60.0% savings
CDNNot detected
Carbon / Page View0.04g · Rating A
substack.com DNS & Domain Info

Complete DNS record analysis including email authentication (SPF, DMARC, DKIM), registrar details, and subdomain discovery.

substack.com DNS Records, Email Authentication & Domain Registration

🤖 DNS Analysis

substack.com resolves to the IPv4 address 172.64.150.56 and also supports IPv6 (2606:4700:4401::ac40:9638), demonstrating modern network infrastructure readiness. The domain has 2 A record(s) configured. The domain name system is managed by 2 name servers: ali.ns.cloudflare.com and lee.ns.cloudflare.com. Having 2 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used. Email for substack.com is handled by mailgun.org with 2 MX records configured: mxa.mailgun.org and mxb.mailgun.org. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server. SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC (Domain-based Message Authentication, Reporting and Conformance) is configured with a reject policy — the strongest setting, instructing receiving servers to reject unauthorized emails entirely. DKIM (DomainKeys Identified Mail) is configured, adding a cryptographic signature to outgoing emails that receiving servers can verify to confirm the email hasn't been tampered with in transit. DNSSEC is not enabled for substack.com. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions. Our subdomain enumeration scan discovered 25 active subdomains for substack.com: admin.substack.com, api.substack.com, app.substack.com, apps.substack.com, blog.substack.com, cdn.substack.com, community.substack.com, and dev.substack.com. Plus 17 additional subdomains. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.

IP Address172.64.150.56
IPv62606:4700:4401::ac40:9638
ASNAS13335 · Cloudflare, Inc.
LocationToronto, CA
Nameserversali.ns.cloudflare.com
MX Providermailgun.org (mxa.mailgun.org)
CountryCA
SPF✓ Configured
DMARC✓ reject
DMARC Recordv=DMARC1; p=reject; pct=100; rua=mailto:re+kvnosxqvppz@dmarc.postmarkapp.com; sp=reject; aspf=r;
DKIM✓ Found
DNSSEC✗ Not enabled
IPv6✓ Supported
WHOIS Privacy🔒 Private

Subdomains 25 found

adminapiappappsblogcdncommunitydevdevelopersdocsftphelpmmailpartnersportalshopsmtpstagingstaticstatusstoresupportwebmailwww

TXT Records / Service Verifications 9

Google ✓ Facebook ✓ +7 more
substack.com Page Analysis

Content structure, media assets, cookie usage, payment methods, and social media presence for substack.com.

substack.com Page Content Analysis

🤖 Content Analysis

The homepage of substack.com contains 56 words of visible text content. This is a relatively short page — adding more descriptive content could improve search engine visibility. The page is structured with 0 H2 headings, 1 H3 headings, 1 H4 headings. The link structure consists of 1 internal link pointing to other pages on the same domain and 1 external link pointing to third-party websites. There are 151 external JavaScript files, 14 CSS stylesheets, and 0 iframes on the page. The site implements the following web standards and features: XML Sitemap (helps search engines discover all pages), robots.txt (controls search engine crawling behavior), and Progressive Web App (PWA) manifest (enabling app-like installation). Notable missing features: Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility.

Word Count56 words
Images0 total · 100% alt coverage
Internal Links1
External Links1
JS Files151
CSS Files14
substack.com SEO & Content Analysis

Evaluate on-page SEO factors including meta tags, Schema.org markup, content metrics, social presence, and environmental impact.

substack.com SEO Analysis, Meta Tags & Content

🤖 SEO Analysis

The title tag for substack.com is good at 8 characters: "Substack". The length is acceptable, though it may be slightly truncated in some search result displays. The meta description is 30 characters (acceptable): "The app for independent voices". Google typically displays up to 155-160 characters of the meta description in search results. A compelling meta description with a clear call-to-action can significantly improve click-through rates from search results. The canonical url is correctly set to https://substack.com/, preventing duplicate content issues, the page language is declared as en, and a favicon is configured. Open Graph meta tags are configured with 4/4 recommended fields: OG title ("Substack..."), OG description, OG image (social sharing thumbnail), OG type (article). These tags control how the page appears when shared on Facebook, LinkedIn, and other social media platforms that support the Open Graph protocol. A Twitter Card of type summary is configured, which controls how links appear when shared on Twitter/X. The "summary" type displays a large image preview, which typically generates higher engagement rates than the basic card type.

TitleSubstack
H1
Word Count56 words
Images0 total
Internal Links1
External Links1
JS Files151
CSS Files14
Heading StructureH3:1 · H4:1
X-Powered-ByExpress
MinificationJS: 0/151 minified · CSS: 0/14 minified
Sitemap✓ Found
Robots.txt✓ Found
Canonical✓ Set
Languageen
Open Graph✓ Complete
Twitter Card✓ summary
PWA✓ Manifest found
RSS FeedNot detected
AMPNot detected
Carbon / Visit0.04g · Rating A

Google SERP Preview

Substack
https://substack.com
The app for independent voices

META TAGS & SCHEMA.ORG

META TAGS

TitleSubstack
Title Length8 chars Too short
Meta Desc Length30 chars Too short
H1
Languageen
Canonical✓ Set
Meta Robots

SCHEMA.ORG & SOCIAL

Schema Types
OG Typearticle
OG Image✓ Set
Twitter Card✓ summary
Favicon✓ Found

📊 Compare With Your Competitors

See how your website stacks up against substack.com in trust, speed, security, and technology.

Compare Now →