Last updated: · By

Is This Website Legit? Evidence Checker

To check if a website is legit, look at evidence a scammer can’t easily fake: how old the domain is, when its first HTTPS certificate appeared, whether the Wayback Machine saw it before, how its DNS and email are set up, and whether the address imitates a brand. Paste a link below and this free checker gathers those facts from public registries, Certificate Transparency logs, Google Public DNS and the Internet Archive, then marks each one red, caution or neutral with the raw data and what it can and can’t tell you. It never says “safe”: in Interisle’s 2025 phishing study, 33% of the .com and .net domains used for phishing were compromised legitimate domains Interisle, Phishing Landscape 2025, and a padlock only means the connection is encrypted FBI IC3 public service announcement, 10 Jun 2019. Use the results with independent reviews and a safe way to pay.

What leaves your browser: only the site’s host name (for example shop.example.com), never the page path or anything after ?. It goes straight from your browser to rdap.org and the registry’s RDAP server, crt.sh, Google Public DNS (dns.google), RIPEstat and the Internet Archive. If crt.sh refuses the direct request, that one query is retried through a proxy run by Max Intel that stores nothing against you. The buttons under “Check further” send the domain to other services only when you click them. Nothing is stored.

    What does each signal mean, at a glance?

    Each check answers one narrow factual question. None of them can say a site is honest; together they show whether the site has a track record and whether its address is trying to look like something it is not.

    SignalWhat the checker readsWhen it raises a flagLimits
    Domain age (RDAP)Registration date, registrar, status codes, registrar abuse contactRed under 32 days; caution under 90 days; hold or deletion statusGenuine new businesses have new domains. Some country-code registries publish no RDAP or no creation date. Old domains get compromised or change owner.
    First certificate (crt.sh)Earliest certificate logged for the exact name, current issuerCaution if the first certificate is under 32 days old, if none is valid now, or if history predates the current registrationCertificates are free and automatic, so they prove control of a name, not honesty. crt.sh is often overloaded; wildcard certificates are not listed by an exact search.
    Wayback MachineLatest capture (quick); first capture (Archive Helper)Caution if the first capture is under 90 days old or predates the current registrationA quick “not found” is not conclusive. Old captures can belong to a previous owner.
    DNS and emailA/AAAA, MX, null MX, SPF, DMARCCaution if the name does not exist or has no web addressAnyone can set up email records in minutes, so their presence proves nothing; absence is common for small genuine sites.
    Hosting networkAS number and holder for the first IP (RIPEstat)Never flaggedBig CDNs front honest and dishonest sites alike. The host is not the owner.
    Look-alike hints (offline)Punycode/IDN decoding, mixed alphabets, brand strings, one-letter typos, hyphens, high-phishing TLDs, “@” tricks, shared platformsRed for mixed-alphabet look-alikes, brand names in a subdomain, “@” tricksString heuristics on a short brand list. Invented shop names pass every hint.

    The 32-day line comes from Palo Alto Networks Unit 42, which defines newly registered domains as “any domain that has been registered or had a change in ownership within the last 32 days” Palo Alto Networks Unit 42, “Newly Registered Domains: Malicious Abuse by Bad Actors”, 20 Aug 2019 — vendor research. The 90-day and one-year lines are this tool’s own thresholds, shown as caution and neutral, not as published risk levels.

    How do you check if a website is legit?

    1. Read the address, not the page. The registered domain is the part just before the ending: in paypal.com.secure-login.example it is secure-login.example, and everything to its left can be set to any text by whoever owns it. Interisle found an exact brand name in 8.9% of phishing domains (137,860 of 1,542,922, May 2024–April 2025) and notes that phishers also put brand names “in subdomains and in URL paths” Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026). The checker splits the address for you and flags brand names in the wrong place.
    2. Check how long the domain has existed. RDAP is the structured successor to WHOIS; rdap.org redirects each query to the registry that is authoritative for the domain About RDAP.org (read 10 Oct 2026). A domain registered last week selling discounted luxury goods deserves far more suspicion than one with years of history.
    3. Compare the dates. The first certificate in Certificate Transparency logs and the first Wayback Machine capture usually come shortly after a site goes live. If they are much older than the current registration, the name probably lapsed and was registered again by someone new, so old reviews may describe a different business.
    4. Look at the setup, without over-reading it. SPF (RFC 7208) lists servers allowed to send a domain’s email RFC 7208 (SPF); DMARC (RFC 7489) tells receivers what to do with mail that fails, with policies none, quarantine or reject RFC 7489 (DMARC). These protect the domain owner against spoofing. Their absence is common on small genuine sites, and a scammer can add them in minutes.
    5. Check outside reputation. Use the pivots under the results: Google Safe Browsing site status, VirusTotal, earlier urlscan.io scans, ScamAdviser and the Wayback calendar. Then follow the FTC’s advice: “Search online for the product or company name, plus the words ‘complaint’ or ‘scam’” FTC Consumer Advice: Online Shopping (updated 20 Nov 2025, read 10 Oct 2026).

    How to check if a website is a scam before you buy

    The warning signs that matter most for shopping sites are the ones a scam can’t easily fake: a short history and an unsafe way to pay. The FTC’s online shopping advice, updated 20 November 2025, says FTC Consumer Advice: Online Shopping (updated 20 Nov 2025, read 10 Oct 2026):

    • “Before you buy something online, shop around and check out sellers and products,” and “don’t rely on star ratings alone because some reviews and ratings are fake or misleading.”
    • “Paying by credit card best protects you and your money in case of a scam, or if something else goes wrong.” Never buy from sellers who insist on gift cards, wire transfers, payment apps or cryptocurrency.
    • Check the return policy: “The site must say whether you’re able to return the item for a full refund.”

    Put those next to the evidence above. A shop whose domain is a few weeks old, whose first certificate is from the same week, which the Wayback Machine has never seen, and which asks for a bank transfer, has every hallmark of a site built to disappear. A shop with years of consistent archive history that takes credit cards is not guaranteed to be honest, but you have more protection if it is not.

    1. Long-press (phone) or right-click (computer) the link and choose Copy link address. Don’t open it.
    2. Paste it into the checker above. Only the host name is sent to the data sources; the path and anything after ?, which can contain personal tokens, stay in your browser. The address bar of this page keeps only the host name, so a shared deep link never carries the path either.
    3. Look first at the look-alike hints: brand names in the subdomain, an @ in the address (everything before it is a user name, not the site), or an internationalized name. Internationalized names start with xn-- in their ASCII form, the prefix that “appears at the beginning of every A-label” RFC 5890 (IDNA definitions); the checker decodes them so you can see what the name really says. Interisle counted only 2,655 internationalized names among phishing domains, 0.17% of the total, so they are rare but deliberate Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026).
    4. Use the pivots if you want a reputation check. VirusTotal warns that indicators searched through its web interface are added to its dataset and visible to its community, so don’t search links that contain personal information VirusTotal docs: Searching (read 10 Oct 2026). The urlscan.io link searches existing public scans by page.domain rather than starting a new scan urlscan.io Search API reference (read 10 Oct 2026).

    For links inside emails and texts, the sender matters as much as the link. The reverse email lookup and reverse phone lookup help with those.

    Why doesn’t this checker give a safety score?

    Because every measurable signal can be passed by a determined scammer and failed by an honest site, and a single number hides which is which.

    So the checker shows red flags, cautions and neutral facts with the raw data behind each one, and leaves the judgement to you.

    What should you do if you already paid or entered your details?

    Speed matters most for getting money back. The FTC’s guidance FTC Consumer Advice: What To Do if You Were Scammed (read 10 Oct 2026):

    How you paid or what you gaveWhat to do now
    Credit card“Report it to the credit card issuer immediately” and ask them to refund your money.
    Debit card“Report it to your bank or credit union immediately” and ask for a refund.
    Bank transfer, Zelle or wireTell your bank, or the wire service (Western Union, MoneyGram), immediately that a scammer tricked you; ask them to reverse the payment.
    Gift card“Contact the gift card issuer immediately. Use the number on the back of the card.”
    Payment app“Report it to the payment app immediately” and ask them to reverse the payment.
    Cryptocurrency“Contact the cryptocurrency exchange or ATM operator immediately” and ask them to reverse the transaction.
    Username and password“Create a new, strong password for the account that was compromised” and turn on two-factor authentication; change it anywhere you reused it.
    Social Security number (US)If it was used, report it at IdentityTheft.gov and follow the recovery plan.

    Where to report a scam website

    Beware of “recovery” services that contact you after a scam promising to get your money back for a fee; the IC3 warning above applies to them too. If the scam started with a romance or investment contact, our pig-butchering scam guide covers the follow-up.

    How was this tool tested?

    • Real responses captured on 10 October 2026 were replayed in headless Chromium: RDAP, Google Public DNS (A, AAAA, MX, TXT, _dmarc), RIPEstat and crt.sh answers for gnu.org (registered 24 November 1995, 99 certificates since 2010) and for a domain registered on 7 October 2026 whose first certificate was issued the same day. A third real domain, re-registered on 7 October 2026 but with certificates from 2020 to 2022, exercised the “history predates the current registration” flags.
    • crt.sh returned HTTP 502 or timed out for exact-name queries on python.org, eff.org and craigslist.org throughout testing (gnu.org succeeded on a retry), so the “not checked” path (direct request, then the proxy, then an honest message) was replayed with python.org’s real RDAP, DNS and RIPEstat answers. Wayback quick mode and Archive Helper mode were replayed with the documented availability and CDX response shapes; the real archive.org was not contacted from the test machine.
    • Offline hints: punycode decoding (RFC 3492) of mixed-alphabet look-alikes, brand names in subdomain, registered name and path, one-letter typos, an “@” trick, shared platforms, high-phishing endings, and email, phone and IP inputs redirected to the right tools. Hostile strings were rendered as text, javascript: input was refused, and there is no horizontal scrolling at 375 px.

    Sources

    Data sources used live by the checker: rdap.org and registry RDAP servers, crt.sh, Google Public DNS, RIPEstat and the Internet Archive. ScamAdviser’s trust score, linked from the results, is a commercial product’s automated rating.

    Frequently asked questions

    How do I check if a website is legit?

    Look at evidence instead of trusting a badge. Paste the address into this checker and read what it finds: when the domain was registered, when its first HTTPS certificate was logged, whether the Wayback Machine archived it before, how its DNS and email are set up, and whether the address imitates a brand. Then search the site name plus the words scam or complaint, as the FTC advises, and pay by credit card if you go ahead. No single check proves a site is genuine.

    How can I tell if a website is a scam before I buy?

    Be most careful when several warning signs line up: a domain registered in the last few weeks, a first certificate from the same week, no archive history, a brand name in the wrong part of the address, prices far below everyone else, and a request to pay by bank transfer, gift card, payment app or cryptocurrency. The FTC says never to buy from sellers who insist on those payment methods and that a credit card gives you the most protection if something goes wrong.

    How do I check if a link is safe without clicking it?

    Copy the link (long-press or right-click, then Copy link address) and paste it here instead of opening it. This page reads the address and sends only the host name, never the path or anything after a question mark, to public registration, certificate, DNS and archive services. The Google Safe Browsing, VirusTotal and urlscan.io buttons open those services only when you click them; VirusTotal says anything searched there is added to its dataset and visible to its community.

    Does HTTPS or a padlock mean a website is safe?

    No. HTTPS only means the connection between you and the site is encrypted. Certificates are issued automatically to whoever controls the domain name, including scammers. The FBI warned in 2019: do not trust a website just because it has a lock icon or https in the browser address bar. A site without HTTPS is a bad place to enter a password or card number, but a padlock is not a sign of honesty.

    Why is a newly registered domain a warning sign, and can old websites be scams too?

    Scam and phishing domains are usually used soon after they are registered. Palo Alto Networks Unit 42, a security vendor, reported in 2019 that more than 70 percent of domains registered in the previous 32 days were malicious, suspicious or not safe for work. Age is not a guarantee in the other direction: in Interisle’s 2025 phishing study, a third of the .com and .net domains used for phishing were compromised legitimate domains, and expired names are often re-registered by new owners.

    Is this website scam checker free, and what data leaves my browser?

    It is free and needs no account. The checks run in your browser and send only the domain name to rdap.org and the registry it redirects to, crt.sh, Google Public DNS, RIPEstat and the Internet Archive. If crt.sh blocks the direct request, that one query is retried through a proxy run by Max Intel, which stores nothing against you. Nothing is saved on our side, and the checks never send the path or query of the link you pasted.

    Can I check a phone number or an email address for scams here?

    This page checks websites. If you type a phone number or an email address it points you to the Max Intel reverse phone lookup or reverse email lookup instead, which open with your entry filled in. For links inside a suspicious email or text message, copy the link itself and check it here.

    What should I do if I already paid a scam website or entered my password?

    Act quickly. Contact your card issuer, bank, payment app or crypto exchange, say the payment was a scam and ask them to reverse it. If you typed a password, change it on the real site and on any other site where you reused it, and turn on two-step verification. In the US, report to the FTC and to the FBI at ic3.gov; in England, Wales and Northern Ireland, report to Report Fraud, which replaced Action Fraud; in Scotland, call Police Scotland on 101.