- Home
- Built-in Tools
- Website Legit Checker
Last updated: · By Ned Walsch
Is This Website Legit? Evidence Checker
To check if a website is legit, look at evidence a scammer can’t easily fake: how old the domain is, when its first HTTPS certificate appeared, whether the Wayback Machine saw it before, how its DNS and email are set up, and whether the address imitates a brand. Paste a link below and this free checker gathers those facts from public registries, Certificate Transparency logs, Google Public DNS and the Internet Archive, then marks each one red, caution or neutral with the raw data and what it can and can’t tell you. It never says “safe”: in Interisle’s 2025 phishing study, 33% of the .com and .net domains used for phishing were compromised legitimate domains Interisle, Phishing Landscape 2025, and a padlock only means the connection is encrypted FBI IC3 public service announcement, 10 Jun 2019. Use the results with independent reviews and a safe way to pay.
shop.example.com), never the page path or anything after ?. It goes straight from your browser to rdap.org and the registry’s RDAP server, crt.sh, Google Public DNS (dns.google), RIPEstat and the Internet Archive. If crt.sh refuses the direct request, that one query is retried through a proxy run by Max Intel that stores nothing against you. The buttons under “Check further” send the domain to other services only when you click them. Nothing is stored.On this page
- The checker
- What does each signal mean, at a glance?
- How do you check if a website is legit?
- How to check if a website is a scam before you buy
- Is this link safe? Checking a link without clicking it
- Why doesn’t this checker give a safety score?
- What to do if you already paid or entered your details
- How was this tool tested?
- Sources
- Frequently asked questions
What does each signal mean, at a glance?
Each check answers one narrow factual question. None of them can say a site is honest; together they show whether the site has a track record and whether its address is trying to look like something it is not.
| Signal | What the checker reads | When it raises a flag | Limits |
|---|---|---|---|
| Domain age (RDAP) | Registration date, registrar, status codes, registrar abuse contact | Red under 32 days; caution under 90 days; hold or deletion status | Genuine new businesses have new domains. Some country-code registries publish no RDAP or no creation date. Old domains get compromised or change owner. |
| First certificate (crt.sh) | Earliest certificate logged for the exact name, current issuer | Caution if the first certificate is under 32 days old, if none is valid now, or if history predates the current registration | Certificates are free and automatic, so they prove control of a name, not honesty. crt.sh is often overloaded; wildcard certificates are not listed by an exact search. |
| Wayback Machine | Latest capture (quick); first capture (Archive Helper) | Caution if the first capture is under 90 days old or predates the current registration | A quick “not found” is not conclusive. Old captures can belong to a previous owner. |
| DNS and email | A/AAAA, MX, null MX, SPF, DMARC | Caution if the name does not exist or has no web address | Anyone can set up email records in minutes, so their presence proves nothing; absence is common for small genuine sites. |
| Hosting network | AS number and holder for the first IP (RIPEstat) | Never flagged | Big CDNs front honest and dishonest sites alike. The host is not the owner. |
| Look-alike hints (offline) | Punycode/IDN decoding, mixed alphabets, brand strings, one-letter typos, hyphens, high-phishing TLDs, “@” tricks, shared platforms | Red for mixed-alphabet look-alikes, brand names in a subdomain, “@” tricks | String heuristics on a short brand list. Invented shop names pass every hint. |
The 32-day line comes from Palo Alto Networks Unit 42, which defines newly registered domains as “any domain that has been registered or had a change in ownership within the last 32 days” Palo Alto Networks Unit 42, “Newly Registered Domains: Malicious Abuse by Bad Actors”, 20 Aug 2019 — vendor research. The 90-day and one-year lines are this tool’s own thresholds, shown as caution and neutral, not as published risk levels.
How do you check if a website is legit?
- Read the address, not the page. The registered domain is the part just before the ending: in
paypal.com.secure-login.exampleit issecure-login.example, and everything to its left can be set to any text by whoever owns it. Interisle found an exact brand name in 8.9% of phishing domains (137,860 of 1,542,922, May 2024–April 2025) and notes that phishers also put brand names “in subdomains and in URL paths” Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026). The checker splits the address for you and flags brand names in the wrong place. - Check how long the domain has existed. RDAP is the structured successor to WHOIS; rdap.org redirects each query to the registry that is authoritative for the domain About RDAP.org (read 10 Oct 2026). A domain registered last week selling discounted luxury goods deserves far more suspicion than one with years of history.
- Compare the dates. The first certificate in Certificate Transparency logs and the first Wayback Machine capture usually come shortly after a site goes live. If they are much older than the current registration, the name probably lapsed and was registered again by someone new, so old reviews may describe a different business.
- Look at the setup, without over-reading it. SPF (RFC 7208) lists servers allowed to send a domain’s email RFC 7208 (SPF); DMARC (RFC 7489) tells receivers what to do with mail that fails, with policies none, quarantine or reject RFC 7489 (DMARC). These protect the domain owner against spoofing. Their absence is common on small genuine sites, and a scammer can add them in minutes.
- Check outside reputation. Use the pivots under the results: Google Safe Browsing site status, VirusTotal, earlier urlscan.io scans, ScamAdviser and the Wayback calendar. Then follow the FTC’s advice: “Search online for the product or company name, plus the words ‘complaint’ or ‘scam’” FTC Consumer Advice: Online Shopping (updated 20 Nov 2025, read 10 Oct 2026).
How to check if a website is a scam before you buy
The warning signs that matter most for shopping sites are the ones a scam can’t easily fake: a short history and an unsafe way to pay. The FTC’s online shopping advice, updated 20 November 2025, says FTC Consumer Advice: Online Shopping (updated 20 Nov 2025, read 10 Oct 2026):
- “Before you buy something online, shop around and check out sellers and products,” and “don’t rely on star ratings alone because some reviews and ratings are fake or misleading.”
- “Paying by credit card best protects you and your money in case of a scam, or if something else goes wrong.” Never buy from sellers who insist on gift cards, wire transfers, payment apps or cryptocurrency.
- Check the return policy: “The site must say whether you’re able to return the item for a full refund.”
Put those next to the evidence above. A shop whose domain is a few weeks old, whose first certificate is from the same week, which the Wayback Machine has never seen, and which asks for a bank transfer, has every hallmark of a site built to disappear. A shop with years of consistent archive history that takes credit cards is not guaranteed to be honest, but you have more protection if it is not.
Is this link safe? How to check a link without clicking it
- Long-press (phone) or right-click (computer) the link and choose Copy link address. Don’t open it.
- Paste it into the checker above. Only the host name is sent to the data sources; the path and anything after
?, which can contain personal tokens, stay in your browser. The address bar of this page keeps only the host name, so a shared deep link never carries the path either. - Look first at the look-alike hints: brand names in the subdomain, an
@in the address (everything before it is a user name, not the site), or an internationalized name. Internationalized names start withxn--in their ASCII form, the prefix that “appears at the beginning of every A-label” RFC 5890 (IDNA definitions); the checker decodes them so you can see what the name really says. Interisle counted only 2,655 internationalized names among phishing domains, 0.17% of the total, so they are rare but deliberate Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026). - Use the pivots if you want a reputation check. VirusTotal warns that indicators searched through its web interface are added to its dataset and visible to its community, so don’t search links that contain personal information VirusTotal docs: Searching (read 10 Oct 2026). The urlscan.io link searches existing public scans by
page.domainrather than starting a new scan urlscan.io Search API reference (read 10 Oct 2026).
For links inside emails and texts, the sender matters as much as the link. The reverse email lookup and reverse phone lookup help with those.
Why doesn’t this checker give a safety score?
Because every measurable signal can be passed by a determined scammer and failed by an honest site, and a single number hides which is which.
- Old domains get compromised. Interisle’s 2025 study found 77% of the domain names used for phishing were maliciously registered by criminals; it classes the others as compromised, meaning legitimate domains that attackers broke into. In .com and .net the split was 67% maliciously registered and 33% compromised Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026). A compromised domain passes every age check.
- Free platforms lend their reputation. 13% of reported phishing attacks in the same study were hosted at subdomain providers such as site builders and free hosting Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026). A site at
something.example-platform.cominherits the platform’s old domain, valid certificate and long archive history. The checker labels these and explains that the evidence describes the platform. - Padlocks prove encryption, not honesty. The FBI: “Do not trust a website just because it has a lock icon or ‘https’ in the browser address bar” FBI IC3 public service announcement, 10 Jun 2019.
- New is not guilty. Unit 42’s 2019 figure that more than 70% of newly registered domains were “malicious” or “suspicious” or “not safe for work” is vendor research from a company that sells URL filtering, measured with its own classifier, and the remaining domains include every genuine new business Palo Alto Networks Unit 42, “Newly Registered Domains: Malicious Abuse by Bad Actors”, 20 Aug 2019 — vendor research.
So the checker shows red flags, cautions and neutral facts with the raw data behind each one, and leaves the judgement to you.
What should you do if you already paid or entered your details?
Speed matters most for getting money back. The FTC’s guidance FTC Consumer Advice: What To Do if You Were Scammed (read 10 Oct 2026):
| How you paid or what you gave | What to do now |
|---|---|
| Credit card | “Report it to the credit card issuer immediately” and ask them to refund your money. |
| Debit card | “Report it to your bank or credit union immediately” and ask for a refund. |
| Bank transfer, Zelle or wire | Tell your bank, or the wire service (Western Union, MoneyGram), immediately that a scammer tricked you; ask them to reverse the payment. |
| Gift card | “Contact the gift card issuer immediately. Use the number on the back of the card.” |
| Payment app | “Report it to the payment app immediately” and ask them to reverse the payment. |
| Cryptocurrency | “Contact the cryptocurrency exchange or ATM operator immediately” and ask them to reverse the transaction. |
| Username and password | “Create a new, strong password for the account that was compromised” and turn on two-factor authentication; change it anywhere you reused it. |
| Social Security number (US) | If it was used, report it at IdentityTheft.gov and follow the recovery plan. |
Where to report a scam website
- United States — FTC: the FTC asks people to report scammers at ReportFraud.ftc.gov FTC Consumer Advice: What To Do if You Were Scammed (read 10 Oct 2026). When we checked on 10 October 2026, that site displayed a notice that, due to the government shutdown, the FTC was unable to offer the service and would resume when the government is funded ReportFraud.ftc.gov (checked 10 Oct 2026); the FTC’s consumer advice pages were still available.
- United States — FBI IC3: the Internet Crime Complaint Center “is the central hub for reporting cyber-enabled crime” and asks you to file “even if you are unsure of whether your complaint qualifies”. It warns that scammers impersonate it: “The IC3 will never directly contact you for information or money,” and it does not work with law firms or crypto services to recover funds FBI Internet Crime Complaint Center, ic3.gov (read 10 Oct 2026).
- England, Wales and Northern Ireland — Report Fraud: since 4 December 2025, Report Fraud from the City of London Police “replaces Action Fraud as the national platform for reporting cyber crime and fraud”, online at reportfraud.police.uk or on 0300 123 2040 GOV.UK: Report Fraud, new service from City of London Police, 4 Dec 2025. People in Scotland are asked to report via 101 Report Fraud, reportfraud.police.uk (read 10 Oct 2026).
- UK — NCSC: report a suspicious website to the National Cyber Security Centre, which says it will investigate and may share details with law enforcement partners NCSC: Report a scam website (read 10 Oct 2026).
- The registrar and host: the results show the registrar’s abuse contact from RDAP and the hosting network, which is who can suspend the domain or the server.
Beware of “recovery” services that contact you after a scam promising to get your money back for a fee; the IC3 warning above applies to them too. If the scam started with a romance or investment contact, our pig-butchering scam guide covers the follow-up.
How was this tool tested?
- Real responses captured on 10 October 2026 were replayed in headless Chromium: RDAP, Google Public DNS (A, AAAA, MX, TXT,
_dmarc), RIPEstat and crt.sh answers for gnu.org (registered 24 November 1995, 99 certificates since 2010) and for a domain registered on 7 October 2026 whose first certificate was issued the same day. A third real domain, re-registered on 7 October 2026 but with certificates from 2020 to 2022, exercised the “history predates the current registration” flags. - crt.sh returned HTTP 502 or timed out for exact-name queries on python.org, eff.org and craigslist.org throughout testing (gnu.org succeeded on a retry), so the “not checked” path (direct request, then the proxy, then an honest message) was replayed with python.org’s real RDAP, DNS and RIPEstat answers. Wayback quick mode and Archive Helper mode were replayed with the documented availability and CDX response shapes; the real archive.org was not contacted from the test machine.
- Offline hints: punycode decoding (RFC 3492) of mixed-alphabet look-alikes, brand names in subdomain, registered name and path, one-letter typos, an “@” trick, shared platforms, high-phishing endings, and email, phone and IP inputs redirected to the right tools. Hostile strings were rendered as text,
javascript:input was refused, and there is no horizontal scrolling at 375 px.
Sources
- Interisle Consulting Group, Phishing Landscape 2025, 9 Sep 2025 (full report PDF read 10 Oct 2026)
- Palo Alto Networks Unit 42, “Newly Registered Domains: Malicious Abuse by Bad Actors”, 20 Aug 2019 — vendor research
- FBI IC3 public service announcement, 10 Jun 2019
- FTC Consumer Advice: Online Shopping (updated 20 Nov 2025, read 10 Oct 2026)
- FTC Consumer Advice: What To Do if You Were Scammed (read 10 Oct 2026)
- ReportFraud.ftc.gov (checked 10 Oct 2026)
- FBI Internet Crime Complaint Center, ic3.gov (read 10 Oct 2026)
- GOV.UK: Report Fraud, new service from City of London Police, 4 Dec 2025
- Report Fraud, reportfraud.police.uk (read 10 Oct 2026)
- NCSC: Report a scam website (read 10 Oct 2026)
- ICANN: EPP Status Codes, What Do They Mean
- RFC 7208 (SPF)
- RFC 7489 (DMARC)
- RFC 5890 (IDNA definitions)
- About RDAP.org (read 10 Oct 2026)
- Internet Archive: Wayback CDX Server API README
- crt.sh advanced search form (match and deduplicate options, read 10 Oct 2026)
- VirusTotal docs: Searching (read 10 Oct 2026)
- urlscan.io Search API reference (read 10 Oct 2026)
Data sources used live by the checker: rdap.org and registry RDAP servers, crt.sh, Google Public DNS, RIPEstat and the Internet Archive. ScamAdviser’s trust score, linked from the results, is a commercial product’s automated rating.
Frequently asked questions
How do I check if a website is legit?
Look at evidence instead of trusting a badge. Paste the address into this checker and read what it finds: when the domain was registered, when its first HTTPS certificate was logged, whether the Wayback Machine archived it before, how its DNS and email are set up, and whether the address imitates a brand. Then search the site name plus the words scam or complaint, as the FTC advises, and pay by credit card if you go ahead. No single check proves a site is genuine.
How can I tell if a website is a scam before I buy?
Be most careful when several warning signs line up: a domain registered in the last few weeks, a first certificate from the same week, no archive history, a brand name in the wrong part of the address, prices far below everyone else, and a request to pay by bank transfer, gift card, payment app or cryptocurrency. The FTC says never to buy from sellers who insist on those payment methods and that a credit card gives you the most protection if something goes wrong.
How do I check if a link is safe without clicking it?
Copy the link (long-press or right-click, then Copy link address) and paste it here instead of opening it. This page reads the address and sends only the host name, never the path or anything after a question mark, to public registration, certificate, DNS and archive services. The Google Safe Browsing, VirusTotal and urlscan.io buttons open those services only when you click them; VirusTotal says anything searched there is added to its dataset and visible to its community.
Does HTTPS or a padlock mean a website is safe?
No. HTTPS only means the connection between you and the site is encrypted. Certificates are issued automatically to whoever controls the domain name, including scammers. The FBI warned in 2019: do not trust a website just because it has a lock icon or https in the browser address bar. A site without HTTPS is a bad place to enter a password or card number, but a padlock is not a sign of honesty.
Why is a newly registered domain a warning sign, and can old websites be scams too?
Scam and phishing domains are usually used soon after they are registered. Palo Alto Networks Unit 42, a security vendor, reported in 2019 that more than 70 percent of domains registered in the previous 32 days were malicious, suspicious or not safe for work. Age is not a guarantee in the other direction: in Interisle’s 2025 phishing study, a third of the .com and .net domains used for phishing were compromised legitimate domains, and expired names are often re-registered by new owners.
Is this website scam checker free, and what data leaves my browser?
It is free and needs no account. The checks run in your browser and send only the domain name to rdap.org and the registry it redirects to, crt.sh, Google Public DNS, RIPEstat and the Internet Archive. If crt.sh blocks the direct request, that one query is retried through a proxy run by Max Intel, which stores nothing against you. Nothing is saved on our side, and the checks never send the path or query of the link you pasted.
Can I check a phone number or an email address for scams here?
This page checks websites. If you type a phone number or an email address it points you to the Max Intel reverse phone lookup or reverse email lookup instead, which open with your entry filled in. For links inside a suspicious email or text message, copy the link itself and check it here.
What should I do if I already paid a scam website or entered my password?
Act quickly. Contact your card issuer, bank, payment app or crypto exchange, say the payment was a scam and ask them to reverse it. If you typed a password, change it on the real site and on any other site where you reused it, and turn on two-step verification. In the US, report to the FTC and to the FBI at ic3.gov; in England, Wales and Northern Ireland, report to Report Fraud, which replaced Action Fraud; in Scotland, call Police Scotland on 101.