SCAMTRIX · INDEPENDENT INVESTIGATION · EST. MMXXVI · EVIDENCE BEFORE VERDICT ·ScamTrixEvidence before verdict
Verified#US-2026-2754Case file · 11 min read

How to Check If a Website Is Legit: 13 Checks (2026)

Verify any website with 13 free checks — domain age, WHOIS, SSL, blacklists, company registers — the tools our investigators use. Read before you deposit.

Trust score

Unrated

By Ray Okafor

Published August 12, 2026

Last updated August 12, 2026

Here is how to check if a website is legit in about fifteen minutes, using only free tools: look up the domain's age in an RDAP record, inspect its SSL history on crt.sh, scan the address against Google Safe Browsing and VirusTotal, replay the site's past on the Wayback Machine, confirm the company in a government register and against regulator warning lists, then stress-test its reviews, address, team photos, and — above all — the way it asks for your money. Thirteen checks. Each one answers a question a scam operation cannot fake all at once.

The stakes are not abstract. Americans reported more than $12.5 billion in fraud losses to the FTC in 2024 — a 25 percent jump in one year — and investment scams, the fake trading platforms and "automated" crypto funds, led every category at $5.7 billion. The FBI's Internet Crime Complaint Center logged $16.6 billion across 859,532 complaints, nearly 150,000 involving cryptocurrency, with $9.3 billion in crypto-linked losses. Almost every dollar moved through a website somebody decided to trust.

That decision is what this page is for. What follows is the 13-point protocol our investigators run before any review — the full version lives on our methodology page — translated so you can verify any website yourself: the tool, and what a pass and a fail look like.

Why one check is never enough

A padlock icon proves nothing. Neither does slick design, a .com address, or a phone number that rings. Every signal you look for can be faked in isolation: aged domains sell openly on marketplaces, SSL certificates are free and automatic, and five-star reviews arrive by the purchased batch.

What a scam operation cannot fake cheaply is the pattern. A domain registered weeks ago, plus a company no government register has heard of, plus a wall of five-star reviews that landed the same weekend, plus a deposit page that accepts only USDT — that combination is not bad luck. It is the anatomy of the thing.

One signal can lie. Thirteen, taken together, almost never do.

The 13-point website trust check

Every tool below is free; the full run takes about fifteen minutes.

#CheckFree toolA pass looks likeA fail looks like
1Domain agelookup.icann.org (RDAP)Registered years agoWeeks old, claims long history
2WHOIS detailsThe same RDAP recordRegistrant matches the companyAnonymous, disposable registrar
3SSL certificatecrt.shCertificate history fits the storyFirst cert issued days after launch
4DNS and mailMXToolboxStable nameservers, real mailParking nameservers, no MX records
5BlacklistsSafe Browsing, VirusTotalClean on every engineA phishing or malware flag
6Infrastructureurlscan.ioServes its own contentRedirect chains, shared scam templates
7Archive historyWayback MachineConsistent captures over yearsEmpty timeline, or a different past site
8Company registerSEC EDGAR, state SOS, Companies HouseEntity exists, dates alignNo entity, or formed last month
9Regulator listsFCA, SEC, DFPILicensed for what it sellsNamed on a warning list
10ReviewsTrustpilot, Reddit, BBBIrregular, organic, years deepStar bursts, withdrawal complaints
11Physical addressGoogle Maps, Street ViewA real commercial officeMail drop, empty lot, fake address
12Team photosReverse image searchIdentities check outStock faces, stolen portraits
13Payment demandsThe site itselfNormal rails, no pressureCrypto-only, guaranteed returns, urgency

Checks 1–4: the domain's plumbing

Websites can lie in prose; their plumbing is sworn testimony.

1. Domain age — the RDAP lookup

Go to lookup.icann.org, paste the domain, and read the registration date. That one field kills more fake platforms than anything else here, because the lie is structural: the marketing says the firm has served clients for a decade, and the registry says the name was born last quarter. Both cannot be true. A pass means the registration date matches or predates the claimed history; a fail means the domain is younger than the story — especially anything under a year old asking for deposits. One edge case matters: scammers buy aged domains at auction to survive this check, which is why check 7 exists.

2. WHOIS details

Same record, deeper fields. Note the registrar and whatever registrant data survives privacy shielding. Privacy protection by itself proves nothing — plenty of honest businesses use it. But a self-described London investment house registered anonymously last month through a bargain registrar favored by disposable sites is telling you what it is. A pass pairs the record with the story. A fail contradicts it.

3. SSL certificate

Click the padlock, then open crt.sh and search the domain for its issuance history. HTTPS proves only that traffic is encrypted — the certificate authority verified control of the domain, not the honesty of whoever controls it. Most scam sites carry perfectly valid certificates. What crt.sh adds is timing: a pass shows history that fits the story; a fail shows the first certificate issued days after registration, or short-lived certificates reissued in bursts as older infrastructure gets flagged.

4. DNS and mail records

MXToolbox shows the nameservers and mail records in seconds. A real financial firm runs email at its own domain through a known provider. A fail: parking nameservers, an IP resolving to a bargain host far from the claimed headquarters, or no mail records at all — a "global institution" that cannot receive email at its own address.

Checks 5–8: history and reputation

5. Blacklists

Two stops answer "is this site safe" with data instead of instinct: Google's Safe Browsing status page, and VirusTotal, which runs the address through a panel of security engines. Clean across the board is a pass. A single phishing or malware flag is a fail — legitimate brokers do not accumulate those.

6. Infrastructure and redirects

urlscan.io loads the site in a sandbox and records everything: IPs it touches, domains it pulls from, redirect chains, a screenshot of what rendered. A pass serves its own content from stable infrastructure. A fail is a redirect chain through throwaway domains, or a "trading platform" built from the same template as other flagged operations.

7. Archive history

The Wayback Machine at web.archive.org shows what a domain hosted in earlier years. A pass is a timeline consistent with the current brand. A fail comes in two flavors: no captures before this year, or a timeline showing the domain previously hosting something unrelated — a shoe store, a parked page, someone's blog. Your "established investment firm" is wearing a recycled name bought at auction.

8. Company register

Every genuine company exists in a government register: a state Secretary of State database in the US, SEC EDGAR for anyone selling securities, Companies House in the UK. Search the exact legal name from the footer and terms page, not the brand name. A pass finds the entity, a formation date that matches the marketing, officers who match the named team. A fail finds nothing, anywhere — or a shell formed last month wearing a decade of invented heritage.

Checks 9–12: does the company exist off the website?

9. Regulator registers and warning lists

A firm that solicits investments must appear in a regulator's register. Check the FCA's Warning List of unauthorised and clone firms, the SEC's register and EDGAR filings, and the California DFPI's crypto scam tracker, which names schemes built from consumer complaints. Being named on any warning list ends the inquiry. Absence from every register while soliciting deposits is the quieter fail: no license, no oversight, no compensation scheme when the money vanishes. How we weigh these sources is in our methodology.

10. Reviews

Read Trustpilot, Reddit, and the BBB together, and read for shape, not stars. Organic praise arrives irregularly, over years, in mixed voices with specific detail; purchased praise lands in bursts of similar, cheerful grammar, usually after launch or after a wave of complaints. The loudest signal is the withdrawal complaint — profits visible on a dashboard that never reach a bank. When several strangers tell the same story, believe them. The "pay a fee to unlock your withdrawal" demand is not a fee. It is the second theft.

11. Physical address

Paste the headquarters address into Google Maps and drop into Street View. A pass is a real commercial building consistent with the operation being claimed. A fail is a mail drop, a virtual-office tower housing hundreds of shelf companies, a suburban house, or no such address at all.

12. Team photos

Right-click the CEO's headshot and run it through a reverse image search. A pass finds a real person whose history matches the bio. A fail finds the same face fronting a dental practice in another country under another name — or smiling from a stock-photo catalog.

Check 13: the payment and pressure test

The last check needs no tool, only attention to what the site demands of you. The FTC found that people who paid scammers by bank transfer or cryptocurrency lost more in 2024 than victims using all other payment methods combined — which is why fraud operations steer you to those rails. Card payments carry chargeback rights; a USDT transfer carries none. Guaranteed returns, countdown timers, an "account manager" who telephones to urge larger deposits, a withdrawal that requires a "tax" paid first: each one, alone, is enough. No legitimate platform guarantees profit. None. Our field guide to spotting a crypto scam maps these scripts line by line.

Is this site safe? Scoring the results

One fail is a yellow light: keep digging. Two fails in different layers — a young domain plus no register entry, say — means treat the site as hostile. Three or more means walk away and report it. Layers matter more than the count: the signature we document across pig-butchering platforms and fake exchanges is always the same triad: a fresh domain, no verifiable company, crypto-only deposits. Run the thirteen and you never have to wonder how to check if a website is legit again — you have a record, not a hunch. The full weighting is published in our methodology, because a verification method you cannot inspect is just another opinion.

Can a scam pass every check?

Rarely. But yes, at the extremes. Clone firms copy a licensed company's identity down to its registration number, differing only in the domain — verify the register entry yourself and compare the domain character by character instead of clicking the link you were sent. Aged-domain resales let a fraud inherit a ten-year-old domain, which is why the archive history in check 7 matters more than the birthday in check 1. Thirteen passes mean "no evidence of fraud found," not a guarantee; they shift the burden to the payment test, which fraud almost always fails.

Already sent money? Do this in order

Stop all payments — including any "fee" demanded to release your balance. Screenshot everything: dashboards, chats, wallet addresses, emails. File with the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, then work through our first-48-hours protocol before the trail cools. Expect a second approach: "recovery agents" who find victims in comment sections and promise to retrieve funds for an upfront payment. That is a second fraud built on the first, and paying it changes nothing except the total. If the platform is one we have reviewed, tell us what happened; victim reports are how warning lists grow teeth.

Frequently asked questions

How do I check if a website is legit for free?

Every tool above is free: lookup.icann.org for domain age, crt.sh for certificate history, Google Safe Browsing and VirusTotal for blacklists, web.archive.org for history, government registers and regulator warning lists for the company, reverse image search for the team. Fifteen minutes, no budget.

Does the padlock or HTTPS mean a website is safe?

No. The certificate proves the connection is encrypted and that the holder controls the domain — nothing about intent. Most scam sites we examine hold valid certificates. Treat the padlock as the absence of one problem, not the presence of trust.

How do I find out who owns a website?

Run the domain through lookup.icann.org or rdap.org and read the RDAP record: registration date, registrar, and any published registrant data. If privacy shielding hides the owner, check the footer and terms page for a legal entity name, then confirm it in a government company register. An honest business does not make this hard.

The site has hundreds of five-star Trustpilot reviews. Can I trust them?

Read the shape before the stars. Real reputations accumulate unevenly over years; fake ones arrive in bursts of similar phrasing after launch or after bad press. Weight one detailed withdrawal complaint — money visible on a dashboard that never reaches a bank — above a hundred generic five-star ratings.

I already deposited money with a site that failed these checks. What now?

Do not send another dollar, including any "tax" or "fee" to unlock a withdrawal. Document everything, file with the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, and follow our first-48-hours guide. Anyone who offers to recover the funds for an upfront payment is running the recovery scam that follows the first one.

Frequently asked questions

How do I check if a website is legit for free?

Every tool above is free: lookup.icann.org for domain age, crt.sh for certificate history, Google Safe Browsing and VirusTotal for blacklists, web.archive.org for history, government registers and regulator warning lists for the company, reverse image search for the team. Fifteen minutes, no budget.

Does the padlock or HTTPS mean a website is safe?

No. The certificate proves the connection is encrypted and that the holder controls the domain — nothing about intent. Most scam sites we examine hold valid certificates. Treat the padlock as the absence of one problem, not the presence of trust.

How do I find out who owns a website?

Run the domain through lookup.icann.org or rdap.org and read the RDAP record: registration date, registrar, and any published registrant data. If privacy shielding hides the owner, check the footer and terms page for a legal entity name, then confirm it in a government company register. An honest business does not make this hard.

The site has hundreds of five-star Trustpilot reviews. Can I trust them?

Read the shape before the stars. Real reputations accumulate unevenly over years; fake ones arrive in bursts of similar phrasing after launch or after bad press. Weight one detailed withdrawal complaint — money visible on a dashboard that never reaches a bank — above a hundred generic five-star ratings.

I already deposited money with a site that failed these checks. What now?

Do not send another dollar, including any "tax" or "fee" to unlock a withdrawal. Document everything, file with the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, and follow our first-48-hours guide. Anyone who offers to recover the funds for an upfront payment is running the recovery scam that follows the first one.

About the investigator

Ray Okafor

Cyber analyst · infrastructure & data

Ray Okafor maps scam infrastructure for a living: DNS graphs, certificate transparency logs, hosting patterns, wallet clusters. Before ScamTrix he spent eight years in threat intelligence, tracking the operators most publications never name.

All investigations by Ray