How to Check If a Website Is Legit: 13 Checks (2026)
Verify any website with 13 free checks — domain age, WHOIS, SSL, blacklists, company registers — the tools our investigators use. Read before you deposit.
Unrated
Here is how to check if a website is legit in about fifteen minutes, using only free tools: look up the domain's age in an RDAP record, inspect its SSL history on crt.sh, scan the address against Google Safe Browsing and VirusTotal, replay the site's past on the Wayback Machine, confirm the company in a government register and against regulator warning lists, then stress-test its reviews, address, team photos, and — above all — the way it asks for your money. Thirteen checks. Each one answers a question a scam operation cannot fake all at once.
The stakes are not abstract. Americans reported more than $12.5 billion in fraud losses to the FTC in 2024 — a 25 percent jump in one year — and investment scams, the fake trading platforms and "automated" crypto funds, led every category at $5.7 billion. The FBI's Internet Crime Complaint Center logged $16.6 billion across 859,532 complaints, nearly 150,000 involving cryptocurrency, with $9.3 billion in crypto-linked losses. Almost every dollar moved through a website somebody decided to trust.
That decision is what this page is for. What follows is the 13-point protocol our investigators run before any review — the full version lives on our methodology page — translated so you can verify any website yourself: the tool, and what a pass and a fail look like.
Why one check is never enough
A padlock icon proves nothing. Neither does slick design, a .com address, or a phone number that rings. Every signal you look for can be faked in isolation: aged domains sell openly on marketplaces, SSL certificates are free and automatic, and five-star reviews arrive by the purchased batch.
What a scam operation cannot fake cheaply is the pattern. A domain registered weeks ago, plus a company no government register has heard of, plus a wall of five-star reviews that landed the same weekend, plus a deposit page that accepts only USDT — that combination is not bad luck. It is the anatomy of the thing.
One signal can lie. Thirteen, taken together, almost never do.
The 13-point website trust check
Every tool below is free; the full run takes about fifteen minutes.
| # | Check | Free tool | A pass looks like | A fail looks like |
|---|---|---|---|---|
| 1 | Domain age | lookup.icann.org (RDAP) | Registered years ago | Weeks old, claims long history |
| 2 | WHOIS details | The same RDAP record | Registrant matches the company | Anonymous, disposable registrar |
| 3 | SSL certificate | crt.sh | Certificate history fits the story | First cert issued days after launch |
| 4 | DNS and mail | MXToolbox | Stable nameservers, real mail | Parking nameservers, no MX records |
| 5 | Blacklists | Safe Browsing, VirusTotal | Clean on every engine | A phishing or malware flag |
| 6 | Infrastructure | urlscan.io | Serves its own content | Redirect chains, shared scam templates |
| 7 | Archive history | Wayback Machine | Consistent captures over years | Empty timeline, or a different past site |
| 8 | Company register | SEC EDGAR, state SOS, Companies House | Entity exists, dates align | No entity, or formed last month |
| 9 | Regulator lists | FCA, SEC, DFPI | Licensed for what it sells | Named on a warning list |
| 10 | Reviews | Trustpilot, Reddit, BBB | Irregular, organic, years deep | Star bursts, withdrawal complaints |
| 11 | Physical address | Google Maps, Street View | A real commercial office | Mail drop, empty lot, fake address |
| 12 | Team photos | Reverse image search | Identities check out | Stock faces, stolen portraits |
| 13 | Payment demands | The site itself | Normal rails, no pressure | Crypto-only, guaranteed returns, urgency |
Checks 1–4: the domain's plumbing
Websites can lie in prose; their plumbing is sworn testimony.
1. Domain age — the RDAP lookup
Go to lookup.icann.org, paste the domain, and read the registration date. That one field kills more fake platforms than anything else here, because the lie is structural: the marketing says the firm has served clients for a decade, and the registry says the name was born last quarter. Both cannot be true. A pass means the registration date matches or predates the claimed history; a fail means the domain is younger than the story — especially anything under a year old asking for deposits. One edge case matters: scammers buy aged domains at auction to survive this check, which is why check 7 exists.
2. WHOIS details
Same record, deeper fields. Note the registrar and whatever registrant data survives privacy shielding. Privacy protection by itself proves nothing — plenty of honest businesses use it. But a self-described London investment house registered anonymously last month through a bargain registrar favored by disposable sites is telling you what it is. A pass pairs the record with the story. A fail contradicts it.
3. SSL certificate
Click the padlock, then open crt.sh and search the domain for its issuance history. HTTPS proves only that traffic is encrypted — the certificate authority verified control of the domain, not the honesty of whoever controls it. Most scam sites carry perfectly valid certificates. What crt.sh adds is timing: a pass shows history that fits the story; a fail shows the first certificate issued days after registration, or short-lived certificates reissued in bursts as older infrastructure gets flagged.
4. DNS and mail records
MXToolbox shows the nameservers and mail records in seconds. A real financial firm runs email at its own domain through a known provider. A fail: parking nameservers, an IP resolving to a bargain host far from the claimed headquarters, or no mail records at all — a "global institution" that cannot receive email at its own address.
Checks 5–8: history and reputation
5. Blacklists
Two stops answer "is this site safe" with data instead of instinct: Google's Safe Browsing status page, and VirusTotal, which runs the address through a panel of security engines. Clean across the board is a pass. A single phishing or malware flag is a fail — legitimate brokers do not accumulate those.
6. Infrastructure and redirects
urlscan.io loads the site in a sandbox and records everything: IPs it touches, domains it pulls from, redirect chains, a screenshot of what rendered. A pass serves its own content from stable infrastructure. A fail is a redirect chain through throwaway domains, or a "trading platform" built from the same template as other flagged operations.
7. Archive history
The Wayback Machine at web.archive.org shows what a domain hosted in earlier years. A pass is a timeline consistent with the current brand. A fail comes in two flavors: no captures before this year, or a timeline showing the domain previously hosting something unrelated — a shoe store, a parked page, someone's blog. Your "established investment firm" is wearing a recycled name bought at auction.
8. Company register
Every genuine company exists in a government register: a state Secretary of State database in the US, SEC EDGAR for anyone selling securities, Companies House in the UK. Search the exact legal name from the footer and terms page, not the brand name. A pass finds the entity, a formation date that matches the marketing, officers who match the named team. A fail finds nothing, anywhere — or a shell formed last month wearing a decade of invented heritage.
Checks 9–12: does the company exist off the website?
9. Regulator registers and warning lists
A firm that solicits investments must appear in a regulator's register. Check the FCA's Warning List of unauthorised and clone firms, the SEC's register and EDGAR filings, and the California DFPI's crypto scam tracker, which names schemes built from consumer complaints. Being named on any warning list ends the inquiry. Absence from every register while soliciting deposits is the quieter fail: no license, no oversight, no compensation scheme when the money vanishes. How we weigh these sources is in our methodology.
10. Reviews
Read Trustpilot, Reddit, and the BBB together, and read for shape, not stars. Organic praise arrives irregularly, over years, in mixed voices with specific detail; purchased praise lands in bursts of similar, cheerful grammar, usually after launch or after a wave of complaints. The loudest signal is the withdrawal complaint — profits visible on a dashboard that never reach a bank. When several strangers tell the same story, believe them. The "pay a fee to unlock your withdrawal" demand is not a fee. It is the second theft.
11. Physical address
Paste the headquarters address into Google Maps and drop into Street View. A pass is a real commercial building consistent with the operation being claimed. A fail is a mail drop, a virtual-office tower housing hundreds of shelf companies, a suburban house, or no such address at all.
12. Team photos
Right-click the CEO's headshot and run it through a reverse image search. A pass finds a real person whose history matches the bio. A fail finds the same face fronting a dental practice in another country under another name — or smiling from a stock-photo catalog.
Check 13: the payment and pressure test
The last check needs no tool, only attention to what the site demands of you. The FTC found that people who paid scammers by bank transfer or cryptocurrency lost more in 2024 than victims using all other payment methods combined — which is why fraud operations steer you to those rails. Card payments carry chargeback rights; a USDT transfer carries none. Guaranteed returns, countdown timers, an "account manager" who telephones to urge larger deposits, a withdrawal that requires a "tax" paid first: each one, alone, is enough. No legitimate platform guarantees profit. None. Our field guide to spotting a crypto scam maps these scripts line by line.
Is this site safe? Scoring the results
One fail is a yellow light: keep digging. Two fails in different layers — a young domain plus no register entry, say — means treat the site as hostile. Three or more means walk away and report it. Layers matter more than the count: the signature we document across pig-butchering platforms and fake exchanges is always the same triad: a fresh domain, no verifiable company, crypto-only deposits. Run the thirteen and you never have to wonder how to check if a website is legit again — you have a record, not a hunch. The full weighting is published in our methodology, because a verification method you cannot inspect is just another opinion.
Can a scam pass every check?
Rarely. But yes, at the extremes. Clone firms copy a licensed company's identity down to its registration number, differing only in the domain — verify the register entry yourself and compare the domain character by character instead of clicking the link you were sent. Aged-domain resales let a fraud inherit a ten-year-old domain, which is why the archive history in check 7 matters more than the birthday in check 1. Thirteen passes mean "no evidence of fraud found," not a guarantee; they shift the burden to the payment test, which fraud almost always fails.
Already sent money? Do this in order
Stop all payments — including any "fee" demanded to release your balance. Screenshot everything: dashboards, chats, wallet addresses, emails. File with the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, then work through our first-48-hours protocol before the trail cools. Expect a second approach: "recovery agents" who find victims in comment sections and promise to retrieve funds for an upfront payment. That is a second fraud built on the first, and paying it changes nothing except the total. If the platform is one we have reviewed, tell us what happened; victim reports are how warning lists grow teeth.
Frequently asked questions
How do I check if a website is legit for free?
Every tool above is free: lookup.icann.org for domain age, crt.sh for certificate history, Google Safe Browsing and VirusTotal for blacklists, web.archive.org for history, government registers and regulator warning lists for the company, reverse image search for the team. Fifteen minutes, no budget.
Does the padlock or HTTPS mean a website is safe?
No. The certificate proves the connection is encrypted and that the holder controls the domain — nothing about intent. Most scam sites we examine hold valid certificates. Treat the padlock as the absence of one problem, not the presence of trust.
How do I find out who owns a website?
Run the domain through lookup.icann.org or rdap.org and read the RDAP record: registration date, registrar, and any published registrant data. If privacy shielding hides the owner, check the footer and terms page for a legal entity name, then confirm it in a government company register. An honest business does not make this hard.
The site has hundreds of five-star Trustpilot reviews. Can I trust them?
Read the shape before the stars. Real reputations accumulate unevenly over years; fake ones arrive in bursts of similar phrasing after launch or after bad press. Weight one detailed withdrawal complaint — money visible on a dashboard that never reaches a bank — above a hundred generic five-star ratings.
I already deposited money with a site that failed these checks. What now?
Do not send another dollar, including any "tax" or "fee" to unlock a withdrawal. Document everything, file with the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, and follow our first-48-hours guide. Anyone who offers to recover the funds for an upfront payment is running the recovery scam that follows the first one.
Frequently asked questions
How do I check if a website is legit for free?
Every tool above is free: lookup.icann.org for domain age, crt.sh for certificate history, Google Safe Browsing and VirusTotal for blacklists, web.archive.org for history, government registers and regulator warning lists for the company, reverse image search for the team. Fifteen minutes, no budget.
Does the padlock or HTTPS mean a website is safe?
No. The certificate proves the connection is encrypted and that the holder controls the domain — nothing about intent. Most scam sites we examine hold valid certificates. Treat the padlock as the absence of one problem, not the presence of trust.
How do I find out who owns a website?
Run the domain through lookup.icann.org or rdap.org and read the RDAP record: registration date, registrar, and any published registrant data. If privacy shielding hides the owner, check the footer and terms page for a legal entity name, then confirm it in a government company register. An honest business does not make this hard.
The site has hundreds of five-star Trustpilot reviews. Can I trust them?
Read the shape before the stars. Real reputations accumulate unevenly over years; fake ones arrive in bursts of similar phrasing after launch or after bad press. Weight one detailed withdrawal complaint — money visible on a dashboard that never reaches a bank — above a hundred generic five-star ratings.
I already deposited money with a site that failed these checks. What now?
Do not send another dollar, including any "tax" or "fee" to unlock a withdrawal. Document everything, file with the FBI at ic3.gov and the FTC at ReportFraud.ftc.gov, and follow our first-48-hours guide. Anyone who offers to recover the funds for an upfront payment is running the recovery scam that follows the first one.
About the investigator
Ray Okafor
Cyber analyst · infrastructure & data
Ray Okafor maps scam infrastructure for a living: DNS graphs, certificate transparency logs, hosting patterns, wallet clusters. Before ScamTrix he spent eight years in threat intelligence, tracking the operators most publications never name.
All investigations by Ray →