LegitVerdict

E-E-A-T - full transparency

The methodology

Every score is explainable. A trust score you cannot explain is just an opinion with digits - this page sets out exactly what LegitVerdict reads, the principles behind how each signal counts, and what the engine refuses to conclude.

01 / Data sources

What we read

LegitVerdict collects evidence live, per domain, from sources anyone can verify: RDAP registration records (age, period, registrar, privacy status), a direct TLS handshake (certificate validity, issuer, assurance level), DNS resolution (records, stability, mail capability), the rendered page itself (contacts, payment methods, social links, content volume, structured data, indexing directives), the research-grade Tranco popularity list, a public TLD abuse dataset, and - for Bulgarian businesses - the public Trade Registry, where published company IDs are verified directly.

Some checks require paid or licensed sources (multi-vendor malware scanning, external review APIs, backlink data, IP reputation). These are disclosed here for transparency but marked premium: they are not part of the free report, and their absence never lowers a score - it only lowers the stated confidence.

Data freshness: collection results are cached (24-48 h per source), and each page shows its last-updated date in the footer. Owners can trigger a recompute through the verification flow.

02 / The scoring principles

What each score is built from

Three headline scores - risk, trust and buyer-safety - are computed independently, each from its own categories of evidence, so a strength in one can never mask a weakness in another. Every signal is individually weighted and each score is fully explainable from the record on the report itself; the methodology is documented and independently auditable.

Risk how dangerous - lower is safer

  • Authoritative abuse-feed, malware and phishing listings
  • Certificate validity and working HTTPS
  • Domain registration, registrar and re-registration history
  • Hosting network and address reputation
  • Search-indexing behaviour and transparency gaps

Trust the track record

  • Domain age and multi-year registration horizon
  • Independent, research-grade popularity footprint
  • Registry-verified company identity
  • Openly published, reachable contact details
  • Social presence and third-party footprint

Buyer-safety how safely a consumer can transact

  • Secure, encrypted checkout and valid TLS
  • Buyer-protected payment methods
  • Published returns, contact and legal policies
  • A real, identifiable business behind the site
  • Operational reachability - live mail and responsive infrastructure

AI-readiness secondary, owner-facing lens

  • Crawlable, server-readable content
  • Structured data and clear entity signals
  • A recognisable, maintained platform
  • Open indexing for search and AI crawlers

What each score reads is published here in full; the exact per-signal weightings are applied consistently to every domain and are open to inspection on request, but are not printed as a copy-paste table - the value is an honest, consistently-applied verdict, not a spec sheet for a look-alike checker.

03 / Context rules

What the engine refuses to do
Rule 1
New is not guilty

A young domain with valid encryption, real contacts and a verifiable company is a startup, not a scam. Newness lowers the stated confidence of the verdict - it does not raise the risk score.

Rule 2
Weak signals stay weak

WHOIS privacy, a cheap TLD, shared hosting or a missing popularity rank are capped at half amplitude. None of them - alone or together - can push a domain into a danger band.

Rule 3
Missing is not negative

Unavailable or premium-tier data contributes exactly zero. The engine reports a lower confidence figure instead of guessing - and the confidence is printed on every report.

04 / Scale

Bands & recourse

The overall scale runs 1-100: 1-20 very likely dangerous, 21-40 likely dangerous, 41-60 caution / mixed, 61-80 likely safe, 81-100 very likely safe. Risk is reported separately (lower is safer), as are trust and buyer-safety (higher is safer to transact), so a strength in one axis can never mask a weakness in another. AI-readiness is published too, as a secondary, owner-facing lens that does not affect the safety verdict.

Every verdict is an algorithmic risk indicator, not an accusation. Owners can verify control of their domain for free to correct the record, attach company details and respond publicly; anyone can report inaccurate data. Both routes are reviewed by a human.