01 / Data sources
LegitVerdict collects evidence live, per domain, from sources anyone can verify: RDAP registration records (age, period, registrar, privacy status), a direct TLS handshake (certificate validity, issuer, assurance level), DNS resolution (records, stability, mail capability), the rendered page itself (contacts, payment methods, social links, content volume, structured data, indexing directives), the research-grade Tranco popularity list, a public TLD abuse dataset, and - for Bulgarian businesses - the public Trade Registry, where published company IDs are verified directly.
Some checks require paid or licensed sources (multi-vendor malware scanning, external review APIs, backlink data, IP reputation). These are disclosed here for transparency but marked premium: they are not part of the free report, and their absence never lowers a score - it only lowers the stated confidence.
Data freshness: collection results are cached (24-48 h per source), and each page shows its last-updated date in the footer. Owners can trigger a recompute through the verification flow.
02 / The scoring principles
Three headline scores - risk, trust and buyer-safety - are computed independently, each from its own categories of evidence, so a strength in one can never mask a weakness in another. Every signal is individually weighted and each score is fully explainable from the record on the report itself; the methodology is documented and independently auditable.
Risk
- Authoritative abuse-feed, malware and phishing listings
- Certificate validity and working HTTPS
- Domain registration, registrar and re-registration history
- Hosting network and address reputation
- Search-indexing behaviour and transparency gaps
Trust
- Domain age and multi-year registration horizon
- Independent, research-grade popularity footprint
- Registry-verified company identity
- Openly published, reachable contact details
- Social presence and third-party footprint
Buyer-safety
- Secure, encrypted checkout and valid TLS
- Buyer-protected payment methods
- Published returns, contact and legal policies
- A real, identifiable business behind the site
- Operational reachability - live mail and responsive infrastructure
AI-readiness
- Crawlable, server-readable content
- Structured data and clear entity signals
- A recognisable, maintained platform
- Open indexing for search and AI crawlers
What each score reads is published here in full; the exact per-signal weightings are applied consistently to every domain and are open to inspection on request, but are not printed as a copy-paste table - the value is an honest, consistently-applied verdict, not a spec sheet for a look-alike checker.
03 / Context rules
A young domain with valid encryption, real contacts and a verifiable company is a startup, not a scam. Newness lowers the stated confidence of the verdict - it does not raise the risk score.
WHOIS privacy, a cheap TLD, shared hosting or a missing popularity rank are capped at half amplitude. None of them - alone or together - can push a domain into a danger band.
Unavailable or premium-tier data contributes exactly zero. The engine reports a lower confidence figure instead of guessing - and the confidence is printed on every report.
04 / Scale
The overall scale runs 1-100: 1-20 very likely dangerous, 21-40 likely dangerous, 41-60 caution / mixed, 61-80 likely safe, 81-100 very likely safe. Risk is reported separately (lower is safer), as are trust and buyer-safety (higher is safer to transact), so a strength in one axis can never mask a weakness in another. AI-readiness is published too, as a secondary, owner-facing lens that does not affect the safety verdict.
Every verdict is an algorithmic risk indicator, not an accusation. Owners can verify control of their domain for free to correct the record, attach company details and respond publicly; anyone can report inaccurate data. Both routes are reviewed by a human.