Homeβ€Ί Infrastructureβ€Ί 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com
Mostly Safe

Yes β€” 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com looks mostly safe

70/ 100 trust score
Industry: Infrastructure Checked Jul 20, 2026 Infrastructure average: 49 25 signals

In plain English

This isn't a normal website you'd browse or buy from β€” it's a technical endpoint for AWS WAF token validation. It returns a 404 error for the path we checked, so there's nothing to interact with. The infrastructure is secure and clean, and the domain clearly belongs to Amazon's infrastructure. Nothing here suggests a scam, but there's also no consumer-facing content to trust.

Cross-referenced 25 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Jul 20, 2026. How we score β†’

Where the score comes from

We look at six areas. Here's how 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com did in each.
90
Security

Solid security setup with a valid Amazon-issued certificate and TLS 1.3, plus a clean Google Web Risk report. No security headers are set, but that's typical for a backend endpoint where browser-based protections aren't needed.

70
Identity

This is a subdomain under 'token.awswaf.com', which is clearly an AWS service domain. No WHOIS record is available for the subdomain itself, but the parent domain is owned by Amazon, so ownership is effectively transparent.

70
Reputation

Not on any DNS blacklists and no threats detected by Google. The absence of Wayback Machine snapshots is normal for an infrastructure endpoint that doesn't serve public web pages.

60
Transparency

No contact page, about page, or social media links. That's completely expected for a backend token endpoint β€” it's not a business trying to communicate with consumers.

70
Compliance

No privacy policy or terms of service found, but this endpoint isn't a commercial site or collecting user data directly. Missing legal pages here isn't a compliance red flag.

85
Infrastructure

Hosted on AWS CloudFront with fast load times and a clean DNS setup. No MX records or DNSSEC, but neither is needed for an endpoint that only handles token validation requests.

What we checked

The 25 signals behind this report.
Security & Transport
Certificate Issuer
Amazon
Google Web Risk
Clean
SSL Certificate
Valid
Security Headers
0 of 6
TLS Version
TLS 1.3
Identity & WHOIS
About Page
Not found
Branding
Missing
Business Disclosure
Not found
Contact Info
Not found
Legal Pages
Missing
Infrastructure & DNS
CDN
AWS CloudFront
DNS Blacklists
Clean
DNS Resolution
4 IP(s)
DNSSEC
Not enabled
Email (MX Records)
None
Hosting Network (ASN)
AS16509 AMAZON-02
Page Load Time
38ms
Reputation & Reach
Sitemap
Not found
Social Media Presence
None found
Structured Data
None found
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
No archive found
Website Status
HTTP 404
robots.txt
Not found

Run this site? Show your score.

Add a trust badge so visitors can see your live score for themselves.

Get your badge β†’
verified.fyi
99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com
70
N Partner pick
This site checks out. Stay covered everywhere: NordVPN's Threat Protection blocks known scam sites before they load.
Try NordVPN β†’

When you come across an address like 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com, it's important to recognize what you're looking at. This isn't a typical e-commerce site or a blog. It's a subdomain under AWS's own 'token.awswaf.com' domain, which is part of Amazon's Web Application Firewall service. Such endpoints are used behind the scenes by legitimate applications to validate security tokens. The site itself returns a 404 error for the main path, meaning there's no public homepage to visit. That's normal for these backend URLs.

From a safety perspective, the infrastructure is solid: a valid SSL certificate, clean blacklist status, and fast CloudFront delivery. The lack of contact info or legal pages is irrelevant here because this isn't a business serving consumers. If you're wondering whether 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com is a scam, the evidence points to a legitimate AWS component rather than a fraudulent operation. There's no consumer risk because there's nothing to buy, log into, or download. Just be aware that this endpoint alone won't tell you anything about the application that uses it β€” that's where your due diligence should focus.

More Infrastructure sites

How similar sites score. See all β†’