When you come across an address like 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com, it's important to recognize what you're looking at. This isn't a typical e-commerce site or a blog. It's a subdomain under AWS's own 'token.awswaf.com' domain, which is part of Amazon's Web Application Firewall service. Such endpoints are used behind the scenes by legitimate applications to validate security tokens. The site itself returns a 404 error for the main path, meaning there's no public homepage to visit. That's normal for these backend URLs.
From a safety perspective, the infrastructure is solid: a valid SSL certificate, clean blacklist status, and fast CloudFront delivery. The lack of contact info or legal pages is irrelevant here because this isn't a business serving consumers. If you're wondering whether 99a173f17960.cb2f8be0.eu-central-1.token.awswaf.com is a scam, the evidence points to a legitimate AWS component rather than a fraudulent operation. There's no consumer risk because there's nothing to buy, log into, or download. Just be aware that this endpoint alone won't tell you anything about the application that uses it β that's where your due diligence should focus.