Is ampproject.org legit?
This site appears mostly safe, demonstrating strong infrastructure and solid security. However, the presence of many external scripts and hidden elements, along with a lack of direct contact information, suggests areas for improved transparency and potential security hardening.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 21, 2026 at 11:49 AM UTC
Is ampproject.org a scam? Here's what we found.
The site boasts a valid SSL certificate with modern TLS, and Google Web Risk reports no threats, which are excellent signs. However, the high number of external scripts introduces a noticeable-yet-manageable security vulnerability.
With a decade-old domain registered through a reputable provider like MarkMonitor, the site establishes a strong and stable online identity. The publicly available WHOIS information further reinforces trust.
Ranking among the top global websites, ampproject.org has a significant and established online presence, further bolstered by its clean DNS blacklist record. While a Trustpilot profile is absent, this is not a concern for an open-source project.
Although legal pages and social media links are present, the site's transparency is significantly hampered by an excessive number of hidden elements and the absence of clear contact information on the homepage, which can be concerning for user trust.
The presence of both privacy policy and terms of service pages indicates a good adherence to basic legal and user protection standards. No other compliance issues were identified.
The robust DNS setup, complete with multiple name servers and strong email authentication via SPF and DMARC, points to a well-maintained and secure infrastructure. The active HSTS header ensures secure connections, even though the primary domain redirects.
Signals Detected
Site has structured data markup
This is one of the most visited websites globally
This business has no Trustpilot presence — not unusual for smaller or newer companies
Excessive number of external scripts — may indicate malicious injection
Excessive hidden content found — may indicate cloaking or deceptive content
Valid certificate, expires in 61 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Resolves to: 2a00:1450:4001:c17::66, 2a00:1450:4001:c17::8a, 2a00:1450:4001:c17::65, 2a00:1450:4001:c17::8b, 142.250.186.78
Mail servers: smtp.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns2.google.com., ns1.google.com., ns4.google.com., ns3.google.com.
Site redirects to https://amp.dev/
Site enforces HTTPS via HSTS
Web server: Netlify
No threats detected by Google Web Risk
No robots.txt file — common for small sites
Domain created 2015-08-31T16:13:25Z (10 years, 9 months ago)
Registered through MarkMonitor Inc.
Expires in 132 days
DNSSEC status from WHOIS
Site has custom branding and social media metadata
No sitemap found — common for smaller sites
Website is live and responding
No obvious contact information found on homepage
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.