Is arxiv.org legit?
arxiv.org is a highly trusted platform, serving as a vital resource for the academic community for nearly three decades. While there are minor concerns regarding an upcoming SSL certificate expiration and incomplete legal pages, its long history, robust technical infrastructure, and high global traffic indicate a reliable and legitimate operation.
Education average: 81/100 · based on 35 sites
Checked: April 18, 2026 at 7:55 AM UTC · Refresh
Is arxiv.org a scam? Here's what we found.
While the connection uses the modern TLS 1.3 protocol and Google Web Risk reports no threats, the rapidly approaching SSL certificate expiration (20 days) is a notable concern that needs immediate attention from the site's administrators to maintain continuous secure access.
With a domain age of over 27 years and public WHOIS information, arxiv.org demonstrates a very strong and transparent identity, indicating long-term commitment and established presence.
As one of the world's most visited websites (Tranco Rank #575) with a 25-year archive history and no presence on DNS blacklists, arxiv.org holds an impeccable reputation within its domain.
Contact information is available, which is good for user assistance. However, the absence of social media links on the homepage suggests a more traditional, academic approach to communication rather than active public engagement.
The presence of only partial legal pages (missing either a privacy policy or terms of service) is a gap that should be addressed for full user transparency and legal adherence, especially for a site of its stature.
The site boasts a robust and well-configured technical foundation, including multiple DNS IPs, strong email authentication (SPF, DMARC), and fast page load times, all contributing to a reliable user experience.
Signals Detected
No structured data markup found
This is one of the most visited websites globally
robots.txt has 326 directives
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 20 days
Certificate issued by Certainly
Connection uses TLS 1.3
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: Google Frontend
No threats detected by Google Web Risk
Resolves to: 151.101.195.42, 151.101.3.42, 151.101.131.42, 151.101.67.42
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-cloud-d1.googledomains.com., ns-cloud-d4.googledomains.com., ns-cloud-d2.googledomains.com., ns-cloud-d3.googledomains.com.
Site has a favicon but no social sharing metadata
Not found on any DNS blacklists
Domain created 1998-12-28T05:00:00Z (27 years, 8 months ago)
Registered through Network Solutions, LLC
Expires in 1349 days
DNSSEC status from WHOIS
No sitemap found — common for smaller sites
Earliest archive snapshot from 20010226
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
No social media links found on homepage
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.