Is att.com legit?
While att.com boasts a long history and strong underlying technical infrastructure, immediate caution is advised due to critical missing elements like legal pages, contact information, and an active website error that prevents access. The imminent domain expiry is also a significant concern that needs addressing.
Telecom average: 74/100 · based on 25 sites
Checked: April 18, 2026 at 7:55 AM UTC · Refresh
Is att.com a scam? Here's what we found.
While the site uses secure TLS 1.2 and has a valid SSL certificate from a reputable issuer, the critical 403 'Forbidden' error prevents access, indicating a significant security or configuration flaw currently impacting usability and potentially trust.
The domain has an impressive 40-year history, indicating a long-established entity. However, the extremely short domain expiry timeframe (7 days) is highly unusual and raises serious questions about its immediate operational stability.
With a high Tranco rank and clean Google Web Risk and DNS Blacklist statuses, the site appears to have a strong overall reputation, typical of a well-known brand, despite other technical issues.
Transparency is severely lacking. The absence of clear contact information, social media links, and even a basic favicon makes it difficult to verify the site's legitimacy or engage with the entity behind it.
The complete absence of both a privacy policy and terms of service is a major issue, especially for a site that would presumably handle user data or provide services, making it non-compliant with standard legal expectations.
The site demonstrates robust foundational infrastructure, including strong email authentication (SPF, DMARC), stable DNS resolution, and good page load times, signaling a professionally managed technical backend.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1986-04-25T05:00:00Z (40 years, 6 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 7 days
DNSSEC status from WHOIS
Resolves to: 144.160.36.42, 144.160.155.43
Mail servers: mx0a-00191d01.pphosted.com., mx0b-00191d01.pphosted.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: a1-187.akam.net., a2-64.akam.net., a22-67.akam.net., a5-66.akam.net., a4-64.akam.net., a11-65.akam.net.
Site enforces HTTPS via HSTS
Web server: AkamaiGHost
No threats detected by Google Web Risk
Not found on any DNS blacklists
Valid certificate, expires in 339 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.2
Website returned status 403
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
No favicon found — unusual for an established business
No sitemap found — common for smaller sites
No robots.txt file — common for small sites
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.