Is casetext.com legit?
Casetext.com appears to be a trusted site with a strong foundation in security and infrastructure. The primary concern is the relatively short domain expiry, which should be addressed, and some minor transparency and auditing gaps.
Legal Services average: 80/100 · based on 10 sites
Checked: April 27, 2026 at 8:44 AM UTC
Is casetext.com a scam? Here's what we found.
The site uses a modern TLS 1.3 connection with a valid SSL certificate and enforces HTTPS via HSTS. While Certificate Transparency could not be checked, Google Web Risk detected no threats, indicating a generally secure environment.
The domain is well-aged at 12 years and registered through a reputable registrar (MarkMonitor). However, the upcoming domain expiry in 46 days is a notable point of concern for a well-established company.
The site has a long history in the web archives spanning 12 years and is not present on any DNS blacklists, reinforcing its established and clean reputation.
Bot protection prevented checks for contact information, legal pages, and social media, which is common for larger sites but limits full transparency verification. The missing favicon is a minor aesthetic and branding oversight.
Due to bot protection, crucial compliance-related pages like legal pages could not be directly inspected. While this prevents a definitive assessment, the presence of a Content Security Policy and Clickjacking protection are positive indicators of security-focused compliance.
The robust infrastructure includes DNSSEC, multiple reliable IP resolutions, comprehensive email authentication (SPF and DMARC), and Cloudflare for DNS and server management, all contributing to high reliability and protection.
Signals Detected
This site has moderate global traffic
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2013-06-12T23:28:27Z (12 years, 0 months ago)
Registered through MarkMonitor Inc.
Expires in 46 days
DNSSEC status from WHOIS
Resolves to: 2606:4700:3108::ac42:28c0, 2606:4700:3108::ac42:2b40, 172.66.40.192, 172.66.43.64
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., aspmx3.googlemail.com., aspmx2.googlemail.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: daisy.ns.cloudflare.com., isaac.ns.cloudflare.com.
crt.sh returned status 429
Valid certificate, expires in 77 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
No favicon found — unusual for an established business
No robots.txt file — common for small sites
No sitemap found — common for smaller sites
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
Not found on any DNS blacklists
Earliest archive snapshot from 20130702
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.