Is cookiedatabase.org legit?
This website appears to be trusted, showing strong technical foundations and transparency regarding its legal information. While it could improve its branding and social media presence, the overall security and infrastructure are robust, and it is a globally popular site.
VPN & Security average: 83/100 · based on 16 sites
Checked: April 21, 2026 at 11:09 PM UTC
Is cookiedatabase.org a scam? Here's what we found.
The site uses modern TLS 1.3, has a valid SSL certificate (though from Let's Encrypt), and enforces HTTPS via HSTS and CSP, showing a strong commitment to user security. The only concern is the high number of external scripts, which introduces potential vulnerabilities.
With a domain age of over 7 years, the site indicates established longevity. The WHOIS information, while using Key-Systems GmbH, is public and not hidden, contributing to identity transparency.
Ranking among the most visited websites globally and being clean on Google Web Risk and DNS blacklists signifies a strong and positive reputation. The lack of a Trustpilot profile is not a significant concern for a site of this type.
The site provides clear contact information and essential legal pages. However, the absence of a favicon and any social media presence impacts its overall transparency and ability to be easily recognized or connected with.
The presence of both a privacy policy and terms of service demonstrates attention to legal compliance, crucial for a platform dealing with data information.
The site exhibits robust infrastructure with multiple IP addresses for DNS resolution, comprehensive email authentication (SPF, DMARC), Cloudflare for DNS, and a valid robots.txt and sitemap. The unsigned DNSSEC is a minor omission but doesn't detract significantly from an otherwise well-configured setup.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
Excessive number of external scripts — may indicate malicious injection
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 82 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Resolves to: 2a06:98c1:3121::3, 2a06:98c1:3120::3, 188.114.96.3, 188.114.97.3
Mail servers: mx10.onlinemailscanner.com., mx20.onlinemailscanner.com., mx30.onlinemailscanner.com., mx40.onlinemailscanner.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: daisy.ns.cloudflare.com., plato.ns.cloudflare.com.
robots.txt has 5 directives and references a sitemap
Site maintains a proper sitemap with 10 indexed pages
No favicon found — unusual for an established business
Domain created 2019-01-07T15:55:53Z (7 years, 4 months ago)
Registered through Key-Systems GmbH
Expires in 260 days
DNSSEC status from WHOIS
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
crt.sh returned status 502
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
No social media links found on homepage
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.