Is cookielaw.org legit?
This site appears trustworthy, particularly regarding its robust technical infrastructure and strong security measures. However, the redirection away from the primary domain and incomplete legal pages are minor points to consider.
SaaS average: 81/100 · based on 62 sites
Checked: April 21, 2026 at 6:18 AM UTC
Is cookielaw.org a scam? Here's what we found.
The site boasts a strong security posture with a valid, modern SSL certificate, TLS 1.3, HSTS, CSP, and clickjacking protection, all backed by a clean Google Web Risk report.
The domain has a substantial age of 14 years, clearly visible WHOIS information, and a long expiry date, indicating a well-established and transparent identity, despite being registered through a common registrar.
With an extremely high Tranco rank, clean DNS blacklists, and a long domain age, the site has a strong reputation. The redirect to another domain is a minor detractor from user experience.
The site provides clear contact information and a complete branding presence, including social media links, demonstrating good transparency about its operations and how to engage with them.
While the site is related to cookie law, the incomplete legal pages (missing either a privacy policy or terms of service) are a notable gap for compliance, especially given the site's explicit purpose.
The underlying infrastructure is robust, featuring multiple IP resolvers, excellent email authentication (SPF, DMARC), Cloudflare for DNS and server, and a swift page load time.
Signals Detected
This is one of the most visited websites globally
Site has structured product information — typical of legitimate e-commerce
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 64 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
crt.sh returned status 429
Resolves to: 2606:4700::6812:572a, 2606:4700::6812:562a, 104.18.87.42, 104.18.86.42
Mail servers: mxa-0085c101.gslb.pphosted.com., mxb-0085c101.gslb.pphosted.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: bob.ns.cloudflare.com., sharon.ns.cloudflare.com.
robots.txt has 21 directives
Site has custom branding and social media metadata
Site redirects to https://www.onetrust.com/products/cookie-consent/
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
Domain created 2011-06-20T12:47:48Z (14 years, 0 months ago)
Registered through NameCheap, Inc.
Expires in 1521 days
DNSSEC status from WHOIS
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.