Is fbi.gov legit?
You can absolutely trust fbi.gov. While there's a minor gap in its legal disclosures, its extensive history, robust security, and official government backing make it a highly credible and safe online destination.
Government average: 80/100 · based on 33 sites
Checked: April 18, 2026 at 8:06 AM UTC · Refresh
Is fbi.gov a scam? Here's what we found.
The site employs a strong security posture with modern TLS 1.3 encryption, HSTS header enforcement, and clickjacking protection, ensuring your connection is secure and protected against common attacks. Google Web Risk found no threats, which is crucial for a site of this stature.
As a highly trafficked government domain with nearly 29 years of age, fbi.gov's identity is unequivocally established. The 'get.gov' registrar further confirms its official capacity.
With a high Tranco rank and a domain age spanning nearly three decades, fbi.gov boasts an impeccable online reputation. It's not listed on any blacklists, reinforcing its standing as a legitimate and essential online resource.
The FBI website is highly transparent, providing clear contact information and an active presence across multiple social media platforms, facilitating public engagement and accessibility.
While the site generally adheres to compliance standards, the partial legal pages are a minor oversight. For a government entity handling public data, comprehensive legal disclosures are paramount.
The site's infrastructure is robust, featuring multiple DNS servers, strong email authentication (SPF and DMARC), and DNSSEC, all contributing to a resilient and secure online presence.
Signals Detected
This is a well-known, high-traffic website
Site has structured data markup
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 30 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Site has custom branding and social media metadata
crt.sh returned status 429
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Resolves to: 2606:4700::6810:95f4, 2606:4700::6810:94f4, 104.16.148.244, 104.16.149.244
Mail servers: mx-east.fbi.gov., mx-west.fbi.gov.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-cloud-e1.googledomains.com., ns-cloud-e3.googledomains.com., ns-cloud-e4.googledomains.com., ns-cloud-e2.googledomains.com.
robots.txt has 21 directives and references a sitemap
Domain created 1997-10-02T01:29:23Z (28 years, 11 months ago)
Registered through get.gov
Expires in 125 days
DNSSEC status from WHOIS
Not found on any DNS blacklists
No sitemap found — common for smaller sites
Could not query Wayback Machine
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.