Is forbes.com legit?
Forbes.com is a well-established and trusted website with a strong security posture and clear identity. While there are some minor technical issues with the sitemap and a high number of external scripts, these do not significantly detract from its overall trustworthiness.
News & Media average: 80/100 · based on 32 sites
Checked: April 21, 2026 at 4:08 AM UTC
Is forbes.com a scam? Here's what we found.
The site uses a valid SSL certificate with a modern TLS version and strong security headers like HSTS and CSP. However, the high number of external scripts and hidden elements present moderate concerns that warrant attention.
With a domain age of over 32 years and a high Tranco Rank, Forbes.com has a very strong and established identity. The upcoming domain expiry is a minor administrative concern but doesn't diminish its historical legitimacy.
The domain's age, clean DNS blacklists, and Google Web Risk status contribute to an excellent reputation. The absence of a Trustpilot profile is not unusual for a publication of this scale.
Forbes.com is highly transparent, featuring clear contact information, legal pages (privacy & terms), and an active presence across multiple social media platforms, indicating a commitment to open communication.
The presence of both privacy policy and terms of service pages demonstrates a strong commitment to compliance with modern web standards and user rights.
The DNS configuration is robust with multiple name servers and DMARC email authentication. The misconfigured sitemap is a minor technical oversight that could impact search engine optimization.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: Organization
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 235 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.2
Domain created 1993-06-17T04:00:00Z (32 years, 3 months ago)
Registered through MarkMonitor Inc.
Expires in 55 days
DNSSEC status from WHOIS
crt.sh returned status 429
Site has custom branding and social media metadata
robots.txt has 13 directives
Sitemap URL returns non-XML content
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: istio-envoy
No threats detected by Google Web Risk
Excessive number of external scripts — may indicate malicious injection
Excessive hidden content found — may indicate cloaking or deceptive content
Resolves to: 151.101.194.49, 151.101.66.49, 151.101.130.49, 151.101.2.49
Mail servers: us-smtp-inbound-2.mimecast.com., us-smtp-inbound-1.mimecast.com.
Domain has DMARC email authentication configured
DNS providers: ns-1028.awsdns-00.org., ns-1637.awsdns-12.co.uk., ns-217.awsdns-27.com., ns-979.awsdns-58.net.
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.