Is goo.gl legit?
This site is Mostly Safe, but you should still use caution due to crucial missing legal pages and an inaccessible website status. While it benefits from the strong infrastructure you'd expect from a Google-affiliated domain and robust security, the lack of transparency is a concern.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 12, 2026 at 9:00 PM UTC · Refresh
Is goo.gl a scam? Here's what we found.
The site boasts excellent security with a modern TLS 1.3 connection, an SSL certificate issued by Google, HSTS, and a Content Security Policy, all showing a strong commitment to protecting user data. Google Web Risk also found no threats.
With a domain age of over 20 years, registered through a reputable registrar like MarkMonitor, and managed by Google, the identity behind goo.gl is extremely well-established and trustworthy.
The domain holds an incredibly high Tranco Rank (Top 54 globally), is not on any DNS blacklists, and has a long history, all pointing to a very strong and reputable web presence despite limited Trustpilot reviews.
Transparency is a weak point here, as the website itself returns an error (HTTP 400) when accessed directly. The absence of contact information and social media links also makes it hard for users to engage or seek support.
A major concern is the complete absence of legal pages like a privacy policy or terms of service, which is a serious oversight for any operational website, particularly one that was formerly a link shortener handling user data.
The infrastructure is robust, supported by Google's authoritative name servers, multiple IP addresses, strong email authentication (SPF and DMARC), and fast page load times, ensuring reliability and performance.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
Valid certificate, expires in 63 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
crt.sh returned status 429
Resolves to: 2a00:1450:4001:c1f::8a, 2a00:1450:4001:c1f::64, 2a00:1450:4001:c1f::8b, 2a00:1450:4001:c1f::65, 142.251.110.102, 142.251.110.101, 142.251.110.113, 142.251.110.139, 142.251.110.138, 142.251.110.100
No MX records found — domain may not handle email
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns2.google.com., ns3.google.com., ns1.google.com., ns4.google.com.
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: ESF
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
No sitemap found — common for smaller sites
Too few reviews to be a reliable indicator
No robots.txt file — common for small sites
Not found on any DNS blacklists
Domain created 2005-06-22T02:00:00.0Z (20 years, 1 months ago)
Registered through MarkMonitor, Inc.
Expires in 264 days
DNSSEC status from WHOIS
Website returned status 400
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.