I'd be wary of gregharrelson.com. The domain has been around for 19 years, but with no about page, no contact info, and no way to tell who runs it, it feels like a ghost site. That level of anonymity is unusual even for a personal blog, and there's just not enough to go on to trust it with anything personal.
What you should do now
Don't panic. These steps limit the damage, and the sooner you take them the better.
1
Don't enter any details
No passwords, card numbers or personal information β even if the site looks professional.
2
Close the tab
Especially if you got here from an email, text message or social media ad.
3
Already paid? Call your bank
Contact your bank or card provider right away. They can often stop or reverse a recent payment.
4
Warn others
Report the site and share this check with anyone who sent you the link.
Cross-referenced 33 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Jun 30, 2026.How we score β
Where the score comes from
We look at six areas. Here's how gregharrelson.com did in each.
70
Security
The site uses a valid certificate with modern TLS 1.3, sets clickjacking protection, and passes Google Web Risk checks. But it still accepts outdated TLS 1.0 and 1.1, which is a minor lingering issue for a 19-year-old domain.
65
Identity
The domain has a solid history: 19 years old and registered through a major registrar. WHOIS privacy is expected for a personal site at this age. No obvious red flags about who runs it, but also no clear ownership disclosure.
75
Reputation
The site has been on the web for 17 years per the Wayback Machine, with no blacklist hits. It's not a high-traffic domain, but longevity without abuse flags is a positive signal for a personal or archival site.
30
Transparency
There is no About page, no contact info, no social media links, and no favicon. For a personal blog or hobby project, some of that is normal, but the complete absence of any identifying or contact elements is unusual even for a low-key site.
85
Compliance
No privacy policy or terms of service were found, but based on the homepage content (which appears to be a personal blog or archive), this is not a commercial operation handling payments or sensitive data, so legal pages aren't required.
70
Infrastructure
Hosted on Cloudflare with fast load times and valid email records. DNSSEC is not enabled, but that's common for older personal domains. The infrastructure is functional and well-maintained, not cutting-edge.
What we checked
The 33 signals behind this report.
Security & Transport
Certificate Issuer
Google Trust Services
Clickjacking Protection
Present
Google Web Risk
Clean
Legacy TLS
Accepted
SSL Certificate
Valid
Security Headers
3 of 6
Server
cloudflare
TLS Version
TLS 1.3
Identity & WHOIS
About Page
Not found
Branding
Missing
Business Disclosure
Not found
Contact Info
Not found
Domain Age
19 years, 1 months
Domain Expiry
2026-08-29T15:08:55Z
Legal Pages
Missing
Registrar
GoDaddy.com, LLC
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
4 IP(s)
DNSSEC
Not enabled
DNSSEC
unsigned
Email (MX Records)
2 record(s)
Hosting Network (ASN)
AS13335 CLOUDFLARENET
Name Servers
2 server(s)
Page Load Time
750ms
Reputation & Reach
Sitemap
Not found
Social Media Presence
None found
Structured Data
None found
Tranco Rank
Not ranked
Trustpilot
No Trustpilot profile
Web Archive History
17 years
Website Status
Bot protection detected
robots.txt
Not found
Other
Content Source
Archive snapshot from 2025-11-29
Think this verdict is wrong?
Site owners can request a fresh scan. Scores update automatically as signals change.
If you've landed on gregharrelson.com and are wondering whether it's safe or a scam, the short answer is: there isn't enough information to give it a green light. The domain was registered back in 2006, which sounds reassuring at first β most fly-by-night sites don't stick around that long. But the site itself offers almost nothing by way of identification.