Is jstor.org legit?
JSTOR is a highly trusted and established academic resource, backed by an impressive 30-year domain history and robust technical security. While it could improve on its upfront transparency with contact information and social media links, these are minor concerns for a site of its reputation.
Education average: 81/100 · based on 35 sites
Checked: April 18, 2026 at 8:12 AM UTC · Refresh
Is jstor.org a scam? Here's what we found.
Security is a strong point for JSTOR, boasting modern TLS encryption, a valid certificate from a reputable issuer, and a clean bill of health from Google Web Risk. This indicates a robust defense against common online threats.
The identity of JSTOR is exceptionally clear and well-established, with a domain age exceeding 30 years and clear registration through a recognized registrar. This long-standing presence speaks volumes about its legitimacy and stability.
JSTOR's reputation is excellent, evident from its high Tranco rank (indicating significant traffic), clean DNS blacklists, and decades of operation. It's a cornerstone of academic research, lending it immense credibility.
While the core purpose of JSTOR is clear, its transparency could be slightly improved. The absence of easily accessible contact information and social media links on the homepage makes it less straightforward for users to connect directly or stay updated outside of the platform.
The site has partial legal pages, missing either a privacy policy or terms of service, which is a noticeable gap for a platform handling user data and access. For an organization of its stature, robust legal documentation is expected.
JSTOR's infrastructure is solid, with resilient DNS resolution, proper email authentication (SPF and DMARC), and a fast page load speed. The minor sitemap misconfiguration doesn't detract significantly from an otherwise well-engineered foundation.
Signals Detected
This is a well-known, high-traffic website
Site uses structured data identifying itself as: WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Site has a favicon but no social sharing metadata
Valid certificate, expires in 135 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.3
robots.txt has 56 directives and references a sitemap
Sitemap URL returns non-XML content
Not found on any DNS blacklists
X-Frame-Options: DENY
Web server: envoy
No threats detected by Google Web Risk
Domain created 1996-02-16T05:00:00Z (30 years, 7 months ago)
Registered through Network Solutions, LLC
Expires in 1765 days
DNSSEC status from WHOIS
Resolves to: 151.101.128.152, 151.101.64.152, 151.101.192.152, 151.101.0.152
Mail servers: IthakaHarbors-org.mail.protection.outlook.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: usaeaz1ns03.ithaka.org., usnjpr2ns02.ithaka.org., usnjpr2ns01.ithaka.org., usnyny1ns05.ithaka.org., usaeaz1ns05.ithaka.org., usmiaa1ns03.ithaka.org., usnjpr2ns04.ithaka.org.
Website is live and responding
No obvious contact information found on homepage
Website is missing either privacy policy or terms of service
No social media links found on homepage
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.