Is kottke.org legit?
kottke.org appears to be a mostly safe and long-standing personal blog, showing a strong technical foundation and good overall reputation. The main area for improvement is the absence of key legal documents like a privacy policy, which is a common oversight for personal sites but still important for user trust.
Personal Blog average: 74/100 · based on 25 sites
Checked: April 18, 2026 at 11:31 AM UTC · Refresh
Is kottke.org a scam? Here's what we found.
The site boasts a robust security posture with a valid SSL certificate, modern TLS 1.3 encryption, and strong HTTP Strict Transport Security enforcement, ensuring data exchanged is protected. Crucially, Google Web Risk detected no threats, which is a strong indicator of safety.
With a domain age stretching back over 27 years, kottke.org has a deeply established online identity. The domain registration is current and publicly visible, indicating transparency about its ownership and longevity.
Its moderate global traffic ranking and clean status on all DNS blacklists suggest a sound reputation, further bolstered by its long history on the internet. This indicates consistent activity and a lack of association with malicious practices.
The site provides clear contact information and maintains an active presence across multiple social media platforms, making it easy for users to engage or reach out. The use of custom branding also reinforces its distinct identity.
While the site is technically sound, the absence of a privacy policy and terms of service is a notable transparency and compliance gap. Even for a personal blog, these documents are good practice for user understanding and legal clarity.
The site's infrastructure is well-configured, utilizing robust DNS and email authentication technologies like SPF and DMARC, which helps prevent email spoofing. Cloudflare's involvement as a DNS provider also indicates a focus on performance and reliability.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: WebSite
robots.txt has 19 directives and references a sitemap
This business has no Trustpilot presence — not unusual for smaller or newer companies
Site has custom branding and social media metadata
Valid certificate, expires in 74 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Resolves to: 2606:4700:3031::ac43:beb0, 2606:4700:3032::6815:2456, 172.67.190.176, 104.21.36.86
Mail servers: ASPMX.L.GOOGLE.COM., ALT2.ASPMX.L.GOOGLE.COM., ALT1.ASPMX.L.GOOGLE.COM., ASPMX4.GOOGLEMAIL.COM., ASPMX3.GOOGLEMAIL.COM., ASPMX2.GOOGLEMAIL.COM.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: kenia.ns.cloudflare.com., hugh.ns.cloudflare.com.
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Site maintains a proper sitemap with 32 indexed pages
Not found on any DNS blacklists
Domain created 1998-12-26T05:00:00Z (27 years, 8 months ago)
Registered through Domain.com - Network Solutions, LLC
Expires in 616 days
DNSSEC status from WHOIS
Website is live and responding
Website appears to have contact information
No privacy policy or terms of service found
Website links to multiple social media platforms
Could not query Wayback Machine
Could not query certificate transparency logs
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.