Is lumen.com legit?
While lumen.com shows several strengths typical of an established online presence, a critical expired SSL certificate significantly undermines its trustworthiness. This major security flaw needs immediate attention before users can fully trust their interactions with the site.
Professional Services average: 81/100 · based on 22 sites
Checked: April 18, 2026 at 8:14 AM UTC · Refresh
Is lumen.com a scam? Here's what we found.
Security is severely compromised by an expired SSL certificate, meaning any data exchanged isn't properly encrypted. While other aspects like HSTS and CSP are good, this single flaw is a major red flag for user safety.
The site boasts a very long-standing domain, over three decades old, indicating a well-established entity. The use of a corporate registrar further supports a legitimate business identity, rather than a fleeting operation.
With moderate global traffic and a clean record on DNS blacklists, the site maintains a generally positive and untarnished reputation. The lack of a Trustpilot profile is not unusual for a company of this type, which often engages directly with business clients.
The site provides clear contact information and has a decent presence across multiple social media platforms, suggesting a willingness to engage publicly. Its custom branding also adds to its apparent legitimacy.
Compliance is good in some areas with elements like DMARC and SPF, but the missing legal pages (either a privacy policy or terms of service) are a notable gap that could expose users to uncertainty about data handling or service terms.
The site's infrastructure is generally robust, showing multiple IP addresses for resilience and proper email authentication. Fast page load times also contribute to a smooth user experience. The DNSSEC, though unsigned, is not uncommon for very large, older domains.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1994-08-05T04:00:00Z (31 years, 1 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 107 days
DNSSEC status from WHOIS
Excessive number of external scripts — may indicate malicious injection
Not found on any DNS blacklists
robots.txt has 5 directives and references a sitemap
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
No threats detected by Google Web Risk
SSL certificate is invalid: tls: failed to verify certificate: x509: certificate has expired or is not yet valid: current time 2026-04-18T08:13:50Z is after 2025-08-21T23:59:59Z
Issued by DigiCert Inc (but certificate is invalid)
Resolves to: 2001:428:b21:16:155:70:66:10, 2001:428:b20:16:155:70:118:10, 151.101.3.10, 151.101.67.10, 151.101.135.10, 151.101.131.10, 151.101.195.10
Mail servers: mxb-007e5801.gslb.pphosted.com., mxa-007e5801.gslb.pphosted.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: authns1.qwest.net., authns2.qwest.net.
Site has custom branding and social media metadata
No sitemap found — common for smaller sites
Could not query Wayback Machine
Could not query certificate transparency logs
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.