Is medium.com legit?
Medium.com is a trusted platform with a strong technical foundation and established web presence. While some automated checks were hampered by bot protection, the core elements of security, identity, and infrastructure are solid, making it a reliable destination.
News & Media average: 80/100 · based on 32 sites
Checked: April 21, 2026 at 4:32 PM UTC
Is medium.com a scam? Here's what we found.
The site employs strong security measures including TLS 1.3, HSTS, and a Content Security Policy, and is clean according to Google Web Risk. The inability to check Certificate Transparency is a minor informational gap.
With a domain aged over 27 years and a clear expiry date, Medium demonstrates a well-established and stable identity. The use of Amazon Registrar is also common and reputable.
Its extremely high Tranco Rank and clean DNS blacklist status solidify Medium's strong reputation. The inability to check archival history is a minor setback but doesn't detract from its known status.
While legal pages are present, the bot protection prevented comprehensive checks on contact info and social media, and the basic branding could be improved for better user trust signals.
The presence of both Privacy & Terms pages indicates a commitment to basic legal compliance. No specific issues were found in this area.
The robust infrastructure includes multiple IP addresses for DNS resolution, well-configured email authentication (SPF, DMARC), and Cloudflare for DNS and server management, all contributing to reliability and security.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 50 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Domain created 1998-05-27T04:00:00Z (27 years, 3 months ago)
Registered through Amazon Registrar, Inc.
Expires in 399 days
DNSSEC status from WHOIS
Resolves to: 2606:4700:7::a29f:9804, 2606:4700:7::a29f:9904, 162.159.153.4, 162.159.152.4
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: alina.ns.cloudflare.com., kip.ns.cloudflare.com.
Site has a favicon but no social sharing metadata
robots.txt has 39 directives and references a sitemap
crt.sh returned status 502
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
Web server: cloudflare
No threats detected by Google Web Risk
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Website has both privacy policy and terms of service pages
Bot protection prevented page inspection
Site maintains a proper sitemap with 27205 indexed pages
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.