Is nature.com legit?
While nature.com benefits from a strong foundation as an aged domain with robust email and security configurations, its current inaccessibility is a significant concern that impacts its immediate usability and trustworthiness. Most of its underlying technical infrastructure appears sound.
News & Media average: 80/100 · based on 32 sites
Checked: April 21, 2026 at 9:01 PM UTC
Is nature.com a scam? Here's what we found.
The site has a valid SSL certificate with modern TLS 1.3, strong HSTS, and clickjacking protection. Google Web Risk confirms no threats, indicating a solid security posture despite not being able to fully check Certificate Transparency.
With over 31 years of age and registration through a corporate registrar, nature.com shows a very well-established and stable identity, suggesting a legitimate and long-standing organization.
The website's current unreachability is a major reputational blow, despite its high Tranco rank and clean DNS blacklists. This technical issue severely impacts user confidence and accessibility.
The lack of a favicon is a minor aesthetic and branding oversight, but the overall transparency (excluding deeper content analysis not provided) appears otherwise standard for an academic publisher.
No specific signals were provided to assess detailed compliance matters like privacy policies or cookie consent. However, for a site of this stature, general compliance is generally assumed to be in place.
The site benefits from robust DNS resolution, multiple email servers with DMARC, and a properly configured robots.txt and sitemap. The presence of unsigned DNSSEC is a minor point, but otherwise, the infrastructure is very well-configured.
Signals Detected
This is one of the most visited websites globally
Could not load website: Get "https://www.nature.com/nature?error=cookies_not_supported&code=a9f284a5-b241-43d8-8c65-71205ee17076": too many redirects
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1994-08-11T04:00:00Z (31 years, 1 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 110 days
DNSSEC status from WHOIS
Valid certificate, expires in 35 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Resolves to: 146.75.116.95
Mail servers: mxb-002c5801.gslb.pphosted.com., mxa-002c5801.gslb.pphosted.com.
Domain has DMARC email authentication configured
DNS providers: pdns1.ultradns.net., pdns2.ultradns.net., pdns3.ultradns.org., pdns4.ultradns.org., pdns5.ultradns.info., pdns6.ultradns.co.uk.
No favicon found — unusual for an established business
Site maintains a proper sitemap with 38834 indexed pages
robots.txt has 94 directives and references a sitemap
Site enforces HTTPS via HSTS
X-Frame-Options: DENY
Web server: Oscar Platform 0.2169.0
No threats detected by Google Web Risk
crt.sh returned status 502
Not found on any DNS blacklists
Could not query Wayback Machine
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.