Is nginx.com legit?
This site is trusted, showcasing robust infrastructure and good security practices overall. However, the excessive number of external scripts and incomplete legal pages are areas that could be improved.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 21, 2026 at 1:21 PM UTC
Is nginx.com a scam? Here's what we found.
The site uses modern TLS 1.3 encryption, has a valid SSL certificate, and is not flagged by Google Web Risk, indicating a generally secure connection. The high number of external scripts, however, presents a potential attack vector.
With a domain age of over 21 years and complete branding, there's clear evidence of a well-established and transparent identity. The domain registrar is also a reputable corporate registrar.
The highly ranked Tranco position and clean DNS blacklists contribute to a strong reputation. However, the redirection away from the primary domain could mildly impact user trust and consistency.
The site provides clear contact information and has a strong social media presence, which are good indicators of transparency. The lack of structured data, while not a deduction, means some information isn't as readily machine-readable.
The partial legal pages are a notable concern, as a complete set of legal documents like a privacy policy and terms of service is crucial for user trust and regulatory compliance, especially for a business website of this stature.
Solid infrastructure is evident with proper email authentication (SPF, DMARC), responsive DNS resolution, and the consistent enforcement of HTTPS via HSTS. The misconfigured sitemap is a minor drawback.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2004-12-23T13:03:30Z (21 years, 7 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 245 days
DNSSEC status from WHOIS
Excessive number of external scripts — may indicate malicious injection
Valid certificate, expires in 40 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Resolves to: 159.60.134.0
Mail servers: mx2.hc5801-97.iphmx.com., mx1.hc5801-97.iphmx.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns2.f5clouddns.com., ns1.f5clouddns.com.
Site has custom branding and social media metadata
robots.txt has 17 directives
Site redirects to https://www.f5.com/products/nginx
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
Web server: volt-adc
No threats detected by Google Web Risk
Sitemap URL returns non-XML content
crt.sh returned status 502
Not found on any DNS blacklists
Could not query Wayback Machine
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.