Is nih.gov legit?
This site is highly trusted, demonstrating a robust security posture and long-standing online presence. While it's missing some legal documentation, the overall picture is overwhelmingly positive.
Government average: 80/100 · based on 33 sites
Checked: April 21, 2026 at 3:46 PM UTC
Is nih.gov a scam? Here's what we found.
Excellent security measures are in place, including a valid SSL certificate with modern TLS, HSTS, Content Security Policy, and reliable clickjacking protection. Google Web Risk also confirms no immediate threats.
The domain has an exceptionally long history, being nearly three decades old. Its registration through the .gov domain indicates a clear government affiliation, which adds significant credibility.
With a top global Tranco rank and a clean DNS blacklist record, this website possesses a strong and established reputation. Its age further reinforces its authority and trustworthiness.
The site provides clear contact information and has an active presence across multiple social media platforms, indicating a commitment to user engagement and accessibility. The branding is professional and complete.
While displaying robust security and clear identity, the site has a partial legal page setup, which is a minor but notable area for improvement in terms of full compliance.
The infrastructure is well-maintained with DNSSEC enabled, proper DMARC email authentication, and a comprehensive sitemap. These elements contribute to a reliable and secure technical foundation.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 300 days
Certificate issued by GoDaddy.com, Inc.
Connection uses TLS 1.2
Domain created 1997-10-02T01:29:27Z (28 years, 11 months ago)
Registered through get.gov
Expires in 122 days
DNSSEC status from WHOIS
robots.txt has 53 directives
Site has custom branding and social media metadata
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Resolves to: 156.40.212.210
Mail servers: nihcesxwayst03.hub.nih.gov., nihcesxway4.hub.nih.gov., nihcesxwayst05.hub.nih.gov., nihcesxwayst04.hub.nih.gov., nihcesxwayst06.hub.nih.gov., nihcesxway5.hub.nih.gov., nihcesxway3.hub.nih.gov., nihcesxway6.hub.nih.gov.
Domain has DMARC email authentication configured
DNS providers: ns.nih.gov., ns2.nih.gov., ns3.nih.gov.
Site maintains a proper sitemap with 2594 indexed pages
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
crt.sh returned status 404
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.