Is reshot.com legit?
You should use caution with reshot.com. While the domain has a long history and strong technical security, the complete lack of contact information, essential legal pages like a privacy policy, and the website's inaccessible status are significant concerns.
Stock Media average: 74/100 · based on 31 sites
Checked: April 18, 2026 at 11:26 AM UTC · Refresh
Is reshot.com a scam? Here's what we found.
While the site uses modern encryption (TLS 1.3) and has clickjacking protection, the critical issue of the website returning a 403 status means it's currently inaccessible, which is a major security and usability barrier.
Reshot.com boasts a strong 20-year domain age, suggesting a historical presence. However, the rapidly approaching domain expiry (56 days) could indicate the site is being phased out or neglected.
The site isn't flagged by Google Web Risk or DNS blacklists, which is positive. Its moderate Tranco rank suggests some level of traffic or recognition, but the inaccessible status could affect its future standing.
This is a major weak point. The complete absence of contact information, social media links, and a favicon makes it nearly impossible to understand who operates the site or how to get support, which is very concerning for users.
The explicit lack of both a privacy policy and terms of service is a severe compliance issue. Without these, users have no idea how their data is handled or what the site's rules of engagement are.
The site benefits from Cloudflare's infrastructure, employs SPF and DMARC for email authentication, and has good DNS resolution. However, the absence of MX records suggests it doesn't handle emails directly, which can be normal but is worth noting.
Signals Detected
This site appears in the top 1 million websites
No structured data markup found
No favicon found — unusual for an established business
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2005-06-13T18:23:45Z (20 years, 1 months ago)
Registered through MarkMonitor Inc.
Expires in 56 days
DNSSEC status from WHOIS
No sitemap found — common for smaller sites
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
crt.sh returned status 429
Valid certificate, expires in 65 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
No robots.txt file — common for small sites
Website returned status 403
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
Resolves to: 104.18.4.234, 104.18.5.234
No MX records found — domain may not handle email
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: karl.ns.cloudflare.com., eleanor.ns.cloudflare.com.
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.