Is reshot.com legit?
This site is mostly safe, but users should use caution due to its redirection away from the original service and short domain expiry. The site seems to be in a state of transition with the original 'Reshot' service having retired.
Stock Media average: 78/100 · based on 31 sites
Checked: April 27, 2026 at 1:09 PM UTC
Is reshot.com a scam? Here's what we found.
The security posture is strong with modern TLS 1.3, an SSL certificate issued by Google, and present HSTS and Clickjacking protection. No threats were detected by Google Web Risk, indicating a safe browsing experience.
While the domain is very old (20 years) and registered with a reputable registrar (MarkMonitor), the short domain expiry of 47 days is a moderate concern. The DNSSEC is unsigned, which is a minor gap.
The redirect to an announcement about 'Reshot retiring' significantly impacts its operational reputation, suggesting it's no longer performing its original function. However, the site is not on any DNS blacklists.
Bot protection prevented checks for contact info, legal pages, and social media, making it difficult to assess transparency. The lack of a favicon is a minor cosmetic issue.
Bot protection prevented checking for legal pages, making it impossible to assess compliance. This is a neutral finding, not necessarily a negative one, but it prevents a high score.
The site benefits from good DNS resolution provided by Cloudflare with SPF and DMARC records for email authentication. The presence of a robots.txt file further indicates good site management, despite a misconfigured sitemap.
Signals Detected
This site appears in the top 1 million websites
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2005-06-13T18:23:45Z (20 years, 2 months ago)
Registered through MarkMonitor Inc.
Expires in 47 days
DNSSEC status from WHOIS
Valid certificate, expires in 56 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Resolves to: 104.18.5.234, 104.18.4.234
No MX records found — domain may not handle email
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: eleanor.ns.cloudflare.com., karl.ns.cloudflare.com.
crt.sh returned status 429
Sitemap URL returns non-XML content
robots.txt has 603 directives
No favicon found — unusual for an established business
Site redirects to https://elements.envato.com/learn/reshot-retiring
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.