Is sec.gov legit?
This site appears highly trustworthy, demonstrating strong security and a well-established presence. The main areas for improvement are related to accessibility for automated checks which impacts our ability to verify transparency and compliance information.
Government average: 80/100 · based on 33 sites
Checked: April 27, 2026 at 5:56 AM UTC
Is sec.gov a scam? Here's what we found.
Excellent security measures are in place, including a valid SSL certificate with TLS 1.3, HSTS header, and a clean Google Web Risk report. The certificate issuer is reputable.
The domain is very old and well-established, registered through get.gov, indicating a legitimate government entity. The domain expiry is also reasonably far in the future.
The site has a very high Tranco rank, indicating significant traffic and recognition. It is clean on all DNS blacklists, reinforcing its strong reputation.
While the branding is basic, the primary concern here is the bot protection preventing checks on contact info and social media, which are important for transparency.
The inability to inspect legal pages due to bot protection is a drawback. However, as sec.gov, it's presumed to adhere to relevant regulations though verification is hindered.
The infrastructure is robust, with proper DNS resolution, DMARC for email authentication, and DNSSEC. The server uses Akamai, a reputable CDN, but the lack of a sitemap is a minor point.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
Valid certificate, expires in 89 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
This business has no Trustpilot presence — not unusual for smaller or newer companies
Resolves to: 2a02:26f0:480:5a1::17b2, 2a02:26f0:480:58c::17b2, 23.210.126.178
Mail servers: sec-gov.mail.protection.outlook.com.
Domain has DMARC email authentication configured
DNS providers: a1-32.akam.net., a3-67.akam.net., a6-64.akam.net., a7-65.akam.net., a18-65.akam.net., a20-66.akam.net.
crt.sh returned status 429
robots.txt has 70 directives and references a sitemap
Site enforces HTTPS via HSTS
Web server: AkamaiGHost
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
Domain created 1997-10-02T01:29:29Z (28 years, 11 months ago)
Registered through get.gov
Expires in 108 days
DNSSEC status from WHOIS
No sitemap found — common for smaller sites
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.