Is windows.com legit?
While `windows.com` belongs to a globally recognized brand and has strong underlying infrastructure, significant technical issues are currently preventing access, which is a major concern. The very short domain expiry and low Trustpilot score, though from limited data, also warrant attention.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 12, 2026 at 9:03 PM UTC · Refresh
Is windows.com a scam? Here's what we found.
The site uses modern encryption (TLS 1.3) with a valid certificate from Microsoft itself, along with HSTS, ensuring a secure connection when it is accessible. Google Web Risk also confirms no immediate threats.
This domain has a long, established history of 30 years and is registered by the reputable MarkMonitor Inc., clearly identifying it with Microsoft. However, the rapidly approaching domain expiry is an unusual and concerning detail for such a high-profile asset.
Being one of the world's most visited sites inherently provides a strong reputation, and it's clean on DNS blacklists. However, the current unreachability due to redirects severely impacts user experience and trust, compounded by a very low Trustpilot rating.
As a major corporation, the assumed transparency of Microsoft is high despite the limited direct signals here. The missing favicon is a minor oversight for a brand of this scale.
While no specific compliance signals are provided, a company like Microsoft is expected to adhere to global compliance standards, and its broad web presence implies a strong legal framework.
The DNS setup is robust with multiple IP addresses and name servers, indicating reliability. Email authentication (SPF and DMARC) is properly configured, minimizing email spoofing risks.
Signals Detected
Could not load website: Get "https://www.microsoft.com/en-gb/windows/": too many redirects
This is one of the most visited websites globally
Domain created 1995-09-11T04:00:00Z (30 years, 0 months ago)
Registered through MarkMonitor Inc.
Expires in 52 days
DNSSEC status from WHOIS
Resolves to: 2603:1030:b:3::152, 2603:1010:3:3::5b, 2603:1030:20e:3::23c, 2603:1020:201:10::10f, 2603:1030:c02:8::14, 20.231.239.246, 20.70.246.20, 20.236.44.162, 20.112.250.133, 20.76.201.171
Mail servers: mail.windows.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns1-205.azure-dns.com., ns2-205.azure-dns.net., ns3-205.azure-dns.org., ns4-205.azure-dns.info.
crt.sh returned status 429
Valid certificate, expires in 146 days
Certificate issued by Microsoft Corporation
Connection uses TLS 1.3
Trustpilot rating: 1.7/5 based on 19 reviews
Not found on any DNS blacklists
No favicon found — unusual for an established business
Site redirects to https://www.microsoft.com/windows
Site enforces HTTPS via HSTS
Web server: AkamaiNetStorage
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
No robots.txt file — common for small sites
Could not query Wayback Machine
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.