Is windows.com legit?
This site is Mostly Safe, mostly due to its strong underlying infrastructure and decades-long history. However, the critical issue of the website being unreachable and excessively redirecting is a significant concern that impacts user experience and trust.
Software & Downloads average: 80/100 · based on 75 sites
Checked: April 27, 2026 at 8:42 AM UTC
Is windows.com a scam? Here's what we found.
While the SSL certificate is valid and uses modern TLS 1.3, the site's fundamental unreachability due to redirect loops is a severe security and accessibility problem that cannot be ignored.
The domain boasts an impressive 30-year age and is registered through a reputable corporate registrar, clearly establishing a long-standing and legitimate identity.
Backed by an extremely high Tranco rank and clean DNS blacklists, the site has a strong reputation, though the imminent domain expiry is a minor red flag.
The absence of a Trustpilot profile and favicon are minor omissions, though the core identity behind the site (Microsoft) is globally recognized and transparently linked.
With no robots.txt or sitemap, these are minor gaps common for redirector sites; no direct compliance red flags are present given the nature of the domain redirecting.
Robust DNS resolution and excellent email authentication (SPF, DMARC) point to a well-maintained backend, though the aggressive redirect policy is a notable functional issue.
Signals Detected
This is one of the most visited websites globally
Could not load website: Get "https://www.microsoft.com/en-gb/windows/": too many redirects
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1995-09-11T04:00:00Z (30 years, 0 months ago)
Registered through MarkMonitor Inc.
Expires in 38 days
DNSSEC status from WHOIS
Resolves to: 2603:1010:3:3::5b, 2603:1030:20e:3::23c, 2603:1030:c02:8::14, 2603:1030:b:3::152, 2603:1020:201:10::10f, 20.70.246.20, 20.112.250.133, 20.231.239.246, 20.76.201.171, 20.236.44.162
Mail servers: mail.windows.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns1-205.azure-dns.com., ns2-205.azure-dns.net., ns3-205.azure-dns.org., ns4-205.azure-dns.info.
Valid certificate, expires in 132 days
Certificate issued by Microsoft Corporation
Connection uses TLS 1.3
No favicon found — unusual for an established business
crt.sh returned status 502
Site redirects to https://www.microsoft.com/en-de/windows/
Site enforces HTTPS via HSTS
Web server: AkamaiNetStorage
No threats detected by Google Web Risk
No robots.txt file — common for small sites
No sitemap found — common for smaller sites
Could not query Wayback Machine
Not found on any DNS blacklists
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.