Features
Every signal, shown — not just the number
A score you cannot interrogate is a score you cannot argue with. LegitSonar shows the reasoning behind every assessment: what was checked, what was found, and how much each finding moved the result.
The six criteria
What goes into a score
Every report breaks its number down the same six ways. No single criterion decides the outcome — a young domain with an impeccable certificate is still young.
-
Technical certificate
Whether TLS is present and valid, who issued it, and at what validation level. A certificate proving only domain control says far less than one where an authority checked that an organisation exists.
-
Reputation
Whether the domain appears on public blocklists and threat feeds. A single listing is a strong signal; the absence of one is not proof of anything.
-
Transparency
How much the operator discloses about itself — a registrant name, a company, an address, a working contact. Four fifths of the web now discloses none of it.
-
Popularity
Reach inferred from traffic signals and the patterns the scanner recognises. Obscurity is not guilt, but genuine businesses leave traces.
-
Domain history
Age, renewal depth and ownership stability. The single most informative signal there is: fraud is overwhelmingly a young business.
-
Findings balance
Positive findings weighed against negative ones, so a site with one flaw and nine strengths is not treated like a site with nine flaws.
Live analysis
Eight checks, a few seconds
Any domain can be analysed on the spot, whether or not it is already on file. The scanner resolves it, reads its registration, completes a TLS handshake and fetches the page — then scores what it found and adds it to the corpus.
- DNS and name servers
- WHOIS registration and registrar
- TLS certificate, issuer and validation level
- Hosting address and its neighbourhood
- Response time and redirect chain
- Registration age and renewal depth
- Blocklist and threat-feed presence
- Page metadata, forms and declared identity
The whole analysis runs against a time budget, so a slow or hostile server cannot hold it open. Private and internal addresses are refused outright — the scanner will not resolve a request to loopback or a private range, which stops it being used to probe networks it cannot see from the outside.
What you get
A report you can act on, keep, or quote
-
A score and a verdict
Out of 100, in one of five bands, with a sentence saying what it means rather than leaving you to interpret a number.
-
The findings, in plain language
Every positive and negative the analysis produced, written to be understood by someone who is not a network engineer.
-
The raw technical record
WHOIS, infrastructure, certificate and web presence, tabbed so the detail is there without burying the answer.
-
A PDF you can attach
The full analysis as a two-page document, dated and sourced — for a bank dispute, a moderation queue or a case file.
Coverage
What is already on file
607,303
Domains assessed
Across 753 address endings.
112,361
Flagged high risk
Already scored, already searchable.
< 1 s
To open a report
Any of them, from a single search box.
Free
All of it
No account, no limits worth mentioning, no advertising.
Try it on something you are unsure about
The fastest way to judge whether this is useful is to point it at a site you were already hesitating over.