Website security intelligenceHigh confidence

Is cisa.gov safe?

Independent website safety report covering the connection, domain history, browser protections, page behavior and reputation signals observed by DarkOra.

https://www.cisa.gov/ HTTP 200
Last analyzedJuly 26, 2026
Evidence collected30 signals
Scan duration2,851 ms
REPORT OVERVIEW

What the latest scan says about cisa.gov

DarkOra separates technical evidence from community opinion and explains the factors behind the score.

Assessment summary

The scan found a broad set of mature technical, behavioural and transparency signals. Its TLS certificate was valid at scan time. Registration records show the domain has existed for more than two years. The accessible homepage exposed a contact route and linked policy or company information. Confidence is high based on 7 distinct evidence groups collected during the latest scan. The result is a risk assessment, not proof that cisa.gov is legitimate or fraudulent.

26Positive factors
4Caution factors
30Total signals
ConnectionHTTPS

Valid TLS certificate observed

Domain history7.6 years

get.gov

Browser hardening50%

3 of 6 monitored headers

Independent gradeB

MDN HTTP Observatory result

CAPTURED HOMEPAGE

Visual snapshot from the scan

https://www.cisa.gov/
Screenshot of cisa.gov captured during the latest DarkOra website safety scan
KEY FINDINGS

Evidence that influenced the score

Review both columns. A high total score does not cancel a material caution signal.

POSITIVE FACTORS

Signals that support trust

26

Valid TLS certificate

The certificate is trusted, matches the hostname and is currently valid.

TLS · transport · +7 points

HTTPS is active

The final page is delivered through an encrypted HTTPS connection.

Transport · transport · +4 points

Long-established domain registration

Registration records indicate an age of about 7 years.

RDAP · domain · +4 points

Website responded successfully

The scanned destination returned HTTP 200.

HTTP · transport · +3 points

Domain email controls are published

The domain exposes multiple mail-routing or anti-spoofing controls.

DNS · domain · +2 points

HSTS is present

The response includes the strict-transport-security header.

Security headers · security · +2 points

Contact route found

The page exposes a contact or support page, an email link, a telephone link.

Content · transparency · +2 points

security.txt is available

A security contact file was found under .well-known.

Public files · transparency · +2 points

Normal homepage content was accessible

The scanner received a usable HTML homepage rather than an interstitial or access-control page.

Content · behavior · +2 points

No monitored high-risk wording detected

The accessible homepage did not contain the monitored high-pressure or credential-request phrases.

Content · behavior · +2 points

Responsive origin server

The initial request completed in about 105 ms.

Performance · transport · +1 points

Public DNS resolution

The domain resolves to 3 validated public network addresses.

DNS · domain · +1 points

Nameserver redundancy

At least two authoritative nameservers were found.

DNS · domain · +1 points

DNSSEC validation confirmed

Google Public DNS returned authenticated DNS data for this hostname.

Google Public DNS · domain · +1 points

Public routing identity found

RIPEstat mapped the address to AS16625 and prefix 23.222.32.0/19.

RIPEstat · domain · +1 points

MIME sniffing protection is present

The response includes the x-content-type-options header.

Security headers · security · +1 points

Clickjacking protection

Framing is restricted through X-Frame-Options or CSP.

Security headers · security · +1 points

HSTS preload list entry

The hostname is included in Chromium’s HSTS preload status data.

Chromium HSTS Preload · security · +1 points

Good MDN Observatory grade

MDN HTTP Observatory assigned grade B.

MDN HTTP Observatory · security · +1 points

Descriptive page title

The homepage provides a usable browser title.

Content · transparency · +1 points

Page description is provided

The homepage includes a descriptive meta summary.

Content · transparency · +1 points

Some policy information is linked

At least one policy or company-information page was found.

Content · transparency · +1 points

robots.txt is available

The website publishes a non-empty robots.txt file.

Public files · transparency · +1 points

Substantive homepage content

The scanned page contains enough readable text to explain its purpose.

Content · transparency · +1 points

Consistent canonical redirect

Redirects remain within the same domain family.

HTTP · behavior · +1 points

Canonical URL declared

The page declares a canonical destination.

Content · transparency
CAUTION FACTORS

Signals worth reviewing

4

Hidden embedded frames detected

1 hidden or zero-sized iframe was found.

Content · behavior · -6 points

Missing content-security-policy

The response did not include this browser security header. Missing headers affect hardening, but do not by themselves prove fraud.

Security headers · security · -1 points

Missing referrer-policy

The response did not include this browser security header. Missing headers affect hardening, but do not by themselves prove fraud.

Security headers · security

Missing permissions-policy

The response did not include this browser security header. Missing headers affect hardening, but do not by themselves prove fraud.

Security headers · security
TECHNICAL EVIDENCE

Network, certificate and page-level observations

These values were captured at scan time and may change after a server, DNS or certificate update.

NETWORK & DNS

Infrastructure footprint

Resolved IP addresses
23.218.59.210, 2a02:26f0:e200:79b::3ff9, 2a02:26f0:e200:7a9::3ff9
Authoritative nameservers
3
Mail / MX records
2
CAA policy
Not found
SPF policy
Published
DMARC policy
Published
HTTPS & TLS

Connection security

HTTP status
200
Final protocol
HTTPS
Certificate validation
Trusted and valid
Certificate issuer
TLS protocol / cipher
TLSv1.3 TLS_AES_256_GCM_SHA384
Certificate expires
September 22, 2026
DOMAIN RECORD

Registration context

Approximate age
7.6 years
Registered
December 6, 2018
Expires
November 4, 2026
Registrar
get.gov
RDAP status entries
1
RDAP available
Yes
BROWSER SECURITY HEADERS

3/6 monitored protections detected

50%
HSTSmax-age=31536000 ; includeSubDomains
Content Security PolicyNot detected
X-Frame-OptionsSAMEORIGIN
X-Content-Type-Optionsnosniff
Referrer-PolicyNot detected
Permissions-PolicyNot detected
INDEPENDENT SIGNALS

External security and reputation context

Provider failures stay separate from the base scan. DarkOra never fabricates a provider result.

GOOGLE PUBLIC DNSValidated

DNSSEC authenticated data

The AD flag confirms that the DNS answer was validated through DNSSEC.

Response code 0 · 2 answers
MDN HTTP OBSERVATORYB

Independent header grade

MDN evaluated the live HTTP security configuration independently from DarkOra.

70 points · 8/10 tests passed
CHROMIUM HSTS PRELOADPreloaded

Preload-list status

Browsers can enforce HTTPS before the first network request.

Independent transport-hardening context
RIPESTAT NETWORKAS16625

Routing and origin identity

The scanned address maps to prefix 23.222.32.0/19.

BGP present · registry present
GOOGLE WEB RISK

Official threat-list context

The optional official Web Risk integration is not configured.

Checked Jul 27, 2026
TRUSTPILOT

Official profile lookup

Trustpilot requires an official API key. DarkOra does not scrape profile pages.

Open Trustpilot profile
HTTP DELIVERY

Response and redirect details

Origin address used
23.222.48.153
Server header
Content type
text/html; charset=utf-8
Downloaded response
71,375 bytes
Redirect hops
1
Initial response time
105 ms
CONTENT FOOTPRINT

What the homepage exposes

Internal links
131
External links
16
External-link ratio
11%
Forms detected
0
Suspicious phrase groups
0
Scanner methodology
Version 4.0.0
REPORT GUIDANCE

Questions about this website safety report

Plain-language answers explain what the score can and cannot tell you.

Is cisa.gov safe to visit?+

The scan found a broad set of mature technical, behavioural and transparency signals. Its TLS certificate was valid at scan time. Registration records show the domain has existed for more than two years. The accessible homepage exposed a contact route and linked policy or company information. Confidence is high based on 7 distinct evidence groups collected during the latest scan. The result is a risk assessment, not proof that cisa.gov is legitimate or fraudulent.

What is the DarkOra score for cisa.gov?+

The latest DarkOra website safety score is 84 out of 100, classified as Strong trust signals. The score reflects observable technical and reputation evidence collected during the latest scan.

How is this website safety score calculated?+

DarkOra uses six independently capped areas: connection and TLS, domain maturity and DNS, browser security, identity and transparency, page behavior, and external reputation. No single signal determines the entire score.

When was cisa.gov last checked?+

The report was last updated on July 26, 2026. Website, DNS and certificate settings can change after this time.

Does a high score prove that cisa.gov is legitimate?+

No. Automated evidence can reduce uncertainty, but it cannot prove ownership, product quality or honest intent. Verify the organization, payment destination, refund terms and independent reputation before sharing sensitive information.

COMMUNITY EXPERIENCE

Reviews from DarkOra members

Account-linked reviews are screened for spam and published only after manual moderation.

No approved community review yet

Be the first member to describe a direct experience with this website.

SHARE A DIRECT EXPERIENCE

Write a review

Use this report as one part of your decision. Automated checks can miss newly created threats and may flag legitimate configurations. Verify the organization, payment recipient, refund terms and independent reputation before sharing money, credentials or sensitive data.