CanITrustThis

Methodology

How we decide what to tell you

Every report is built from evidence — measurable facts, detected warning signals, honest unknowns — and the score is computed by a deterministic algorithm, not by an AI's opinion. This page documents exactly how, generated from the same signal registry the scanner runs.

What we check

  • Domain history — registration and expiry dates via public RDAP registry data, registrar, privacy-proxy use, internationalized-name (homograph) risks, suspicious name patterns.
  • Technical & security — HTTPS and certificate validity (direct TLS inspection), redirect behavior, security headers, DNS mail configuration (MX, SPF, DMARC) via DNS-over-HTTPS.
  • Company identity — company details published on the site (imprint, contact, terms, privacy pages), cross-page consistency, contact quality, and verification against official registers: the Swiss Zefix index, UK Companies House, and EU VIES VAT validation. Jurisdictions without a supported register are reported as Unknown, never as negative.
  • Website consistency — essential policies, placeholder content, mixed currencies or languages, pressure tactics, copied legal text.
  • Reputation — independent web mentions, classified conservatively into counts of positive and negative experiences. Scored only when a search provider is configured; otherwise shown as ⚪ Unknown.
  • Offer plausibility — not scored yet; appears as ⚪ Unknown and is excluded from the score entirely rather than silently counted.

How the score works

Each finding maps to a signal with a fixed impact between −1 and +1 and a confidence factor (low 0.35, medium 0.7, high 1.0). Per category:

category = clamp(0.5 + Σ(impact × confidence × 0.35), 0, 1)
score    = weighted mean over evaluated categories × 100    (trust-score-v1)

0.5 is the neutral baseline. Categories with no evaluable signals are excluded from the weighted mean — an unknown never lowers a score. The algorithm version is stored with every scan so older reports remain interpretable.

Domain historyweight 15
Company identityweight 20
Reputationweight 20
Website consistencyweight 15
Offer plausibilityweight 15
Technical & security signalsweight 15

80100🟢 Strong trust signals

6079🟢 Generally trustworthy

4059🟡 Proceed with caution

2039🟠 Significant concerns

019🔴 High risk

Every signal we score

46 signals in trust-score-v1. Positive impacts add trust; negative impacts reduce it; zero-impact entries only document unknowns.

SignalCategoryImpact
DOMAIN_AGE_VERY_NEWDomain history-0.9
DOMAIN_AGE_NEWDomain history-0.5
DOMAIN_AGE_RECENTDomain history-0.2
DOMAIN_AGE_ESTABLISHEDDomain history+0.4
DOMAIN_AGE_MATUREDomain history+0.8
DOMAIN_EXPIRY_SOONDomain history-0.3
DOMAIN_IDN_HOMOGRAPHDomain history-0.7
DOMAIN_SUSPICIOUS_PATTERNDomain history-0.4
DOMAIN_PRIVACY_PROXYDomain history-0.1
DOMAIN_AGE_UNKNOWNDomain history0
HTTPS_MISSINGTechnical & security signals-1
CERT_INVALID_OR_EXPIREDTechnical & security signals-0.9
HTTPS_VALIDTechnical & security signals+0.6
CERT_ORG_VALIDATEDTechnical & security signals+0.4
REDIRECT_CHAIN_SUSPICIOUSTechnical & security signals-0.6
SECURITY_HEADERS_PRESENTTechnical & security signals+0.2
DNS_MX_MISSINGTechnical & security signals-0.2
DNS_SPF_DMARC_PRESENTTechnical & security signals+0.15
IDENTITY_COMPLETECompany identity+0.7
IDENTITY_PARTIALCompany identity+0.2
IDENTITY_MISSINGCompany identity-0.8
IDENTITY_INCONSISTENT_NAMESCompany identity-0.9
IDENTITY_VAT_FORMAT_VALIDCompany identity+0.3
IDENTITY_REG_NUMBER_PRESENTCompany identity+0.3
CONTACT_FREEMAIL_FOR_COMPANYCompany identity-0.3
CONTACT_PHONE_PRESENTCompany identity+0.15
IDENTITY_COPYRIGHT_MISMATCHCompany identity-0.4
IDENTITY_REGISTRY_VERIFIEDCompany identity+0.8
IDENTITY_REGISTRY_NOT_FOUNDCompany identity-0.5
IDENTITY_VAT_VERIFIEDCompany identity+0.4
IDENTITY_VAT_INVALIDCompany identity-0.5
IDENTITY_UNVERIFIED_NO_REGISTRYCompany identity0
REPUTATION_NO_MENTIONSReputation-0.2
REPUTATION_LIMITEDReputation-0.1
REPUTATION_ESTABLISHEDReputation+0.6
REPUTATION_MIXEDReputation-0.3
REPUTATION_NEGATIVE_PATTERNReputation-0.7
POLICY_PAGES_PRESENTWebsite consistency+0.5
POLICY_MISSING_ESSENTIALWebsite consistency-0.6
POLICY_COMPANY_MISMATCHWebsite consistency-0.8
CONTENT_PLACEHOLDER_TEXTWebsite consistency-0.7
CONTENT_MIXED_CURRENCY_LANGUAGEWebsite consistency-0.3
CONTENT_URGENCY_SCARCITYWebsite consistency-0.4
CONTENT_COPIED_LEGAL_TEXTWebsite consistency-0.3
CONTENT_STRUCTURE_PROFESSIONALWebsite consistency+0.3
CONTENT_ANALYSIS_UNAVAILABLEWebsite consistency0

Where AI is involved — and where it isn't

AI does

  • extract company details from page text
  • classify content red flags into fixed categories
  • describe visual patterns in images
  • write the plain-language summary

AI never

  • sets or adjusts the trust score
  • determines domain age, DNS or certificates
  • declares anything a scam
  • overrides collected evidence

AI-image analysis

“Is This AI?” verdicts follow a strict evidence hierarchy: cryptographically verified C2PA Content Credentials outrank generator metadata (Midjourney, Stable Diffusion, Firefly, DALL-E markers), which outrank coherent camera EXIF, which outranks visual observations by a vision model. Visual observations alone can never produce more than “Probably AI-generated” at medium confidence, and results are never presented as proof. Detector placeholders that are not configured are clearly marked and ignored by the verdict.

Limitations & independence

  • A high score is evidence-based reassurance, not a guarantee; a low score is a set of concerns, not an accusation.
  • Some registries (certain country domains) don't expose registration data — those lookups become Unknown, not negative.
  • Sites behind aggressive bot protection may only be partially analysable; reports say so explicitly.
  • Trust scores cannot be bought. There is no paid way to improve a score, and there never will be.
  • Site owners can dispute findings — contact us with verifiable documentation and we'll re-examine the evidence.