Verdict
aagofoundation.org is low-trust and potentially risky.
Several risk patterns were present. Do not send money or personal details until you have verified this business another way.
| What this site appears to be | Public-facing foundation website for the AAGO Foundation, Inc. Provides information about charity partners, scholarship, events, contact details, and donation options. Contains address and phone contact details and user actions like Donate and Login. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 2 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 13 years oldRegistered history | Clear |
| Web archive | Archived since 2013Public history exists | Clear |
| Certificate | Encrypted connectionIssued by GeoTrust TLS RSA CA G1 | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 2013.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Overview
This website presents itself as the public site of AAGO Foundation, Inc., a nonprofit foundation associated with the Apartment Association of Greater Orlando. It promotes charity partnerships, scholarships, events, volunteering, merchandise, donations, and account login, with an apparent business model based on donor contributions and related activities.
Scam/Impersonation Risk
No conflicting legal-entity names or detected brand-impersonation indicators were observed in the supplied page analysis. However, the site is subject to a confirmed blacklist signal from multiple external sources, including two malicious detections, which is a material contradiction to the otherwise coherent charity presentation. Browser observation also identified unusually dynamic page changes, substantial external communications, and non-whitelisted requests after interaction; these findings do not establish malicious intent on their own, but they materially increase the risk associated with login, credentials, donations, and other sensitive actions.
- The homepage identifies “AAGO Foundation, Inc.” and presents donation, login, scholarship, event, and charity-partner functions; the page analyzer recorded no content red flags or suspected brand impersonation.
- External reputation checks recorded 2 malicious detections and a confirmed blacklist result; a separate broad reputation check did not record a malicious result.
- Browser behavior recorded 32 external XHR requests, 16 external POST requests, 6 non-whitelisted XHR requests, and 6 non-whitelisted POST requests; the largest observed external-activity proportion was 90%.
- Domain registration records show registration on 2013-04-23, approximately 13.33 years of age, through GoDaddy.com, LLC, with expiry on 2028-04-23; archive records show 73 snapshots spanning 2013–2026, across 14 tracked years.
Regulatory Verification Notes
The site provides substantive charity-oriented content, including board, governance, charity-partner, scholarship, contact, and event pages. Its long-established registration, multi-year archival presence, coherent organizational content, reputable registrar, and valid mainstream TLS provide affirmative evidence of an established web presence. Nevertheless, the real-world operator identity remains unverified, governance and ownership transparency are incomplete in the available evidence, and the supplied pages do not state a license or registration number. That is a verification gap rather than, by itself, proof of fraud. The external blacklist result remains a serious reputational signal, while the absence of a broker-specific match provides no regulatory authorization or safety determination.
- The governance and identity navigation exposes board, governance, charity-partner, scholarship, contact, and meeting-schedule pages, but no license or registration number is stated in the supplied site content.
- The website is served from AS8075, Microsoft Corporation, United States.
- The site’s TLS certificate is issued by GeoTrust TLS RSA CA G1 at DV validation level and is valid through 2026-11-07.
- The homepage’s content analysis classified the site as a charity/foundation and recorded a page risk score of 0.15, with no detected sensitive form destination or hidden form.
What to Verify Next
Before any donation or account interaction, an independent party should confirm that AAGO Foundation, Inc. is the legal charitable entity intended to receive funds and that the relevant charitable-solicitation or nonprofit registration requirements are satisfied. The organization’s board and governance information should be cross-checked against an independently obtained institutional contact route, and payment processing should be confirmed to use a recognized provider with appropriate donor protections. Credentials should not be reused on this site, and any request for unusual payment methods or additional identity information should be independently validated before proceeding.
- The site’s governance and board pages provide named organizational areas that can be cross-checked against an official registry or independently sourced organizational records.
- The contact page and homepage provide the primary channels for comparison against contact details obtained through an offline or independently verified route.
- The donation and login functions create sensitive interaction points requiring separate validation of recipient identity, payment handling, and account-security practices.
Summary Verdict
The overall posture is low trust with elevated sensitive-interaction risk. The website has characteristics of a mature, coherent nonprofit information portal, but those legitimacy-consistent signals are outweighed by confirmed external threat detections and unresolved operator-verification concerns. Passive review may be appropriate, but the available evidence does not support treating sensitive interactions as trustworthy.
Infrastructure Integrity
The site is protected by a CDN/WAF layer, with observed edge infrastructure on AS8075 operated by Microsoft Corporation; the origin server was not observable in this analysis. This provides a mitigating layer against direct origin exposure, but it does not validate the site’s identity or offset the external reputation concerns.
Closing Assessment
Prospective users should restrict engagement to independently validated, low-sensitivity activity until the organization, recipient of funds, and payment path have been confirmed through trusted external channels.
Written analysis generated 2026-08-20 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - The page sent data to a destination TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_POSTS - The page rewrote itself after it was interacted with, so what a visitor first sees is not what they end up on.Behaviour in a sandbox
rule:BEHAV_DOM_DIFF_AFTER_INTERACTION - Most of what the page loaded came from other domains rather than from this one.Behaviour in a sandbox
rule:BEHAV_EXTERNAL_RATIO_HIGH - The page exchanged network traffic with destinations TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_TRAFFIC - The page made background requests to destinations TrustSniffer does not recognise.Behaviour in a sandbox
rule:BEHAV_NONWHITELISTED_XHR - The structure of the page changed sharply while it was loading.Behaviour in a sandbox
rule:BEHAV_DOM_DENSITY_SPIKE - The page replaced a large part of its own content after loading.Behaviour in a sandbox
rule:BEHAV_DOM_CHANGE_HIGH
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 30/100 |
| Identity verification confidence | 50% |
- No on-site identity signals detected
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of aagofoundation.org.
- The request stayed on aagofoundation.org. It was not redirected to another domain. Clear
- Registration is published under GoDaddy.com, LLC. Clear
- DNS for this domain is served by domaincontrol.com, across 2 name servers. Noted
- The registration is paid up to 2028-04-23. Clear
- The earliest public archive of this site is from 2013-08-23. Clear
- It is hosted on MICROSOFT-CORP-MSN-AS-BLOCK, from a server in US. Noted
Domain intelligence
| Registrar | GoDaddy.com, LLC |
|---|---|
| Hosting | MICROSOFT-CORP-MSN-AS-BLOCK - Microsoft Corporation, US |
| Country | US |
| Server IP | 2620:1ec:46::53 |
| Name servers | ns45.domaincontrol.com, ns46.domaincontrol.com |
| SSL issuer | GeoTrust TLS RSA CA G1 |
| SSL expiry | 2026-11-07 |
| Domain age | 13.33 years (continuous registration) |
| Domain expiry | 2028-04-23 |
| Archive first seen | 2013-08-23 |
| Archive snapshots | Not counted (archive lookup incomplete) |
| Reputation | VirusTotal: 2 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about aagofoundation.org at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.