Verdict
amucta.ac.tz is low-trust and potentially risky.
Several risk patterns were present. Do not send money or personal details until you have verified this business another way.
| What this site appears to be | Official website for Archbishop Mihayo University College of Tabora (AMUCTA). Contains institutional information, program listings, admissions instructions, news, publications, student services, contact details, and downloads. Appears to be a legitimate academic site with clear contact and governance information. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | 3 flagged itVirusTotal | Risk |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 15 years oldRegistered history | Clear |
| Web archive | Archived since 20111135 snapshots | Clear |
| Certificate | Encrypted connectionIssued by ZeroSSL RSA Domain Secure Site CA | Noted |
The page as captured
Key findings
- Automated classification: Sensitive Interaction Risk.
- Domain age: more than 10 years (registration continuity).
- Public web-archive history exists since 2011.
- At least one reputation service TrustSniffer consulted had flagged this domain at assessment time.
Full analysis
Overview
The website is the public-facing institutional site of Archbishop Mihayo University College of Tabora (AMUCTA), presenting academic programs, admissions guidance, institutional news, research, student services, downloads, contact information, and channels associated with tuition, fees, and donations. Its apparent purpose is to support the college’s educational administration and public communications.
Scam/Impersonation Risk
The site presents coherent university content, including an “About Us” section, governance information, academic faculties and departments, admissions instructions, student services, publications, and staff areas. Its pages do not show brand-impersonation indicators, conflicting legal identities, suspicious forms, wallet functionality, or other overtly deceptive mechanisms. However, this positive on-site presentation is materially outweighed by external reputation telemetry recording malicious and suspicious detections and by confirmed blacklist status from two independent sources. The result is a high-risk posture for sensitive interaction: the website may reflect a genuine institutional publication, but its external reputation creates a serious unresolved contradiction, and real-world identity is not independently verified.
- The homepage identifies “Archbishop Mihayo University College of Tabora” and links to admissions, academic programs, research, student services, staff areas, and contact functions.
- The admissions and institutional pages provide program, application, governance, and student-service information without detected phishing forms or untrusted form destinations.
- Domain registration telemetry records registration on 2012-06-25, with an age of 14.16 years.
- Web-archive telemetry records 1,135 snapshots spanning 2011–2026, covering 16 tracked years.
Regulatory Verification Notes
The legal and identity material on the site is consistent with an academic institution and includes governance-related content, staff and governing-board references, terms, privacy information, and contact details. That presentation supports an apparent institutional purpose but does not independently establish the operator’s legal identity. The site’s licensing or education-authorisation disclosure is unclear: no license claim, registration number, or named licensing authority is supplied in the available business information. This is a regulatory verification gap rather than, by itself, proof of fraud. The academic-domain context and the absence of a matching broker record provide contextual support only and do not override the adverse external reputation findings.
- The About, History, Principal’s Message, and Governing Board sections present institutional identity and governance information.
- The Terms & Conditions and Privacy & Policy pages provide formal site-policy disclosures, while the Contact page supplies institutional contact details.
- The site’s transport encryption uses a DV certificate issued by ZeroSSL RSA Domain Secure Site CA, valid through 2026-09-05.
What to Verify Next
Before any account, admissions, payment, donation, or document-submission activity, the institution’s existence and the relevant payment or application instructions should be confirmed through an independently obtained contact route or an education-authority registry. Any bank, mobile-money, or payment recipient should be matched to the institution through an offline or independently sourced confirmation rather than relying solely on instructions displayed on the site. The official support and contact channels should also be confirmed independently before credentials or sensitive documents are submitted.
- The admissions pages describe application procedures, entry requirements, fees, and funding information that can be cross-checked with the relevant education authority.
- The homepage and Contact page provide the institution’s stated communication channels for independent confirmation.
- The site links to staff-portal and student-information functions, making account and document handling a relevant verification point.
Summary Verdict
The website has the appearance and historical continuity of an academic institution, but the confirmed external reputation contradiction is decisive for trust assessment. Its legitimacy remains apparent rather than proven, and the overall posture is unsuitable for treating sensitive interactions as routine without independent confirmation.
Infrastructure Integrity
The site resolves directly to a single apparent origin rather than a CDN edge network, with hosting provided by Habari Node Public Limited in Tanzania on AS36909. No CDN or WAF protection was detected; this does not establish maliciousness, but it means the observed hosting environment provides limited infrastructure-based mitigation. The site’s valid DV TLS certificate protects transport confidentiality but does not authenticate the underlying organisation.
Closing Assessment
The appropriate course is to restrict activity to low-risk informational review until institutional identity, authorisation, payment details, and account-handling channels have been independently confirmed.
Written analysis generated 2026-08-22 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
2 findings contributed to this verdict, raised by registration and ownership, analysis engine, behaviour in a sandbox.
01 Governance Risk
- The public registration record for this domain is incomplete.Registration and ownership
rule:KF_WHOIS_INCOMPLETE
02 Sensitive Interaction Risk
- The analysis matched a pattern TrustSniffer treats as a direct threat to a visitor.Analysis engine
signal:direct_threat - The structure of the page changed sharply while it was loading.Behaviour in a sandbox
rule:BEHAV_DOM_DENSITY_SPIKE
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 55/100 |
| Identity verification confidence | 60% |
- Identity verified on page
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of amucta.ac.tz.
- The request stayed on amucta.ac.tz. It was not redirected to another domain. Clear
- Registration is published under REG-HABARI. Clear
- DNS for this domain is served by co.tz, across 2 name servers. Noted
- The registration is paid up to 2027-06-24. Noted
- The earliest public archive of this site is from 2011-12-27. Clear
- It is hosted on Habari Node Public Limited, from a server in TZ. Noted
Domain intelligence
| Registrar | REG-HABARI |
|---|---|
| Hosting | Habari Node Public Limited - Habari Node Public Limited, TZ |
| Country | TZ |
| Server IP | 41.220.128.10 |
| Name servers | ns2.habari.co.tz, ns3.habari.co.tz |
| SSL issuer | ZeroSSL RSA Domain Secure Site CA |
| SSL expiry | 2026-09-05 |
| Domain age | 14.65 years (continuous registration) |
| Domain expiry | 2027-06-24 |
| Archive first seen | 2011-12-27 |
| Archive snapshots | 1135 |
| Reputation | VirusTotal: 3 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about amucta.ac.tz at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.