Verdict
medlineplus.gov appears legitimate.
Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.
| What this site appears to be | GPT summary status=degraded | GPT summary call failed: HTTP error from GPT: 429 Too Many Requests { "error": { "message": "You exceeded your current quota, please check your plan and billing details. For more information on this error, read the docs: https://platform.openai.com/docs/guides/error-codes/api-errors.", "type": "insufficient_quota", "param": null, "code": "insufficient_quota" } } |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | None flagged itVirusTotal | Clear |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 27 years oldRegistered history | Clear |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by Amazon RSA 2048 M01 | Noted |
The page as captured
No screenshot is retained for this report.
Key findings
- Automated classification: Not Scam.
- Domain age: more than 10 years (registration continuity).
- No flags from the reputation services TrustSniffer consulted at assessment time.
Full analysis
Overview
MedlinePlus is a government-domain public health information website presenting itself as a source of health information from the National Library of Medicine, with an apparent public-service and informational purpose rather than a commercial trading or transactional model.
Scam/Impersonation Risk
No blacklist, phishing, malicious-content, or conflicting-identity indicators were observed, and the available evidence is consistent with an established site. Behavioral inspection did identify a hidden form, suspicious inline scripting, console errors, and substantial post-interaction page changes; however, no externally submitted password forms, wallet-drainer activity, clipboard hijacking, non-whitelisted external requests, or cloaking were observed. These isolated behavioral anomalies therefore do not establish impersonation or a scam mechanism, but they warrant ordinary application-security monitoring.
- The homepage is titled “MedlinePlus - Health Information from the National Library of Medicine” and uses the medlineplus.gov government-domain identity.
- External reputation checks recorded 0 malicious and 0 suspicious detections, with no blacklist or phishing hit.
- Behavioral inspection covered 2 successful runs; it detected 1 hidden form, 2 suspicious inline scripts, and 14 console errors, but 0 external password forms, 0 wallet-drainer runs, and 0 clipboard-write events.
Regulatory Verification Notes
The homepage communicates a clear public-health information purpose and is hosted under a government-domain suffix. The available evidence does not independently verify the real-world operator identity or establish a separate professional or clinical licensing status; this is a verification note, not an adverse legitimacy finding. The site’s long registration continuity, substantial public web presence, known TLS issuer, and clean external reputation materially support an established-site assessment. No third-party broker-reputation match was identified.
- Domain registration: 2000-02-04; registered 2000 (~26.53 years old), with get.gov listed as registrar and an expiration date of 2026-09-15.
- The site is served from AS16509 (AMAZON-02 - Amazon.com, Inc., US).
- TLS uses a DV certificate issued by Amazon RSA 2048 M01, valid through 2027-01-30.
- The domain is ranked 2415 globally and is within the top 1 million sites.
What to Verify Next
For credential-bearing or payment-related interactions, an independent check should confirm that the service identity corresponds to the intended official government resource and that any applicable privacy, account-use, and payment-protection terms are appropriate. Official contact channels should be confirmed through an independent government directory or offline institutional route rather than relying solely on page-level contact information. If a separate clinical, professional, or transactional service is offered, its responsible organization and applicable authorization should be checked against the relevant official registry.
- The homepage identifies the service as health information from the National Library of Medicine.
- The domain uses the .gov suffix and has a registration history beginning in 2000.
- The site’s transport encryption is valid and issued by Amazon RSA 2048 M01 through 2027-01-30.
Summary Verdict
The overall posture is high trust and low risk, and the evidence is consistent with an established, apparently legitimate public-information website. The classification supports normal informational use, while the real-world operator identity remains independently unverified and should not be treated as proven solely from the available evidence.
Infrastructure Integrity
The site is hosted on Amazon infrastructure and benefits from content-delivery-network characteristics that reduce direct exposure of an origin service and provide a stabilizing infrastructure signal. This is a mitigating technical factor only and does not independently prove institutional legitimacy.
Closing Assessment
Ordinary browsing is proportionate to the assessed posture; before submitting credentials or making any payment, the intended institutional identity, applicable terms, and payment protections should be confirmed through independent official channels.
Written analysis generated 2026-08-12 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
No rule findings contributed to this verdict.
Identity verification
| Status | UNKNOWN |
|---|---|
| Identity score | 50/100 |
| Identity verification confidence | 30% |
- AI page analysis unavailable (page captured; identity not AI-verified)
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of medlineplus.gov.
- The request stayed on medlineplus.gov. It was not redirected to another domain. Clear
- Registration is published under get.gov. Clear
- DNS for this domain is served by nih.gov, across 3 name servers. Noted
- The registration is paid up to 2026-09-15. Noted
- It is hosted on AMAZON-02, from a server in US. Noted
Domain intelligence
| Registrar | get.gov |
|---|---|
| Hosting | AMAZON-02 - Amazon.com, Inc., US |
| Country | US |
| Server IP | 2600:9000:2045:2800:1:6b7c:7400:93a1 |
| Name servers | gslb01.nlm.nih.gov, gslb02.nlm.nih.gov, gslb03.nlm.nih.gov |
| SSL issuer | Amazon RSA 2048 M01 |
| SSL expiry | 2027-01-30 |
| Domain age | 26.53 years (continuous registration) |
| Domain expiry | 2026-09-15 |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 0 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about medlineplus.gov at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.