Verdict
moe.gov.my appears legitimate.
Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.
| What this site appears to be | Official Ministry of Education (KPM) portal in Malay/English containing announcements, news, services, quick links, contact details and ministry address; appears to be an established government site. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- The real-world operator identity was not independently verified.
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | None flagged itVirusTotal | Clear |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 29 years oldRegistered history | Clear |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by GlobalSign Atlas R46 DV TLS CA 2026 Q2 | Noted |
The page as captured
Key findings
- Automated classification: Not Scam.
- Domain age: more than 10 years (registration continuity).
- No flags from the reputation services TrustSniffer consulted at assessment time.
Full analysis
Overview
The website is a Malay/English Ministry of Education portal presenting announcements, news, education information, public-service links, contact details, and ministry resources; its apparent purpose is to provide official government information and access to related education services rather than conduct commercial transactions.
Scam/Impersonation Risk
No contradictions were observed between the site’s stated purpose, page content, domain context, and observed technical behavior. The homepage identifies the KPM Ministry of Education portal and provides ministry-oriented sections such as corporate information, education services, public complaints, directories, and sub-portals. Interaction testing did observe hidden form elements, but there was no login form, sensitive form, external password submission, wallet activity, suspicious script, or external network posting. A page-similarity signal involving another domain was not corroborated by the site’s content or behavior and does not establish impersonation. The external reputation checks recorded no malicious or suspicious detections, and no broker-reputation match was identified.
- Domain registration evidence: registered 1997-03-31, approximately 29.4 years old, through MYNIC Berhad, with expiry on 2027-03-31.
- Homepage: displays “PORTAL RASMI KEMENTERIAN PENDIDIKAN,” ministry sections, education services, public contacts, and links to Malaysian government institutions.
- Interaction testing: hidden form elements were detected, but no login form, sensitive form, external password form, wallet connection, wallet-drainer activity, or suspicious inline script was observed.
- External reputation telemetry: 0 malicious detections and 0 suspicious detections; no external blacklist hit and 0 abuse reports were recorded for the assessed infrastructure.
Regulatory Verification Notes
The site presents a governmental public-information model, not a financial or commercial service requiring a displayed commercial license. Its pages provide ministry identity, organizational information, institutional contacts, and a ministry address, while links connect to other Malaysian public-sector services. Available evidence is consistent with an established, apparently legitimate government website, but the real-world operator identity is treated as likely rather than independently verified. The absence of a separate commercial license number is therefore not an indication of misconduct; any specific regulated service reached through a linked sub-portal should be assessed against that service’s own disclosure and authorization requirements.
- Homepage: identifies the Ministry of Education and provides corporate, leadership, organizational, education, complaints, directory, and e-service sections.
- Domain context: uses the `gov.my` government suffix and is classified as a government/public-service portal.
- Transport security: TLS is DV-validated, issued by GlobalSign Atlas R46 DV TLS CA 2026 Q2, valid to 2026-09-23T11:29:07+00:00.
- Social and institutional presence: the homepage links to Facebook, Twitter, Instagram, YouTube, RSS, and multiple Malaysian government domains.
What to Verify Next
For ordinary public-information use, the available evidence supports routine browsing. Before submitting credentials or making any payment through a linked service, independently confirm that the destination remains within the relevant official government domain, validate the responsible ministry or agency through an independently sourced contact route, and review the applicable service terms, refund or return provisions, and payment protections. Any request that departs from the portal’s stated informational and public-service purpose should receive separate scrutiny.
- Contact page and homepage: provide the ministry’s published contact details and address for independent confirmation.
- E-service and sub-portal menus: identify the specific service destination that should be checked before credential or payment interaction.
- Corporate and organizational pages: provide the institutional structure against which a linked service or request can be compared.
Summary Verdict
The overall posture is high trust and low risk, with the available evidence consistent with an established, apparently legitimate website. The classification is strong enough to support normal public-service interaction, while the operator’s real-world identity remains a qualified rather than independently proven conclusion.
Infrastructure Integrity
The site is protected by Incapsula CDN/WAF infrastructure, which is a mitigating control that reduces direct exposure of the underlying service; protective hosting alone is not proof of legitimacy. All observed addresses were CDN edge addresses, with no origin candidate identified in the analysis.
- Hosting telemetry: served from AS19551, INCAPSULA - Incapsula Inc, US.
- Observed edge addresses: 45.60.64.11 and 45.60.66.11, both associated with AS19551.
Closing Assessment
Proceed with ordinary public-information use, and apply independent identity, service-policy, and payment-protection checks before any credentialed or financial interaction with a linked service.
Written analysis generated 2026-08-17 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
No rule findings contributed to this verdict.
Identity verification
| Status | LIKELY |
|---|---|
| Identity score | 80/100 |
| Identity verification confidence | 40% |
- Identity verified on page
- Trusted social count=4
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of moe.gov.my.
- The request stayed on moe.gov.my. It was not redirected to another domain. Clear
- Registration is published under MYNIC Berhad. Clear
- DNS for this domain is served by gov.my, across 4 name servers. Noted
- The registration is paid up to 2027-03-31. Noted
- It is hosted on INCAPSULA, from a server in US. Noted
Domain intelligence
| Registrar | MYNIC Berhad |
|---|---|
| Hosting | INCAPSULA - Incapsula Inc, US |
| Country | US |
| Server IP | 45.60.64.11 |
| Name servers | ns1.moe.gov.my, ns2.moe.gov.my, ns3.moe.gov.my, ns0.moe.gov.my |
| SSL issuer | GlobalSign Atlas R46 DV TLS CA 2026 Q2 |
| SSL expiry | 2026-09-23 |
| Domain age | 29.40 years (continuous registration) |
| Domain expiry | 2027-03-31 |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 0 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about moe.gov.my at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.