Verdict
sso.acesso.gov.br appears legitimate.
Our checks found nothing pointing to fraud. Ordinary care still applies when you pay or sign in.
| What this site appears to be | Portuguese-language gov.br sign-in page asking users to identify themselves using a CPF, accredited bank, QR code, or digital certificate. It is essentially a login-only page and provides little context beyond authentication and privacy/help links. |
|---|
Evidence status and limitations
Evidence completeness: UNKNOWN
- Module-level completeness metadata is unavailable for this legacy report.
At a glance
The checks that decide most of this verdict.
| Malware engines | None flagged itVirusTotal | Clear |
|---|---|---|
| Google Safe Browsing | Not listedGoogle | Clear |
| Abuse reports on the host | 0 reportsAbuseIPDB; shared hosting inflates this count | Noted |
| Domain age | 7.7 years oldRegistered history | Clear |
| Web archive | Never archivedNo public history of this site | Watch |
| Certificate | Encrypted connectionIssued by YR1 | Noted |
The page as captured
No screenshot is retained for this report.
Key findings
- Automated classification: Not Scam.
- Domain age: 3 to 10 years (registration continuity).
- No flags from the reputation services TrustSniffer consulted at assessment time.
- The operator behind the site could not be independently connected to a real-world brand or person.
Full analysis
Overview
The website is an official Brazilian government authentication service that provides access to a gov.br identity account through CPF entry, accredited-bank authentication, QR code, or digital certificates; it operates as a public-service sign-in gateway rather than a commercial platform.
Scam/Impersonation Risk
No identity contradictions, brand impersonation, phishing indicators, or adverse reputation findings were observed. Although the page is intentionally limited to authentication and therefore contains little explanatory context, its government identity, established provenance, clean external reputation, and benign observed network behaviour collectively support its legitimacy. The sensitive form is consistent with the stated government-authentication purpose, and no untrusted submission destination was identified.
- The login page presents a single government-identity form for CPF entry; no password form submitting to an external destination was detected.
- The page title and visible interface consistently identify the service as gov.br, with no competing legal-entity name or suspected impersonated brand.
- External reputation checks recorded 0 malicious and 0 suspicious detections, no malicious safe-browsing finding, and 0 reported abuse incidents for the hosting address.
- The domain was registered in 2018 and is approximately 7.69 years old; registration identifies MINISTERIO DA FAZENDA as the owner.
Regulatory Verification Notes
This is a sovereign public-service authentication endpoint under Brazil’s restricted government namespace, not a broker, investment service, or other commercial activity for which an on-page financial licence would ordinarily be expected. The available identity evidence consistently connects the service to Brazilian federal-government administration. The page also provides access to terms of use and a privacy notice, which is appropriate for an identity service processing CPF data.
- The domain uses the verified sovereign `gov.br` namespace and is categorized as a Brazilian government service.
- Registration records name MINISTERIO DA FAZENDA as the domain owner.
- The hosting infrastructure serves the site from AS10954 (SERVICO FEDERAL DE PROCESSAMENTO DE DADOS — SERPRO, BR).
- The site’s transport encryption uses a TLS certificate issued by YR1 with DV validation, valid to 2026-09-17.
What to Verify Next
For operational assurance, access should originate from an independently known Brazilian government portal or a trusted bookmark, and the browser should be checked for the expected government hostname before CPF submission. Organisations integrating or directing users to this service should also confirm the current terms, privacy notice, and approved authentication flow through official government documentation.
- The assessed page is a dedicated login endpoint with limited context beyond authentication, help, terms-of-use, and privacy links.
- The page requires browser cookies for the authentication process to function.
- Observed testing completed two successful runs with stable HTTP responses, no cloaking, and no non-whitelisted external form submissions.
- The page offers a help route for users requiring assistance with the authentication process.
Summary Verdict
Cross-evidence convergence establishes the website as a legitimate, established, and trustworthy government authentication service. No contradictory security or identity signals undermine that conclusion, and normal interaction—including account login and standard use—is appropriate.
Infrastructure Integrity
The site resolves directly to a likely origin address in Brazil without a CDN or WAF layer. Direct origin visibility is an architectural characteristic rather than evidence of compromise; the infrastructure is operated within the identified federal data-processing environment, and the normalized infrastructure assessment found no material trust concern.
Closing Assessment
Prospective users may proceed with normal authentication and account activity while applying routine hostname and browser-security checks customary for government identity services.
Written analysis generated 2026-07-31 by the TrustSniffer Analysis Engine from the evidence in this report.
What the analysis found
No rule findings contributed to this verdict.
Identity verification
| Status | UNVERIFIED |
|---|---|
| Identity score | 55/100 |
| Identity verification confidence | 60% |
- Identity verified on page
Identity verification measures whether the site can be independently connected to a real-world brand or person. It is separate from the classification confidence.
What TrustSniffer observed
First-party facts recorded during the assessment of sso.acesso.gov.br.
- The request stayed on sso.acesso.gov.br. It was not redirected to another domain. Clear
- DNS for this domain is served by gov.br, across 2 name servers. Noted
- It is hosted on AS10954, from a server in BR. Noted
Domain intelligence
| Registrar | Not available |
|---|---|
| Hosting | AS10954 - SERVICO FEDERAL DE PROCESSAMENTO DE DADOS - SERPRO, BR |
| Country | BR |
| Server IP | 189.9.180.29 |
| Name servers | bsa1.lb.serpro.gov.br, spo1.lb.serpro.gov.br |
| SSL issuer | YR1 |
| SSL expiry | 2026-09-17 |
| Domain age | 7.7 years |
| Domain expiry | Not available |
| Archive first seen | Not available |
| Archive snapshots | 0 |
| Reputation | VirusTotal: 0 flagged | AbuseIPDB: 0 reports | Google Safe Browsing: 0 matches |
About this assessment
A trust score summarises the evidence TrustSniffer could collect about sso.acesso.gov.br at assessment time. It is a starting point for your own judgement, not a guarantee: a high score means the signals were consistent with a legitimately operated site, a low or critical score means several risk patterns were present.
TrustSniffer assesses a website from the evidence it can collect at a point in time: domain registration and age, hosting and certificate, the content the site served, and third-party reputation feeds. A score is a summary of that evidence, not a guarantee and not a legal finding. There is no human rating and no user review in it. A site can change after it is assessed.