Google Safe Browsing
UnknownNot available — provider did not respond.
Learn more
Google's threat database flags sites known to host malware, phishing, or unwanted software. A clean result is a strong positive signal.
facebook.com looks safe overall. It uses HTTPS correctly, has existed for over 29 years, and publishes SPF and DMARC email records.
This website scored 82/100 because:
TD-6D6A3AScan took 4122 msHow this domain connects to the rest of the TrustDepth graph.
Every signal, its weight, and how many points it contributed to facebook.com's score.
Not available — provider did not respond.
Google's threat database flags sites known to host malware, phishing, or unwanted software. A clean result is a strong positive signal.
Not available — provider did not respond.
We check independent abuse databases like URLhaus and PhishTank. Being listed means researchers have observed the site being used maliciously.
Registered 29 years ago · via RegistrarSafe, LLC.
Older domains are much less likely to be scams. Most phishing sites are registered within the last 90 days.
Valid HTTPS certificate.
A valid HTTPS certificate proves the site owns the domain and encrypts traffic. Broken or missing certificates are a red flag.
SPF ✓ DMARC ✓
SPF, DMARC and DNSSEC records help stop attackers from spoofing this domain in email or redirecting visitors to fake copies.
Reachable over HTTPS with HSTS.
We confirm the site actually responds, upgrades HTTP to HTTPS, and returns a healthy status code.
No suspicious naming patterns.
Lookalike names, homoglyphs, brand-typosquats, suspicious TLDs, and digit-heavy strings correlate with scam sites.
Not available — provider did not respond.
HSTS, CSP, X-Frame-Options and Referrer-Policy show the operator takes basic browser-side hardening seriously.
Not available — provider did not respond.
Real businesses publish contact, about, privacy and terms pages. Missing all of them is a common scam pattern.
Not available — provider did not respond.
Long redirect chains or cross-domain hops are common in cloaking, affiliate abuse, and phishing landers.
Not available — provider did not respond.
Robots.txt, sitemap.xml, server headers and framework markers show the site is a properly built, maintained web app.
Not available — provider did not respond.
Signed-in visitors can share first-hand experiences. Aggregated ratings supplement automated checks.
Simple habits that keep you safe whether or not this site scores well.
2FA blocks the vast majority of account takeover attempts even if your password leaks.
Preview the destination URL — shortened links in DMs are a top phishing vector.
Cloned profiles copy real friends. Confirm through a second channel before accepting sensitive DMs.
Audit which third-party apps have access to your account every few months and revoke unused ones.
Automated safety signals do not indicate facebook.com is a scam. That said, no automated system catches every fraud — always verify unusual offers independently.
facebook.com passes TrustDepth's core safety checks and is not present on any abuse blocklists we consult. It's likely legitimate.
Most signals look good for facebook.com. Trust it for normal browsing, but be cautious with payment info.
facebook.com looks safe for everyday use based on our automated checks. Still practice basic hygiene: verify URLs, use strong unique passwords, and enable two-factor authentication.
We combine live SSL, WHOIS, DNS and reachability checks with lookups against Google Safe Browsing and abuse blocklists such as URLhaus and PhishTank. Naming heuristics and (soon) community reviews add extra context. Each signal contributes a weighted portion of a 0–100 score.
Our SSL/TLS check inspects the live certificate served by facebook.com, verifying issuer, validity window and hostname match. See the "SSL / TLS certificate" signal above for the exact result for this scan.
We cross-check facebook.com against Google Safe Browsing, URLhaus and PhishTank. If any of them flag the domain, it will show as a red signal in the "Safety signals" section above.
WHOIS registration age is one of the strongest anti-scam signals — most fraudulent sites are less than 90 days old. Check the "Domain age (WHOIS)" signal above for the registration date and age for facebook.com.
Close the tab, do not enter any credentials, and do not download files. Report the URL to Google Safe Browsing (safebrowsing.google.com/safebrowsing/report_phish/) and to your browser's built-in reporting tool. If you already entered a password, change it immediately on the real site and enable 2FA.
Every scan is live — signals are re-checked from source when you load this page (with a short cache to avoid rate limits). You can force a fresh scan any time by re-submitting facebook.com from the home page.
TrustDepth generated this scorecard for facebook.com by running seven independent checks in parallel: SSL/TLS certificate validity, WHOIS registration age, DNS configuration (SPF, DMARC, DNSSEC), HTTPS reachability, Google Safe Browsing status, abuse blocklists (URLhaus, PhishTank), and naming heuristics. Each signal contributes a weighted share of the 0–100 score.
A verdict of trusted means the domain passed all core checks with high confidence. Likely safe means most signals are positive with one minor gap. Unclear means we don't have enough evidence to recommend for or against. Suspicious and dangerous mean at least one strong red flag — proceed with caution or avoid entirely.
Automated scans catch most fraud, but no scanner is perfect. Always cross-check unusual offers, verify contact details, and prefer payment methods with buyer protection. Read our methodology for the full scoring breakdown.
Real reports from people who have used facebook.com. Add yours to help others decide.
Loading comments…