sigstore.dev

#00E77D63 · Very Safe
100 / 100
ArrowSweep · sigstore.dev — Report card
United States 75.2.60.5 Valid HTTPS 5.3 years 1API GmbH Updated

Sigstore.dev Trust Review

sigstore.dev appears to be the official home of Sigstore, an open-source software signing and verification project. The domain shows a normal U.S. hosting footprint, HTTPS is enabled, and the 2021 registration date fits a mature project rather than a throwaway site.

IP Address · Server Location

75.2.60.5
United States

SSL Certificate

Valid HTTPS
E7
Valid Until: 2026-08-11

Registrar

1API GmbH
Registered On: 2021-02-18
5.3 years

Very Safe

100/100
Verdict at a glance

Public-record summary

From the public records linked to sigstore.dev we extracted four anchors: country United States, registrar 1API GmbH, age 5.3 yrs, encryption status OK. Everything else builds on those.

How long has sigstore.dev existed?

According to RDAP records, sigstore.dev was registered around 5.3 years ago through 1API GmbH. This is a useful signal but should be combined with content review.

In-transit protection

For data moving between the user and sigstore.dev, the encryption check returned: OK. This is the single most important infrastructural safety check we run.

Infrastructure provider

Our GeoIP lookup places sigstore.dev on the Unknown network, geographically in United States. ISP-level reputation matters: established networks tend to act on abuse reports faster.

How we read this profile

For sigstore.dev, the combined picture (5.3 yrs, SSL OK, United States hosting, 1API GmbH registration) lands in the "very_safe" band. That is a starting point, not a final verdict.

Final take

Combining all signals, we rate sigstore.dev at 100/100 (very_safe). Always perform your own due diligence before sharing personal data or money.

What looks good

  • Certificate issued by a recognised CA
  • No DNS hijack indicators in current records
  • Returns valid SOA and TXT records
  • Registered with an established registrar

What to watch

  • TLS configuration accepts older cipher suites
  • Limited public reputation data
  • No HSTS header detected at the apex

Frequently Asked Questions

Is the WHOIS information about sigstore.dev hidden?
Most modern registrars apply privacy protection by default, so personal contact data may be redacted. Registration dates and registrar are still visible.
Is sigstore.dev on a security blocklist?
At the time of audit, sigstore.dev was not present in the public blocklists we sample (PhishTank, abuse feeds, etc.).
Is sigstore.dev a phishing website?
Our scanner does not perform visual similarity checks. We can only confirm that no obvious infrastructure markers (cert mismatch, fresh registration with high traffic) were triggered.
What looks risky about sigstore.dev?
For sigstore.dev we look at: age 5.3 yrs, SSL OK, registrar 1API GmbH and hosting in United States. Any single weak point can drag the technical confidence down.
How often is sigstore.dev re-checked?
By default the report is refreshed every 30 days, plus on every manual re-check from the dashboard.

This report is generated automatically from public technical signals. It is not legal or financial advice.

Vet your next domain in under 10 seconds.

No signup. No credit card. No hidden quotas.

Start a free check →