How to Verify a Company Is Legitimate Before You Do Business With It
A company can have a polished website, a registered entity, an office address, and still be a problem. Each of those is cheap to produce. What is expensive to fake is a consistent operating history across sources that nobody controls at once.
That is the principle behind this check. You are not looking for a single disqualifying fact. You are looking for whether the business's public footprint coheres — and where it does not, whether the gap has an innocent explanation.
Use this before onboarding a vendor, accepting a partner, paying an invoice from a new counterparty, or committing to a contract with a company you have not worked with.
Start by writing down the decision
"Is this company legitimate" is too vague to answer. Legitimate for what?
- Real enough to accept a $200 subscription from?
- Real enough to wire a five-figure payment to?
- Real enough to grant data access to under a processing agreement?
The threshold determines the depth. A cheap, reversible decision justifies ten minutes. An irreversible payment or a data-sharing arrangement justifies far more, and justifies asking the company directly for what public sources cannot tell you.
Step 1 — Confirm you have the right company
More due diligence goes wrong here than anywhere else. Similar names, dormant lookalike entities, acquired brands, and regional subsidiaries all produce confident research about the wrong organization.
Anchor on the domain, then find the legal entity:
- Read the footer, terms of service, and privacy policy — these usually name the actual contracting entity, which is often not the brand name
- Note the company number, registered address, and tax identifiers if published
- Check whether the entity you were given by email matches the entity on the site
A mismatch between the entity a counterparty names in correspondence and the entity published on their own website is worth resolving before anything else.
Step 2 — Check the registry record
Look the legal entity up in the company register of its stated jurisdiction, and read the record rather than just confirming it exists:
- Status — active, dissolved, struck off, in liquidation, or overdue on filings
- Incorporation date — a company incorporated three weeks ago is not disqualified, but it changes what the other evidence has to carry
- Registered address — and whether it belongs to a registered-agent or virtual-office service
- Filing history — whether accounts and returns are current
- Officers and any published ownership — and whether those names appear anywhere else in the picture
Coverage varies by country. Some jurisdictions publish detailed filings for free; others publish almost nothing without a fee, and a few publish little at all. Thin registry data in a low-disclosure jurisdiction is a limitation of the source, not a finding about the company.
Step 3 — Verify the domain, not just the website
The website is the artifact the counterparty controls most completely. The domain around it is harder to dress up.
- Registration age. A domain registered last month behind a brand claiming a decade of operation is a direct contradiction. (Privacy-redacted registration details are normal and not themselves suspicious.)
- Mail infrastructure. Does the company send from its own domain, and does that domain have properly configured mail records? Correspondence from a free webmail address for a company with its own domain is a common pattern in invoice fraud.
- Lookalike domains. Check whether the domain you were contacted from is the company's actual domain, or a near-miss variant of it. This is the mechanic behind most business email compromise.
- History. Whether the domain previously hosted something entirely unrelated.
The related techniques are covered in how to map a company's domain and website footprint and, for the sender side, how to investigate a suspicious email address.
Step 4 — Look for evidence of operation
Registration proves a company was created. It says nothing about whether it runs. Look for the residue that continuing operation leaves behind:
- Dated release notes, changelogs, or product announcements
- Maintained documentation and a status page with actual incident history
- Marketplace or app store listings with reviews and update history
- Public repositories or published packages with recent activity
- Job postings that appear, change, and close
- Named customers, partners, or integrations confirmed on the other party's site
- Coverage in publications that are not the company's own press releases
None of these is mandatory — plenty of legitimate businesses are offline-oriented or deliberately quiet. But when a company's claims are large and every supporting artifact traces back to material the company itself published, you have one source, not many.
Step 5 — Weigh the signals against each other
| Signal | Weight | Why |
|---|---|---|
| Contracting entity differs from the entity on the website | High | Directly contradicts the counterparty's own documentation |
| Domain far younger than the claimed operating history | High | Verifiable contradiction, not an interpretation |
| Correspondence from a lookalike domain | High | Primary mechanic of invoice and BEC fraud |
| Registry status dissolved or in liquidation | High | Material to whether a contract is enforceable |
| Payment details that changed mid-engagement | High | The single most common fraud trigger |
| Every claim traces to company-published material | Medium | One source, presented as several |
| No dated activity anywhere in the footprint | Medium | Consistent with a dormant or staged operation |
| Registered-agent address | Low | Extremely common and legitimate |
| Privacy-redacted domain registration | Low | The default for most registrars |
| Small public footprint | Low | Consistent with a small, private, or offline business |
Read the table as a whole. Three low-weight signals do not add up to a high-weight one, and a single high-weight contradiction outweighs a long list of comfortable-looking positives. This is the same weighting discipline described in the stages of a fraud investigation.
Step 6 — Ask the company for what public sources cannot give you
Open-source research is not a substitute for direct verification, and treating it as one is the point where diligence becomes theater.
Before an irreversible commitment, confirm directly:
- Bank details — through a channel you initiated, using contact details you already had, never from the invoice or an inbound email
- The exact contracting entity and its jurisdiction
- References you can independently reach
- Insurance, certification, or compliance documentation your process requires
The rule that prevents most payment fraud is procedural, not investigative: a change in payment details is always verified out of band, by calling a number you already held.
What a clean result actually means
If the entity checks out, the domain is old enough, the operating evidence is current and corroborated by parties the company does not control, and the contracting details match — you have established that the business exists, operates, and is who it says it is.
You have not established that it will perform. Solvency, delivery capability, and good faith are not observable from public sources. Diligence lowers the probability of the obvious failures. It does not remove counterparty risk, and no amount of research will.
Frequently asked questions
How can I check if a company is legitimate for free? Most of this check uses free sources: the company's own site and legal pages, the national company register for its jurisdiction, domain registration and DNS records, app or marketplace listings, and public developer artifacts. Paid data services mainly save time and add coverage in low-disclosure jurisdictions — they do not replace the reasoning.
What are the strongest red flags that a company is not legitimate? Verifiable contradictions rather than impressions: a contracting entity that differs from the one published on the company's website, a domain far younger than the claimed history, correspondence from a lookalike domain, a dissolved or liquidating registry status, and any mid-engagement change to payment details.
Is a virtual office or registered-agent address a red flag? On its own, no. Registered-agent and virtual-office addresses are used by an enormous number of ordinary companies, particularly small and remote-first ones. It matters only in combination with other contradictions.
Does a small online footprint mean a company is fake? No. Absence of evidence is not evidence. Small, private, regional, and offline-oriented businesses routinely have thin public footprints. What matters is whether the footprint contradicts the company's claims — a business claiming global scale with no trace of it is a contradiction; a small business that is quietly small is not.
How do I avoid paying a fraudulent invoice? Verify payment details out of band, every time, using contact details you already had rather than any supplied in the invoice or the message carrying it. Confirm the sending domain is the company's real domain and not a near-miss variant. Treat any urgent request to change bank details as fraudulent until proven otherwise.
Investigate a counterparty
DefenceCore investigates domains, URLs, and identifiers together — following connected public signals and returning a sourced evidence map with confidence on every link.
→ Run an investigation · See a sample report
For the commercial side of the same research — what a company sells, its products and connected websites, and the markets it operates in — see our company intelligence review.