What is this website?
cmu.edu is currently classified in the Education category based on observed public pages. An About page was also found. The sampled pages were marked as English-language. Recurring page-metadata topics include carnegie mellon university, rankings, global.
No listed local patterns observedHomepage-only analysis is not a malware clearance. Read the scope and findings below.
How to read this report
Safety Score evaluates observed signals. Evidence Confidence measures how complete, direct, fresh, and consistent those signals are.
No automated scan can guarantee that a website is safe.
Independent evidence brief
What we observed about cmu.edu
The latest scan examined 10 public pages on cmu.edu. Website descriptions below come from the site itself. Registration, connection and threat findings were checked separately.
Purpose and visible content
On its About page, the site says: CMU pushes the boundaries of innovation and creativity across disciplines. Learn about our visionary research, rankings, mission and locations.
- About Carnegie Mellon | Carnegie Mellon UniversityCMU pushes the boundaries of innovation and creativity across disciplines. Learn about our visionary research, rankings, mission and…
- Vision, Mission and Values | Carnegie Mellon UniversityCarnegie Mellon University’s vision, mission and values guide our innovative approach to education, research and creating global impact.…
- History | Carnegie Mellon UniversityCMU , now a global research university , began when Andrew Carnegie famously stated, "My Heart is in…
Registrar and domain history
A reliable creation date was not returned by the registration lookup. The report leaves domain age unverified rather than guessing.
Connection and hosting evidence
The checked homepage returned HTTP 200 in about 1000 ms.
A valid TLS certificate was observed, expiring Jan 18, 2027.
Threat checks and score context
External malware-provider coverage was unavailable. The report does not treat this missing check as a clean result.
Safety Score: 61/100. Evidence Confidence: 70%. These measure different things.
Public content profile
Pages reviewed on cmu.edu
We sampled public pages from this website to understand its subject and contact paths. The titles and short descriptions below come from the website itself. They are not endorsements or independent safety findings.
Public page evidence
Topics and keywords observed on cmu.edu
These phrases were extracted locally from sampled public page metadata. They are observations, not search-volume or ranking estimates.
At a glance
Key findings
Report is current
The displayed evidence comes from the published immutable scan.
Confidence is separate
Unavailable evidence is shown as missing and never counted as clean.
Verify before sensitive actions
Check the exact URL and context before payments, credentials, or downloads.
Fully explainable
Why this score?
Threat providers were unavailable. The neutral uncertainty baseline is not a clean verdict.
Evidence is unavailable.
Observed DNS records and network address were checked.
Observed certificate validity and TLS protocol were checked.
Observed security header values were checked for basic protective settings. Empty values, disabled HSTS and unrecognized values receive no credit. This is not a complete browser-policy validation.
Observed site metadata and About page were checked. Publisher-supplied details are not independently verified.
Popularity is weak context, not proof of safety. Unranked sites use a neutral baseline.
Observed HTTP status and final connection scheme were checked.
Server-side analysis
Automated security checks
Local antivirus and phishing checks
Sampled scripts and pages
Resource analysis incomplete
6 resources checked · 16 script links observed on the homepage. Partial resource coverage.
ClamAV inspects the fetched homepage HTML on our server. New scans also sample up to four linked scripts and two collected internal pages, with size and time limits. Scripts are not executed. Other downloads, private server files and logged-in pages remain outside this check. A signature match needs investigation and can be a false positive. No match is not a whole-site safety guarantee.
Exact hostname lookup uses a downloaded Phishing.Database snapshot. It does not send this domain to an external lookup API or mark sibling subdomains as harmful. Not listed does not mean safe. Snapshot age is download age, not proof that every entry was recently revalidated.
Homepage HTML only · Eight local rule families · local-security-v2
Checks use the fetched page and redirect chain. Scripts are not executed, forms are not submitted, and linked files are not downloaded. This is not a malware clearance.
Page resource inventory
Counts describe the sampled HTML, not every resource loaded by the browser. External resources are common and are not automatically harmful.
No listed local patterns observed. The limited rule set cannot detect every threat or behavior.
External threat intelligence
Local checks do not query external reputation databases. An unavailable check is never a clean result.
Registration
Domain information
Infrastructure
Network & hosting
At a glance
Infrastructure summary
A compact view of the connection, DNS and security surface. These observations describe what the scanner could verify at scan time and do not prove ownership or ongoing availability.
Page telemetry
Observed page statistics
These counters describe the fetched response and sampled HTML. Script counts describe references in the markup, not a complete browser network log. Cookie counts cover observed response headers.
Encrypted transport
TLS certificate
Resolution
DNS footprint
DNSKEY presence does not verify the DNSSEC signature chain. Missing records can mean no record was returned or the lookup was unavailable.
128.2.42.10TTL —nsauth1.net.cmu.eduTTL —nsauth2.net.cmu.eduTTL —nsauth3.net.cmu.eduTTL —1 aspmx.l.google.comTTL —10 alt3.aspmx.l.google.comTTL —10 alt4.aspmx.l.google.comTTL —5 alt1.aspmx.l.google.comTTL —5 alt2.aspmx.l.google.comTTL —[NRDR 16337_IN_LOC_40.26.39.0.N.79.56.36.2.W.283.1.10.10 5PS/aNXhz6qcZ6tfoRdgeQ]TTL —[NRDR 30017_IN_TXT_google-site-verification=O2gyijlOW-8BSOghh0tL_4N1PlWU_qznkYhUA22dLJ0 PiRIS0yTtnNYmTWYpWCCVw]TTL —[NRDR 31057_IN_TXT_00df4000000231leaa QSq9rQj5GCBh30pVnLGMtQ]TTL —[NRDR 31504_IN_TXT_v=spf1.include:_spf.cmu.edu.~all jxEj2x9CC1Gu8ePZldY84w]TTL —[NRDR 32847_IN_TXT_facebook-domain-verification=vxpo0xkores42yfj9ggcdd2o2d2v2n 9I1LCDr7zb+jK0IoSEFayA]TTL —[NRDR 32936_IN_TXT_r4bgkix7EqRv+dJHKYelMrye44oR+366MsSA0lCP0TOcMK8wfs0bpTMDP1tLTZ66OFh0Qx+ZMLBCeVx0NJ3syQ== tGCEAk5qNOFhWjjp1w58vw]TTL —[NRDR 33014_IN_TXT_ZOOM_verify_FruZuJfdTeW1OOezpsuIVA +31oybl7gh2i74ky0SLQcg]TTL —[NRDR 33356_IN_TXT_MS=ms17583017 io8/1MnXyp5PTqiijD8s0Q]TTL —[NRDR 34068_IN_TXT_atlassian-domain-verification=H4RHVEsTq5YZaRen7VBly2a3AqWhfLMxAL3wBScS8EB0Pg5x1vaPhj3eXsGaUOGi ePUw4Mw9giYZRVzpV/ysvQ]TTL —[NRDR 34190_IN_TXT_docusign=048da45a-23c6-4f6b-8f96-6dff4fa6b22b AWGRCMvgvpXmHSJ7nxKghg]TTL —[NRDR 34415_IN_TXT_apple-domain-verification=yZrPHuazhdH42CPf dbWBQEISZeHDi/9KkKT96g]TTL —[NRDR 34436_IN_TXT_google-site-verification=MYZf5OssFVvgYQF1snvJdiFbMjHy53WzLrnsVGkgpFU C0YNNkwQ5Qfm8taSZKc+1A]TTL —[NRDR 34437_IN_TXT_google-site-verification=m3lUupwhWqjbGCA6JswqWyBi7tkzh-BjbRiYuC6EXTg Or5AmLIb59AN+oiEMjOqoA]TTL —[NRDR 34438_IN_TXT_google-site-verification=pNbrq7j_EeIowr_Kw1Jfy46bmFWR9p1llXH_leCdLrg eMgkItPzPonrYzRZBOx13w]TTL —[NRDR 34441_IN_TXT_zoho-verification=zb38550127.zmverify.zoho.com sbctKhpo8bhwlNq+f0khtw]TTL —[NRDR 34503_IN_TXT_google-site-verification=JopPlnNv9VupQydpE3TiwZAEod-zouxEX0inao6rggg HxtpS+uc1I0HuPBMBaTlCA]TTL —[NRDR 36038_IN_TXT_cisco-ci-domain-verification=5f809f49f9d3ca48d84db537e031b2007011ea11f6410de6a8a02919908675d6 VTvqYpCLdM5K6bM5zRNwDQ]TTL —[NRDR 36124_IN_TXT_e2ma-verification=fu2 tn9dGsCpd6YZrmWG6O9dqw]TTL —[NRDR 36125_IN_TXT_e2ma-verification=fu2 tn9dGsCpd6YZrmWG6O9dqw]TTL —[NRDR 37073_IN_TXT_reftab-domain-verification=c24d073b23fed3af77c9e3b40010223f Kmo0sQxn82COz9etYwP/3w]TTL —[NRDR 37284_IN_TXT_airtable-verification=878daeee4665d51015a6dda912bbb9f5 GCXTwRluJG0dSxHBUrbFYA]TTL —[NRDR 37587_IN_TXT_EECD69320F38F645362247248BD675F4 vdnDjzc5a9LVXuQ6DmgOhA]TTL —[NRDR 37683_IN_TXT_A8809FFAB54BD9C6F7DFBE92616764D0 1pWIIBS0QK7rR0bt/OqwZg]TTL —00df4000000231leaaTTL —A8809FFAB54BD9C6F7DFBE92616764D0TTL —airtable-verification=878daeee4665d51015a6dda912bbb9f5TTL —apple-domain-verification=yZrPHuazhdH42CPfTTL —atlassian-domain-verification=H4RHVEsTq5YZaRen7VBly2a3AqWhfLMxAL3wBScS8EB0Pg5x1vaPhj3eXsGaUOGiTTL —cisco-ci-domain-verification=5f809f49f9d3ca48d84db537e031b2007011ea11f6410de6a8a02919908675d6TTL —docusign=048da45a-23c6-4f6b-8f96-6dff4fa6b22bTTL —e2ma-verification=fu2TTL —EECD69320F38F645362247248BD675F4TTL —facebook-domain-verification=vxpo0xkores42yfj9ggcdd2o2d2v2nTTL —google-site-verification=JopPlnNv9VupQydpE3TiwZAEod-zouxEX0inao6rgggTTL —google-site-verification=m3lUupwhWqjbGCA6JswqWyBi7tkzh-BjbRiYuC6EXTgTTL —google-site-verification=MYZf5OssFVvgYQF1snvJdiFbMjHy53WzLrnsVGkgpFUTTL —google-site-verification=O2gyijlOW-8BSOghh0tL_4N1PlWU_qznkYhUA22dLJ0TTL —google-site-verification=pNbrq7j_EeIowr_Kw1Jfy46bmFWR9p1llXH_leCdLrgTTL —MS=ms17583017TTL —r4bgkix7EqRv+dJHKYelMrye44oR+366MsSA0lCP0TOcMK8wfs0bpTMDP1tLTZ66OFh0Qx+ZMLBCeVx0NJ3syQ==TTL —reftab-domain-verification=c24d073b23fed3af77c9e3b40010223fTTL —v=spf1 include:_spf.cmu.edu ~allTTL —zoho-verification=zb38550127.zmverify.zoho.comTTL —ZOOM_verify_FruZuJfdTeW1OOezpsuIVATTL —DNS observations · no external lookup API
Domain email protection
Exact-host SPF and DMARC observations help the owner investigate email impersonation risks. They are separate from website malware checks and do not change the Safety Score.
What to do next
Review the records with your mail administrator. Inventory legitimate senders and test SPF and DKIM alignment before enforcing a stricter DMARC policy. Fix duplicate records and investigate overly permissive SPF rules.
This bounded check does not send email, probe SMTP, evaluate recursive SPF includes, verify DKIM signatures or apply organizational-domain DMARC inheritance. A missing subdomain record does not prove that no inherited protection exists. A DNS timeout is unknown, not an absent record. A policy record is not proof that messages authenticate successfully.
Responsible disclosure
security.txt
No readable security.txt file was observed at the standard locations. This is informational and is not evidence of malware.
Browser protections
Security headers
Response headers
Cookie protections
No Set-Cookie header was observed on the sampled homepage response. Other pages may set cookies separately.
Detected stack
Technologies
Versions are shown only when publicly exposed by the page or response headers. An observed version is not, by itself, proof of a vulnerability.
JavaScript library advisories
JavaScript advisory analysis could not be completed or no eligible script files were sampled. No clean result is implied.
Recommended maintenance checks
About this website
What the site says about itself
CMU pushes the boundaries of innovation and creativity across disciplines. Learn about our visionary research, rankings, mission and locations.
This is publisher supplied information. The independent safety findings are shown separately.
Publisher supplied
Public contact details
These details were observed on the website, not independently verified as an active support channel.
Structured facts
Website identity & response
Connection path
Redirect chain
The chain is shown exactly as observed by the scanner. A redirect is not itself a malware finding, but unexpected domains or an HTTP downgrade deserve review.
Compared with the previous scan
What changed
A comparison will appear after the next completed scan.
Explainable matching
Digital fingerprint
Comparable components help find technically related websites. A match does not prove common ownership.
Material changes only
Change history
No meaningful changes recorded yet.
Visual evidence
Website screenshot

For site owners
Show your verified trust report
Place this lightweight badge in your footer to show visitors an independent, dated WebsiteVirusScanner report. It can increase visitor confidence, but it never changes or guarantees the score.
Questions about cmu.edu
FAQ
Is cmu.edu safe to visit?
The latest Safety Score is 61/100 with 70% Evidence Confidence. This is a point-in-time assessment of observed technical signals, not a guarantee. Check the exact address and avoid entering payment details if anything looks unusual.
Did the scan detect malware on cmu.edu?
ClamAV found no signature match in the sampled homepage HTML. External scripts, downloads and private server files were not checked. This is not a whole-site malware clearance.
When was cmu.edu registered?
The registry lookup did not provide a reliable creation date in this scan.
Did cmu.edu have a valid TLS certificate?
The scanner observed a valid TLS certificate using TLSv1.2. A valid certificate alone does not establish that the site is safe.
How does cmu.edu describe itself?
The website's About page describes its purpose in the report above. This is publisher-supplied information and is separate from independent security findings.
Can a paid listing change this website's score?
No. Premium placement and owner-supplied pages are labelled separately. Technical evidence, the Safety Score and moderation decisions remain independent.