ProviderCheck

How does ProviderCheck work?

ProviderCheck is an independent platform that reports what was declared, detected, verified, unable to verify, or requires review for hosting and infrastructure providers.

Check a provider

What is ProviderCheck?

We support buyers, verified operators, and technology partners by making verification status clearer. We do not publish scam, fraud, or safety scores. Payment starts a process — it never purchases Verified status.

How do I check a provider?

  1. 1

    Copy the provider's URL

  2. 2

    Paste it into the search bar

  3. 3

    Select the provider & view results

For buyers

Check a domain before you buy hosting, cloud, or related infrastructure services.

  • Search without creating an account
  • See verification status and coverage facts
  • Suggest a provider if it is not listed yet

For operators

Complete independent review and show a live Trust Seal on authorized domains.

  • Evidence-based verification workflow
  • Live seal linked to your public report
  • Continuous monitoring after approval

For technology partners

Help keep detection, licensing, and verification language accurate across the market.

  • Clear separation of detected vs verified
  • Source outages do not become Not Found
  • Partnership does not auto-verify operators

What Does ProviderCheck Verify?

ProviderCheck combines technical checks with authorized manual review where automated verification is unavailable.

Company Identity

We review available company and provider information to help confirm who operates the service — including business identity, ownership signals, website and submitted corporate evidence.

Domain Ownership

We verify that the provider controls the domains associated with its ProviderCheck profile via DNS TXT, verification file, meta tag, or manual review.

Software & Licensing

ProviderCheck distinguishes software detection from license verification. Detected does not automatically mean licensed. Unable to verify does not automatically mean unlicensed.

Infrastructure

Checks may include hosting infrastructure signals, endpoints, DNS, SSL/TLS, nameservers and publicly observable infrastructure.

Network & ASN

May include ASN, IP ownership/routing, network provider, reverse DNS, nameserver infrastructure and consistency signals.

Security Signals

May include HTTPS, SSL validity, DNS configuration, email security signals and relevant public technical findings. ProviderCheck is not a penetration test.

ProviderCheck Manual Review

Where reliable automated verification is unavailable, authorized ProviderCheck reviewers may review available evidence manually.

What each verification category covers

Every category is reported separately. A category we could not verify is never merged into a category we did.

Company Identity

What we check
Legal or trading name, country of registration, and registration identifiers supplied by the provider.
Evidence we rely on
Documents reviewed by a ProviderCheck analyst, plus public registry lookups where a registry is accessible.
What this does not prove
It does not audit the company finances, its ownership structure, or its conduct with customers.

Domain Ownership

What we check
That the applicant controls the domain, via a DNS TXT record, a meta tag, or a .well-known file challenge.
Evidence we rely on
The challenge response observed directly by our checker at the time of verification.
What this does not prove
It does not prove who owns the underlying company, only who controls the domain.

Infrastructure

What we check
DNS records, TLS certificate validity and hostname match, and reachability of the primary domain.
Evidence we rely on
Direct technical observation from our own checks, with SSRF protection on every request.
What this does not prove
It does not measure uptime, performance, or capacity, and it is not a security audit.

Network Context

What we check
The announcing network for the primary address, the responsible registry, and the routing context.
Evidence we rely on
Public registry and routing data recorded at check time.
What this does not prove
It does not confirm that the provider owns the network, only which network answers for the domain.

Software Detection

What we check
Publicly observable signals that suggest which control panel or server software is in use.
Evidence we rely on
Passive signals from public endpoints and response fingerprints.
What this does not prove
Detected is not licensed. A detection signal says software appears to be present, nothing more.

License Verification

What we check
Whether a license for detected software can be independently confirmed with the vendor or by reviewed evidence.
Evidence we rely on
Vendor sources where a machine-readable source exists, otherwise documented manual review by an analyst.
What this does not prove
Most vendors publish no public license API. Where we cannot confirm, we say Unable to Verify rather than guess.

Continuous Monitoring

What we check
Re-observation of DNS, TLS, seal installation and license review dates between verification cycles.
Evidence we rely on
Scheduled monitoring runs recorded against the provider profile.
What this does not prove
Monitoring raises findings for human review. It never grants, extends, or withdraws verification on its own.

Not Applicable is not the same as Failed

Four different outcomes are often collapsed into one word elsewhere. We keep them apart, because they mean very different things.

Verified

We checked this category and the evidence supported it.

Not Applicable

This category does not apply to this provider. For example, there is no license to verify for software the provider does not run. Nothing failed here, and it counts neither for nor against the provider.

Unable to Verify

The category applies, but no authoritative source was available to us — commonly because the vendor publishes no public license check. This is a limit of our access, not a finding against the provider.

Failed

We checked this category and the evidence contradicted the claim, or a required check did not pass. This is a finding against the claim, and it blocks verification until it is resolved.

The coverage score counts how much of the checklist we could complete. Categories marked Not Applicable are excluded from the calculation rather than counted as failures, so a provider is never penalised for software it does not run.

Once a provider is verified, monitoring keeps observing the same signals. A change is recorded and reviewed by a person; a temporary network failure is recorded as a temporary failure and never as a verification problem.

What the coverage score means

The coverage score reflects how much of our verification checklist could be completed for this provider. It is not a quality rating, a ranking, or a recommendation.

A higher score never means "better provider" — only "more of the checklist was verifiable".

The score is only shown while verification is active.

Verification statuses

Statuses are evidence-based. Not Verified does not mean untrusted.

Verified

Provider currently has an active ProviderCheck verification.

Review Required

Additional review is required.

Not Verified

No active ProviderCheck verification is currently available.

Verification Expired

Previous verification is no longer current.

Verification Issue

An unresolved verification issue exists.

ProviderCheck distinguishes between software detection and license verification. Detecting software does not by itself confirm that the software is licensed.

Unable to verify does not mean unlicensed.

Payment starts the verification process and does not guarantee approval. Verification integrity cannot be purchased.

Expired verification is not the same as high risk or fraud.

Methodology in detail

What We Check

Domain ownership, DNS/SSL, network/ASN signals, software fingerprints, license sources where available, company identity evidence, and manual analyst review.

What We Do Not Check

We do not certify service quality, uptime SLAs, or legal compliance. Not Verified does not mean untrustworthy.

Software Detection

Passive fingerprints. Detection is observational and separate from licensing.

License Verification

Confirmed only via documented vendor sources or audited manual evidence. Timeouts never become License Not Found.

Company Verification

Legal/trading names, country, registration identifiers, and private supporting documents.

Domain Ownership

DNS TXT, meta tag, or .well-known file challenges.

Technical Checks

DNS, SSL/TLS, RDAP, email security, and network context via queued jobs with SSRF protection.

Manual Review

Analysts review incomplete automation and evidence before a final decision.

Continuous verification

A verification is a decision made on a date, and we do not leave it there. Once a provider is verified we re-observe the technical signals behind that decision on a schedule: the primary domain, its DNS records, the TLS certificate, the announcing network, software signals, licence review dates and whether the trust seal is still installed. Each observation is stored with the provider, so a change has a before and an after rather than appearing out of nowhere. Monitoring reports; it does not decide. A finding is queued for a ProviderCheck analyst, and only a person can suspend, revoke or renew a verification. Where our own checks fail — a blocked request, a source that publishes nothing — that is recorded as a limit of our access, not as a finding against the provider.

Verification Coverage & Score

Coverage measures methodology completeness. Domain+SSL alone never yield Verified.

Expiration

Typically 12 months. Expired seals show Verification Expired — not High Risk.

Revocation & Suspension

Suspension is temporary review. Revocation withdraws Verified status with audit logging.

Appeals / Corrections

Providers may request review with additional evidence. Appeals do not automatically change status.

Continuous verification

What happens after a provider is verified.

Is verification a one-off check?

No. Verification is a decision made on a date, and after that we keep re-observing the technical signals behind it on a schedule. Each observation is recorded against the provider profile.

Does monitoring remove a provider's verification automatically?

Never. Monitoring records findings and asks a ProviderCheck analyst to review them. Only a person can suspend or revoke a verification, and the reason is published on the provider profile.

What happens if your checks cannot reach a provider?

It is recorded as a temporary observation failure, not as a finding against the provider. Many hosts legitimately block automated requests, and our inability to look is a limit of our access rather than evidence of a problem.

What does "verified since" mean?

It is the start of the current uninterrupted verification period. If a verification lapses, expires or is revoked, the clock resets when it is reinstated — we never advertise continuity that does not exist.

What happens when a verification period ends?

The provider re-applies and the evidence is reviewed again. When the new certificate is issued, the previous one is marked superseded rather than expired, because the verification itself was never interrupted.

Trust should be checkable.

Look up a provider, explore the Trust Seal, or apply for verification.