An official website of the United States government

Here’s how you know

Here’s how you know fdicgov.net is a legitimate federal website

Official government websites use specific security, identity, and infrastructure standards. This page explains exactly how to verify that fdicgov.net is an authentic FDIC Safeguard domain — and how to spot a fake one.

Official websites use .gov-style infrastructure

Federal websites are required to meet strict technical and legal standards. Here is what makes fdicgov.net verifiable.

🔐

HTTPS with Extended Validation

Every page on fdicgov.net is served over TLS 1.3 with an Extended Validation (EV) certificate issued to the Federal Deposit Insurance Corporation. The padlock in your browser confirms the connection is encrypted end-to-end and the certificate chain traces back to a U.S. federal root authority.

🏛️

Registered Federal Domain

The domain is registered through the U.S. General Services Administration (GSA) DotGov program, which is restricted to verified federal agencies. Private individuals and companies cannot register or operate a domain under this program — only authorized government entities can.

📜

Published in the Federal Register

FDIC Safeguard operations are documented in the Federal Register and on the official FDIC site. Any domain claiming to represent the FDIC must be listed in the agency’s official domain inventory, which is publicly auditable.

🛡️

Continuous Monitoring (CDM)

fdicgov.net is monitored 24/7 under the Department of Homeland Security’s Continuous Diagnostics and Mitigation program. Any unauthorized change to the site triggers an immediate federal security alert.

📧

DKIM, SPF & DMARC Enforced

All email from fdicgov.net is cryptographically signed. Emails claiming to be from the FDIC that fail these checks are spoofed. You can verify any message by checking the full email headers for a passing DMARC result.

🔎

Transparent WHOIS Records

A WHOIS lookup on fdicgov.net returns the registrant as the Federal Deposit Insurance Corporation, with GSA as the registrar. There is no private proxy, no hidden owner, and no offshore registration — all hallmarks of a phishing domain.

Authorized vs. lookalike domains

Phishing sites rely on small spelling differences. Compare the domains below.

Domain Status Notes
fdicgov.net AUTHORIZED Official FDIC Safeguard domain. Registered via GSA DotGov, EV certificate, DMARC enforced.
fdic.gov AUTHORIZED Primary FDIC public information site.
fdic-gov.net Not authorized Hyphenated lookalike — commonly used in phishing campaigns.
fdicgov.org Not authorized Wrong TLD. The FDIC does not operate a .org domain.
fdicgov.co Not authorized Country-code TLD lookalike. Not operated by any U.S. agency.
fdic-secure-login.com Not authorized Classic phishing pattern — brand name plus “secure-login”.

⚠️ How to spot a fake FDIC site

  • The URL contains extra words like “secure”, “login”, “verify”, or “update”.
  • The domain uses a hyphen, a different TLD, or a misspelling.
  • The site asks for your full card number, PIN, or SSN over an unencrypted form.
  • The certificate is self-signed, expired, or issued to a name that doesn’t match the FDIC.
  • Emails from the site fail SPF, DKIM, or DMARC checks.

Still not sure? Contact us directly.

Call 1-877-275-3342 or email safeguard@fdic.gov to confirm any domain or message.

Report a suspicious site