Dallas, TX · serving Dallas–Fort Worth · remote across Texas Remote support 24/7/365, including US holidays [email protected]

Hiring an IT company

How to check that an IT company is legitimate

A verification checklist anyone can run in fifteen minutes before handing an IT provider the keys to the business, plus what a legitimate provider will happily show you.

Written and reviewed by Anthony Omini, Cross River Tech·9 min read·Published · Updated

How do I know if an IT company is legitimate?

You can verify most of it in fifteen minutes. Look up the business name in Texas Secretary of State and Comptroller records, confirm a real address and a phone a person answers, check email is on the company domain, read reviews that describe specific work, look at the owner's LinkedIn history, ask for two references and a written agreement, and see how they handle passwords.

Answered by Anthony Omini, Cross River Tech, Dallas

Open notebook with handwritten notes, pens and reading glasses on a desk

Key takeaways

  • Texas business records, a real address, a domain email and a phone a person answers rule out most fakes in ten minutes.
  • Read reviews for named people and specific work; a burst of short praise in one week is a warning, not a recommendation.
  • Ask for two references in your industry and actually call them; a refusal is an answer.
  • Nothing should start without a written scope, and no legitimate provider needs your passwords on a first call.
  • The strongest signal is how a provider handles your accounts: your business must own its domain, tenant and firewall configuration.

How do I know if an IT company is legitimate?

Verify four things and the question is largely settled: the business exists on public record, a real human answers the phone at a real address, the work history is traceable to a named person, and everything is put in writing before anyone touches your systems. Each of those takes a few minutes to check, and together they filter out almost everyone you would regret hiring.

This matters more for IT than for most trades. A landscaper who turns out to be unreliable costs you a lawn. An IT provider holds administrator access to your email, your files, your backups and your network, which means the damage from choosing badly is not limited to money. That is why it is entirely reasonable to run checks, and why nobody serious will take offence when you do. I would think less of a client who did not.

What follows is the order I would run the checks in, from cheapest to most involved. Stop as soon as something fails.

What can you verify in the first ten minutes?

Five public checks, no phone calls required.

  • Business registration. Search the company name in the Texas Secretary of State business search and in the Comptroller's taxable entity search. A registered LLC or corporation with a filing history is a strong baseline. A sole proprietor may trade under an assumed name filed with the county, which is also legitimate; what you are looking for is a name that exists somewhere official.
  • An address that is a place. Put it into a map and look at it. A commercial address, a suite or a home office in Dallas is fine. A mailbox store address presented as an office suite is not fraud, but it is worth asking about. No address at all on a website is a flag.
  • Email on the company domain. A provider whose contact address is a free consumer mailbox is telling you something about how the business is set up. Mine is on the company domain, and any IT provider's should be.
  • The website itself. Does it name a person? Does it publish a phone number and an address? Does it say what is and is not included? Stock photographs of a fake team in a glass office are worth noticing when the same site claims a single location.
  • Domain age and consistency. A brand-new domain does not mean a scam, but a new domain plus a long list of client logos plus no named owner is a pattern.

None of these prove competence. They prove existence, which is the first thing to establish.

How do you verify the people behind the company?

Behind every legitimate small IT provider there is a person with a traceable career. Find that person.

  • Find the owner by name. A website that never names anyone is unusual for a small provider. I put my name on mine: I am Anthony Omini, and Cross River Tech is based in Dallas, TX 75215.
  • Read the LinkedIn profile, not the headline. Look at employers, roles and how long each lasted. Somebody with over fifteen years of IT experience across many industries will have a history you can follow. A profile created recently with no connections and no history deserves a question.
  • Check credentials and where they are published. Ask what technical qualifications they hold and where you can see them. Mine are MCSA and CCNA, listed on my LinkedIn. Be sceptical of vague partner-tier language on a website with no named individual attached to it.
  • Look for a real presence beyond the website. A Google Business Profile, a LinkedIn company page, a chamber or BNI listing. Any of these means someone has been accountable to a local audience.
  • Ask who will actually do the work. In an owner-led company like mine the answer is a name: I plan the work and come onsite myself, and my team handles the routine monitoring and updates behind me. In a larger firm, ask whether the person in the meeting will ever appear again.

Is this Dallas IT company real, or is it a scam?

Outright scams in local IT support are less common than sloppiness, but they exist, and they follow recognisable patterns. Two are worth naming because they target businesses rather than home users.

The unsolicited support call. Someone calls or emails claiming your computers are infected, your Microsoft licensing is out of compliance, or your account has been flagged, and asks you to install a remote access tool. No legitimate provider learns about your infection before you do and cold-calls you about it. Hang up, and if anyone in the office has already installed something, treat it as a security incident and work through what to do after someone clicks a phishing email.

The invoice or bank-detail switch. A provider you do work with appears to email new bank details for payment. Verify by calling a number you already had, never the one in the email. The full pattern is in a supplier changed their bank details by email: is it fraud.

Then there is the larger grey area: a real business that is simply not what it presents itself as. Watch for these.

What you seeWhat it often means
Client logos with no case detail and no references offeredLogos may be from a previous employer, not clients
Superlatives about being the top provider, with nothing measurable behind themMarketing language rather than a claim you can check
A price far below the other two quotesA narrower scope, or add-ons arriving after signature
Pressure to sign today for a discountSales urgency; a real assessment does not expire
Asks for passwords by email before any agreementPoor security practice at best
Wants to register your domain or Microsoft tenant in their own nameControl over assets that should be yours
Will not name the technician who will do the workSubcontracting, or a revolving door
No written scope, only a verbal promise of "everything covered"Every dispute later becomes your word against theirs

How do you verify an IT support company before hiring?

Once the basics check out, these five steps take the verification from "exists" to "safe to hire".

  1. Call the main number at a random time in the working day. Note whether a person answers, how long a callback takes, and whether the caller is the person who would do the work. This single test predicts more than anything on a website.
  2. Ask for two references in your industry and call them. Ask what specifically was fixed, how long it took, what went wrong at some point and how it was handled, and whether they would hire again. The questions worth asking are set out in how to check an IT provider's references and reviews. A provider who cannot produce a single reference is telling you something.
  3. Ask for proof of business insurance. General liability, and professional liability or a cyber policy if they will hold administrative access. Request the document rather than a verbal assurance, and keep it with your vendor records.
  4. Read the agreement before you sign it. Scope, what is excluded, notice period, what happens to your data and documentation if you leave, and whether it renews automatically. A one-page document with a long auto-renewal and no exclusions is worse than a longer one that is honest about its edges, and the wider list of things to ask before you sign is in questions to ask before hiring a managed service provider.
  5. Ask how they will hold your credentials. The correct answer involves a password manager, individual named administrator accounts and multi-factor authentication, not a shared spreadsheet. What access an IT company needs explains what to grant and how to revoke it later.

What will a legitimate provider happily show you?

This is the reassuring half. Everything below is something you can ask for on a first or second conversation, and a serious provider will hand it over without hesitation.

  • Their legal business name and where it is registered.
  • A W-9, if your bookkeeper needs one to set them up as a vendor.
  • Proof of business insurance.
  • A written scope of work stating what is included, what is billed separately and what is not covered at all.
  • A sample of the documentation you would receive, with another client's details removed: an asset inventory, a network diagram, a license list.
  • Their offboarding process: what you get back, in what format, and how long it takes.
  • Two references, ideally in a similar industry or of a similar size.
  • A plain explanation of how they will access your systems and how you can revoke that access at any time.
  • Their rates in writing. Mine are published: $100 an hour remote and $150 onsite during business hours, $150 and $225 after hours, weekends and holidays, one-hour minimum. Managed IT is quoted per user or per device after a short conversation, month-to-month, cancel anytime.

Notice how much of that is paperwork rather than technology. That is the point. The technical claims are hard for a non-technical buyer to assess; the business behaviour is not, and the two correlate more strongly than you would expect.

What should never happen before you sign?

A short list of things that should stop the process regardless of how good everything else looks.

  • Being asked to email or read out passwords. Ever, but especially before an agreement exists.
  • Being asked to install remote access software during a first call that you did not initiate.
  • Being told your systems are compromised by someone who has not seen them.
  • Being pushed to buy hardware before anyone has looked at what you have.
  • Being asked to pay a large deposit by wire or card over the phone with no invoice and no written scope.
  • Being told the contract cannot be shown until you commit.
  • Being asked to transfer your domain to their account "so it is easier to manage". It is easier for them and worse for you. See who owns your passwords, domain and equipment.

If you are checking a provider because the current one has gone quiet, deal with access first and hiring second. Your IT guy stopped answering: how to take back control sets out how to recover ownership of your domain, tenant and firewall before you hand the keys to anybody new.

How do you keep verifying after you hire someone?

Verification is not a one-time gate. A provider who was excellent two years ago may have taken on too much, and quiet decay is far more common than dramatic failure. Once a year, spend an hour on these.

  • Ask for a current asset and account inventory and check it matches reality: people who left, devices you no longer own, licenses you are still paying for.
  • Ask for evidence of a real backup restore, not a green dashboard. A restored file with a date on it.
  • Review who holds administrator access to your Microsoft 365 or Google Workspace tenant, your firewall and your backups, and remove anyone who should no longer be there.
  • Check your domain registration renewal date and confirm the registrant is your business.
  • Look at your invoices as a year, not as monthly line items. Recurring charges for tools nobody uses are common.
  • Confirm the insurance is still current.

That annual hour is the same discipline as the wider review in the annual IT check-up every Dallas office should run, and it is the cheapest protection available to a small business.

If you would like to run these checks on me, please do. Look up the business, call (214) 612-7080 and see who answers, ask for references and read the scope before signing anything. When you are ready, get in touch and I will send a written scope for managed IT or a quote for consulting work, whichever fits.

Questions people ask

How can I check that an IT company is a real registered business in Texas?

Search the company name in the Texas Secretary of State business search and the Comptroller's taxable entity search. Both are free and public. A sole proprietor may instead have an assumed name filed with the county, which is equally legitimate. What you want is a name that appears somewhere official and matches the name on the quote, the invoice and the bank details.

Is it rude to ask an IT provider for references and insurance?

No, and the reaction tells you a great deal. You are about to give this provider administrative access to your email, files and backups. Any provider who runs a real business expects to be asked for a written scope, proof of insurance and two references, and has them ready. Offence at a standard vendor question is itself a useful answer.

What is the biggest warning sign when hiring IT support?

Wanting control of assets that should belong to you. If a provider registers your domain or your Microsoft 365 tenant in their own name, keeps the only administrator credentials, or will not hand over documentation, they have built a business on making you hard to leave. Everything else on a red-flag list is recoverable. That one takes weeks to unwind.

Should I worry if an IT company has no reviews?

Not on its own. Plenty of good providers grow entirely on referrals and never ask anyone to write a review. Treat an empty profile as neutral and lean harder on the other checks: business registration, a traceable work history, two references you actually call, and a written scope. A burst of short five-word reviews posted the same week is more concerning than none.

Should an IT provider ask for my passwords?

Not for individual users, and never by email. A provider should be granted its own named administrator account in your Microsoft 365 or Google Workspace tenant, with multi-factor authentication, so every action is attributable and access can be revoked in a minute. Shared credentials for legacy systems that genuinely cannot do this belong in a password manager, not in a spreadsheet or an email thread.

How do I verify an IT company if I am not technical?

Almost none of the checks are technical. Business registration, an address on a map, a phone a person answers, a LinkedIn history, two reference calls, proof of insurance and a written scope are all things any office manager can verify in an afternoon. Judge the business behaviour, and bring in a technical opinion only for comparing the actual work in competing quotes.

Anthony Omini

Written and reviewed by

Anthony Omini, founder of Cross River Tech

Over 15 years in IT across many industries, now running Cross River Tech, a small owner-led managed IT company in Dallas. Every article is written from his own client work and checked by him before it is published.

Run the checks on me Look up the business, call the number and see who answers, then ask for a written scope and references. When you are ready, tell me about your office and I will send a quote you can compare.

Let's fix it — or plan it.

Call, or send a short request and I will get back to you personally.

Call now Get a quote

Free, no-obligation quote

Tell me what is going on

Three quick steps. I read every request myself and reply personally, usually the same business day.

What can I help with?

Pick the closest option. There is room to explain in a moment.

or call (214) 612-7080