Is 1password.com legit?
1Password.com appears to be a highly trustworthy website, backed by a long-standing domain and robust security measures. While there are a few minor areas for improvement, particularly regarding external scripts and DNSSEC, these don't detract significantly from its overall reliability as a password management service.
SaaS average: 81/100 · based on 62 sites
Checked: April 18, 2026 at 7:53 AM UTC · Refresh
Is 1password.com a scam? Here's what we found.
The site employs strong security protocols like TLS 1.3 and HSTS, and Google Web Risk found no threats. The high number of external scripts is a slight concern that could increase vulnerability if not managed carefully.
With a domain age of over 22 years, 1Password.com demonstrates strong historical credibility and stability in its online presence, suggesting a well-established company.
The extremely high Tranco Rank signifies a well-known and heavily trafficked website, reinforcing its established reputation. The absence of a Trustpilot profile is not unusual for a B2B or specialized SaaS company, and certainly doesn't detract from its positive standing.
The site clearly presents contact information, legal pages, and maintains an active presence across multiple social media platforms, indicating a commitment to open communication and accessibility for its users.
The presence of both a privacy policy and terms of service pages shows a responsible approach to user data handling and legal obligations, which is crucial for a service managing sensitive information like passwords.
The site benefits from a robust infrastructure with Cloudflare and diverse DNS providers, fast page loads, and comprehensive email authentication. However, the lack of DNSSEC is a minor oversight that could be addressed for an even more resilient setup.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 43 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Site has custom branding and social media metadata
crt.sh returned status 429
Domain created 2003-11-30T04:56:20Z (22 years, 8 months ago)
Registered through Tucows Domains Inc.
Expires in 344 days
DNSSEC status from WHOIS
Site maintains a proper sitemap with 10 indexed pages
Excessive number of external scripts — may indicate malicious injection
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
Web server: cloudflare
No threats detected by Google Web Risk
Resolves to: 2a06:98c1:58::18b, 2606:4700:7::18b, 162.159.141.147, 172.66.1.143
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., aspmx3.googlemail.com., aspmx2.googlemail.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-1527.awsdns-62.org., ns-1850.awsdns-39.co.uk., ns-671.awsdns-19.net., ns-109.awsdns-13.com.
robots.txt has 4 directives and references a sitemap
Not found on any DNS blacklists
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.