Is affirm.com legit?

85
/ 100
Trusted
Industry: Finance

Affirm.com appears to be a trusted and legitimate financial platform. While there are a couple of minor points of concern, such as excessive hidden content and a relatively short SSL certificate expiry, its strong foundational elements and high traffic volume suggest a reliable service.

Finance average: 80/100 · based on 48 sites

Checked: April 18, 2026 at 7:54 AM UTC · Refresh

Is affirm.com a scam? Here's what we found.

Security 88/100

The site boasts strong security with modern TLS 1.3, HSTS enforcement, and clickjacking protection. Google Web Risk found no threats, which is a major positive. The main watch-out is the higher-than-average hidden content and a shorter SSL certificate expiry, which ideally should be renewed further in advance.

Identity 95/100

The domain has a very long history, over 26 years, and is registered through MarkMonitor Inc., a reputable registrar commonly used by large corporations. This indicates a well-established and stable entity behind the website.

Reputation 95/100

With a high Tranco Rank and a clean slate on DNS blacklists, Affirm.com has a robust online reputation. The lack of a Trustpilot profile isn't a red flag for a company of this size, as they often manage feedback directly or through other channels.

Transparency 75/100

While the site has complete branding, comprehensive legal pages, and a good social media presence, the lack of readily available contact information on the homepage is a notable drawback. For a financial service, easy access to support is crucial for user trust.

Compliance 90/100

Affirm.com clearly provides both a privacy policy and terms of service, which are essential legal documents for any business, especially one handling personal financial information. This is a solid indicator of compliance.

Infrastructure 95/100

The site's infrastructure is robust, featuring multiple DNS servers, proper email authentication (SPF, DMARC), and a fast page load time. The extensive robots.txt and sitemap also point to a well-managed and optimized web presence.

Signals Detected

[+]
Tranco Rank: Rank #3152

This is a well-known, high-traffic website

[?]
Structured Data: None found

No structured data markup found

[?]
Trustpilot: No Trustpilot profile

This business has no Trustpilot presence — not unusual for smaller or newer companies

[+]
SSL Certificate: Valid

Valid certificate, expires in 84 days

[?]
Certificate Issuer: Google Trust Services

Certificate issued by Google Trust Services

[+]
TLS Version: TLS 1.3

Connection uses TLS 1.3

[+]
HSTS Header: Present

Site enforces HTTPS via HSTS

[+]
Clickjacking Protection: Present

X-Frame-Options: SAMEORIGIN

[?]
Server: cloudflare

Web server: cloudflare

[+]
Google Web Risk: Clean

No threats detected by Google Web Risk

[~]
Hidden Content: 125 hidden elements

Excessive hidden content found — may indicate cloaking or deceptive content

[+]
Domain Age: 26 years, 9 months

Domain created 1999-12-02T11:39:45Z (26 years, 9 months ago)

[?]
Registrar: MarkMonitor Inc.

Registered through MarkMonitor Inc.

[+]
Domain Expiry: 2027-12-02T11:39:44Z

Expires in 593 days

[+]
DNSSEC: unsigned

DNSSEC status from WHOIS

[+]
DNS Blacklists: Clean

Not found on any DNS blacklists

[+]
Branding: Complete

Site has custom branding and social media metadata

[+]
robots.txt: Present

robots.txt has 40 directives and references a sitemap

[+]
Sitemap: 325 pages

Site maintains a proper sitemap with 325 indexed pages

[+]
Website Status: Online

Website is live and responding

[~]
Contact Info: Not found

No obvious contact information found on homepage

[+]
Legal Pages: Privacy & Terms found

Website has both privacy policy and terms of service pages

[+]
Social Media Presence: 4 platforms

Website links to multiple social media platforms

[+]
DNS Resolution: 2 IP(s)

Resolves to: 162.159.140.33, 172.66.0.33

[+]
Email (MX Records): 3 record(s)

Mail servers: mailstream-central.mxrecord.mx., mailstream-west.mxrecord.io., mailstream-east.mxrecord.io.

[+]
SPF Record: Present

Domain has SPF email authentication configured

[+]
DMARC Record: Present

Domain has DMARC email authentication configured

[+]
Name Servers: 4 server(s)

DNS providers: ns-1890.awsdns-44.co.uk., ns-217.awsdns-27.com., ns-614.awsdns-12.net., ns-1463.awsdns-54.org.

[?]
Web Archive: Unable to check

Could not query Wayback Machine

[?]
Certificate Transparency: Unable to check

Could not query certificate transparency logs

[+]
Page Load Time: 475ms

Fast page load

Embed This Badge

Own this site? Show visitors your trust score.

Trust badge for affirm.com
<a href="https://verified.fyi/review/affirm.com"><img src="https://verified.fyi/badge/affirm.com?size=medium&style=full&theme=dark" alt="affirm.com trust score — verified.fyi" /></a>
[![affirm.com trust score](https://verified.fyi/badge/affirm.com?size=medium&style=full&theme=dark)](https://verified.fyi/review/affirm.com)

Stay Safe Online

Good habits to protect yourself, no matter the scan result.

Use a password manager

Never reuse passwords across sites.

Enable two-factor authentication

Add a second layer of security to your accounts.

Check before you buy

Always verify unfamiliar stores before entering payment info.

When evaluating a financial technology platform like Affirm.com, it’s crucial to look beyond surface-level information. Affirm operates in the 'buy now, pay later' space, which inherently deals with sensitive financial data and lending practices. A legitimate service in this industry should exhibit robust security, clear operational transparency, and a well-established digital footprint. Affirm.com checks many of these critical boxes. Their long domain history, dating back over 26 years, signifies a deeply rooted and persistent presence, far exceeding what you'd expect from a fly-by-night operation. Companies handling financial transactions typically invest heavily in their foundational security, and Affirm's use of modern TLS 1.3, HSTS, and clickjacking protection aligns perfectly with industry best practices. For a financial platform, accessible customer support is paramount. While Affirm provides legal documents like privacy policies and terms of service – a definite plus for compliance – the absence of direct contact information from the homepage is a drawback. Users of financial services often need quick access to support. Reputable fintech companies often highlight their customer service options, including phone numbers, email, or chat, directly on their main pages. This is one area where Affirm could enhance user reassurance. Despite this, the overall impression is one of a professional and secure financial service.