Is bilibili.com legit?
While bilibili.com shows strong technical infrastructure and a long-standing web presence, users should proceed with some caution due to significant gaps in transparency and compliance, particularly the missing legal pages which are crucial for user trust and data privacy.
Entertainment average: 79/100 · based on 15 sites
Checked: April 21, 2026 at 12:44 PM UTC
Is bilibili.com a scam? Here's what we found.
The site has a robust security setup with a valid SSL certificate and modern TLS 1.3 encryption, and it passes Google Web Risk checks, indicating a secure browsing experience.
The domain has been established for over two decades, which is a strong indicator of legitimacy, despite the registrar being an Alibaba affiliate, which is standard for Chinese companies.
Its high Tranco rank confirms its global prominence, and the clean DNS blacklist status further supports its reputable standing, even though external trust signals like Trustpilot are absent.
This category is a weak point, with missing contact information and social media links making it difficult for users to connect or understand the site's public face.
The complete absence of crucial legal pages like privacy policies or terms of service is a significant concern, leaving users with no clear understanding of their rights or data usage.
The site benefits from well-configured email authentication (SPF, DMARC) and robust DNS, ensuring reliable email communication and domain integrity.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2004-10-21T11:37:37Z (21 years, 9 months ago)
Registered through Alibaba Cloud Computing (Beijing) Co., Ltd.
Expires in 2008 days
DNSSEC status from WHOIS
Resolves to: 139.159.241.37, 8.134.50.24, 47.103.24.173, 119.3.70.188
Mail servers: mgw.bilibili.co., bilibili-com.mail.protection.partner.outlook.cn.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns3.dnsv5.com., ns4.dnsv5.com.
crt.sh returned status 502
Valid certificate, expires in 235 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.3
Site maintains a proper sitemap with 8 indexed pages
robots.txt has 31 directives
Site has a favicon but no social sharing metadata
No threats detected by Google Web Risk
Website is live and responding
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
Could not query Wayback Machine
Not found on any DNS blacklists
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.