Is calendly.com legit?
Calendly.com appears to be a trusted and well-established service. While there are some minor concerns regarding external scripts and hidden content, its strong security, identity, and compliance signals outweigh these issues.
SaaS average: 82/100 · based on 62 sites
Checked: April 28, 2026 at 1:07 AM UTC
Is calendly.com a scam? Here's what we found.
The site uses modern TLS 1.3, has a valid SSL certificate from a reputable issuer, and is clean according to Google Web Risk, indicating a robust security posture. However, the presence of numerous external scripts introduces a slight potential for vulnerability.
Calendly.com benefits from a significant domain age of over 13 years and public WHOIS information, which builds trust and indicates a well-established entity. While the registrar is neutral, the overall profile is strong.
The website holds a very high Tranco rank, indicating global popularity and widespread usage. It is not found on any DNS blacklists, which is a strong positive sign for its reputation.
Calendly transparently provides contact information, legal pages, and a strong social media presence. However, the discovery of a high number of hidden elements raises some concerns about complete content transparency.
The site clearly provides both privacy and terms of service pages, demonstrating a commitment to legal and user data compliance. The robust branding also suggests a professional and regulated entity.
The infrastructure is well-configured with DNSSEC, multiple IP addresses for DNS resolution, active DMARC, and clear name servers, all contributing to a reliable and secure technical foundation.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: Organization, WebSite
Domain created 2013-02-26T19:50:41Z (13 years, 4 months ago)
Registered through GoDaddy.com, LLC
Expires in 304 days
DNSSEC status from WHOIS
Valid certificate, expires in 71 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
This business has no Trustpilot presence — not unusual for smaller or newer companies
Site has custom branding and social media metadata
Resolves to: 2a06:98c1:3107::ac40:9251, 2606:4700:4402::6812:29af, 104.18.41.175, 172.64.146.81
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., aspmx3.googlemail.com., aspmx2.googlemail.com.
Domain has DMARC email authentication configured
DNS providers: hope.ns.cloudflare.com., roan.ns.cloudflare.com.
robots.txt has 17 directives and references a sitemap
Excessive number of external scripts — may indicate malicious injection
Excessive hidden content found — may indicate cloaking or deceptive content
crt.sh returned status 429
Site enforces HTTPS via HSTS
Web server: cloudflare
No threats detected by Google Web Risk
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
No sitemap found — common for smaller sites
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.