Home› VPN & Security› canarytokens.com
Mostly Safe

Yes — canarytokens.com looks mostly safe

70/ 100 trust score
Industry: VPN & Security Checked Jun 30, 2026 VPN & Security average: 56 33 signals
Check another site

In plain English

Canarytokens is a legitimate security tool from a real company that's been around for years. It's not a scam — it's a free service designed to help people detect breaches. The main things to note are that the site has limited contact options and doesn't use all the standard browser security protections, but for what it is, that's not a dealbreaker.

Cross-referenced 33 live signals from Google Safe Browsing, VirusTotal, WHOIS and more on Jun 30, 2026. How we score →

Where the score comes from

We look at six areas. Here's how canarytokens.com did in each.
80
Security

This site has strong, standard protections: a valid TLS certificate with modern encryption, no malware or phishing flags from Google, and a published security.txt policy for researchers. The only gap is the absence of browser security headers that guard against clickjacking and other attacks — typical for a tool site but worth noting.

85
Identity

The domain has been around for a decade and whois shows the company behind it, Thinkst, is transparent about its legal identity. A 10-year-old domain with a published business disclosure page is a strong indicator of a real, established organization.

85
Reputation

No blacklists, no Google Safe Browsing flags, and a decade of consistent web presence. The site ranks in the top 1 million websites, which reflects real usage. The web archive shows activity going back about a year, but the domain itself has been registered since 2015 — the archive gap isn't a red flag for a specialized security tool.

70
Transparency

The site has a legal-entity disclosure page (Impressum) that names the company behind it, which is good. However, contact information is limited — there's no obvious phone number or physical address outside the legal disclosure, and the site is a single-page app that makes it harder to find details. For a free security tool, this is acceptable, though not exceptional.

85
Compliance

Privacy policy and terms of service are present, and the site also has a security.txt vulnerability disclosure policy. For a free service that doesn't collect payment details, this meets and slightly exceeds what's expected. The legal disclosure page satisfies EU requirements.

65
Infrastructure

Basic setup is fine: fast load times, reliable hosting on AWS, and a valid SSL certificate. But there are no MX records (the domain doesn't handle email), DNSSEC isn't enabled, and the site doesn't set common browser security headers. None of these are alarming for a tool that primarily serves detection tokens, but a more robust configuration would be better.

What we checked

The 33 signals behind this report.
Security & Transport
Certificate Issuer
Let's Encrypt
Google Web Risk
Clean
SSL Certificate
Valid
Security Headers
0 of 6
Server
nginx
TLS Version
TLS 1.3
security.txt
Present
Identity & WHOIS
Branding
Complete
Business Disclosure
Found
Contact Info
Unable to check
Domain Age
10 years, 0 months
Domain Expiry
2027-07-30T13:24:22Z
Legal Pages
Privacy & Terms found
Registrar
Gandi SAS
Infrastructure & DNS
DNS Blacklists
Clean
DNS Resolution
1 IP(s)
DNSSEC
Not enabled
DNSSEC
unsigned
Email (MX Records)
None
Hosting Network (ASN)
AS16509 AMAZON-02
Name Servers
1 server(s)
Page Load Time
151ms
Reputation & Reach
Page Description
Canarytokens is a free tool that helps you discover you’ve been breached by having attackers announce themselves. Th...
Page Language
en
Page Title
Canarytokens
Sitemap
Misconfigured
Social Media Presence
Unable to check
Structured Data
None found
Tranco Rank
Rank #119165
Trustpilot
No Trustpilot profile
Web Archive History
1 years
Website Status
Online
robots.txt
Present

Run this site? Show your score.

Add a trust badge so visitors can see your live score for themselves.

Get your badge →
verified.fyi
canarytokens.com
70
N Partner pick
This site checks out. Stay covered everywhere: NordVPN's Threat Protection blocks known scam sites before they load.
Try NordVPN →

If you've come across Canarytokens.com and wondered whether it's safe to use, the short answer is yes. This is a free security tool from a real company, Thinkst, that has been operating since 2015. It lets you create small digital traps — called canary tokens — that alert you if an attacker touches them inside your network. Security professionals and IT teams use it regularly.

What do the signals tell us? The domain is a decade old, the SSL certificate is valid, and Google hasn't flagged it for malware or phishing. There's a published legal disclosure page with the company details, plus privacy and terms pages. The site is hosted on Amazon's reliable infrastructure and loads fast. Is Canarytokens.com a scam? No — the evidence points to a legitimate security tool, not a fake or deceptive operation.

What should you watch for with a site like this? Since it's a free tool, you're not handing over payment details, but you may enter email addresses or API keys. The site has a security.txt file for responsible disclosure, meaning they take vulnerability reports seriously. The main limitations are sparse contact info and the absence of some browser security headers — minor concerns for a tool that doesn't process payments. If you're looking for Canarytokens.com reviews from the infosec community, you'll generally find positive feedback from real users. It's not a fake site; it's a niche utility that does exactly what it says.

More VPN & Security sites

How similar sites score. See all →