Is canva.com legit?
Canva.com appears mostly safe due to its strong technical foundation and widespread recognition. However, significant red flags around missing crucial legal pages and contact information mean users should proceed with caution.
SaaS average: 81/100 · based on 62 sites
Checked: April 12, 2026 at 10:18 PM UTC · Refresh
Is canva.com a scam? Here's what we found.
While technical security is strong with TLS 1.3, HSTS, and clean Google Web Risk results, the HTTP 403 status is concerning for user access and functionality, preventing a higher score.
This domain boasts impressive longevity at 24 years, with a clear registration through a known registrar, indicating a well-established and long-standing presence.
With a high Tranco rank (one of the most visited sites globally) and clean DNS blacklists, Canva has a very strong reputation, despite a middling Trustpilot score that doesn't fully capture its market standing.
Transparency is a significant weak point, with no obvious contact information or social media links on the homepage, making it difficult for users to connect or resolve issues directly.
The complete absence of a privacy policy and terms of service is a critical compliance failure, which is especially problematic for a service handling user-generated content and personal data.
The underlying infrastructure is robust, featuring modern DNSSEC, SPF, and DMARC records, alongside multiple IP addresses and efficient page load times, signaling a well-managed technical backend.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
Valid certificate, expires in 249 days
Certificate issued by Amazon
Connection uses TLS 1.3
Domain created 2001-05-05T00:03:52Z (24 years, 3 months ago)
Registered through Gandi SAS
Expires in 1483 days
DNSSEC status from WHOIS
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
No sitemap found — common for smaller sites
Not found on any DNS blacklists
Website returned status 403
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
robots.txt has 225 directives and references a sitemap
Trustpilot rating: 3.7/5 based on 4270 reviews
Resolves to: 2600:9000:2130:1e00:b:add6:7500:93a1, 2600:9000:2130:1800:b:add6:7500:93a1, 2600:9000:2130:6200:b:add6:7500:93a1, 2600:9000:2130:9c00:b:add6:7500:93a1, 2600:9000:2130:8e00:b:add6:7500:93a1, 2600:9000:2130:400:b:add6:7500:93a1, 2600:9000:2130:a400:b:add6:7500:93a1, 2600:9000:2130:b000:b:add6:7500:93a1, 18.245.46.84, 18.245.46.29, 18.245.46.39, 18.245.46.76
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-1421.awsdns-49.org., ns-1851.awsdns-39.co.uk., ns-253.awsdns-31.com., ns-730.awsdns-27.net.
Could not query Wayback Machine
crt.sh returned status 503
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.