Is depop.com legit?
Depop.com appears to be a mostly safe platform, primarily due to its long-standing domain, high traffic, and robust technical security. However, significant compliance gaps like missing legal pages and an inaccessible website status raise concerns that users should be aware of.
E-commerce average: 71/100 · based on 28 sites
Checked: April 18, 2026 at 8:02 AM UTC · Refresh
Is depop.com a scam? Here's what we found.
The site boasts strong technical security, featuring modern TLS 1.3, an HSTS header, and clickjacking protection. Google Web Risk also confirms no immediate threats, providing a solid foundation for user safety.
With a domain age of over 20 years and a well-known registrar like Amazon, Depop.com projects a very strong and established identity, indicating it's not a fly-by-night operation.
Its high Tranco rank confirms a significant and well-established online presence. While a missing Trustpilot profile is noted, it doesn't detract significantly from the overall solid reputation based on traffic and domain age.
While contact information is present, the absence of social media links on the homepage and basic branding suggest less transparency or engagement than a major marketplace might typically offer. The website returned 403, which is concerning for accessibility.
The critical absence of a privacy policy and terms of service is a major compliance issue for a platform handling user data and transactions, indicating a significant legal gap.
Despite generally good infrastructure including robust DNS and email authentication, the HTTP 403 status code (Forbidden) when trying to access the website is a significant functional problem. This indicates users might be blocked from accessing the site, compromising its utility.
Signals Detected
No structured data markup found
This is a well-known, high-traffic website
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2006-02-08T22:05:23Z (20 years, 5 months ago)
Registered through Amazon Registrar, Inc.
Expires in 296 days
DNSSEC status from WHOIS
Site has a favicon but no social sharing metadata
Valid certificate, expires in 48 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
No robots.txt file — common for small sites
Resolves to: 2a06:98c1:58::db, 2606:4700:7::db, 162.159.140.221, 172.66.0.219
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-522.awsdns-01.net., ns-1277.awsdns-31.org., ns-1995.awsdns-57.co.uk., ns-367.awsdns-45.com.
Website returned status 403
Website appears to have contact information
No privacy policy or terms of service found
No social media links found on homepage
Not found on any DNS blacklists
No sitemap found — common for smaller sites
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.