Is discover.com legit?
This site appears highly trustworthy, showing strong security practices and a long-established online presence. You can proceed with confidence, as it meets the high standards expected for a major financial institution.
Finance average: 80/100 · based on 48 sites
Checked: April 18, 2026 at 7:45 AM UTC · Refresh
Is discover.com a scam? Here's what we found.
The site employs top-tier security protocols, including current TLS 1.3 encryption, HSTS, robust content security, and effective clickjacking protection. Google Web Risk also confirms no threats, which is crucial for a financial service.
With a domain tenure exceeding 32 years, discover.com demonstrates an exceptional track record and long-term commitment. Its registration through a corporate registrar further reinforces its institutional identity and stability.
The moderate global traffic and extensive operational history, free from blacklists, confirm its established reputation. While a Trustpilot profile is absent, this is less critical given the site's age and brand recognition.
The presence of clear contact information and active social media channels indicates a transparent operation, making it easy for users to find support and engage with the company directly.
Comprehensive legal pages, including both a privacy policy and terms of service, are clearly in place. This signals a commitment to user rights and regulatory compliance, which is essential for financial institutions.
The robust DNS configuration, including DNSSEC and full email authentication (SPF, DMARC), highlights a professional and well-managed internet infrastructure. Fast page load times also contribute to a reliable user experience.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: Organization, WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1993-11-15T05:00:00Z (32 years, 10 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 209 days
DNSSEC status from WHOIS
Valid certificate, expires in 100 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: Apache
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
Resolves to: 23.197.138.28
Mail servers: mxb-001d7a03.gslb.pphosted.com., mxa-001d7a03.gslb.pphosted.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: a1-23.akam.net., a4-64.akam.net., a8-66.akam.net., a5-67.akam.net., a3-64.akam.net., a6-65.akam.net.
robots.txt has 37 directives and references a sitemap
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Not found on any DNS blacklists
No sitemap found — common for smaller sites
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.