Is drugs.com legit?
This site appears trustworthy, demonstrating a strong, long-standing online presence with excellent security and infrastructure. While bot protection prevented verification of some standard elements like contact and legal pages, this is a common anti-abuse measure that does not inherently indicate a lack of legitimacy.
Health & Wellness average: 79/100 · based on 17 sites
Checked: April 27, 2026 at 4:10 AM UTC
Is drugs.com a scam? Here's what we found.
The security posture is excellent, with a modern TLS 1.3 certificate from a reputable issuer, HSTS, CSP, and no Google Web Risk threats or DNS blacklist hits. This indicates robust protection for user data and a low risk of malware.
The domain has a long history, dating back over 27 years, which is a strong indicator of an established and credible entity. The domain registrar is also a well-known corporate provider, adding to its legitimacy.
With a high Tranco rank and nearly three decades of existence, drugs.com has a significant and established online reputation. The clean DNS blacklist status reinforces its standing as a non-malicious entity.
While bot protection prevented direct verification of contact and legal pages, the high traffic and long domain age suggest these are likely in place. The basic branding is a minor point, but not a significant detractor from overall transparency.
The inability to check legal pages due to bot protection reduces the score slightly. However, for a site of this stature and age, it's highly probable that fundamental legal compliances are met.
The site benefits from good DNS practices, including multiple IP resolutions and comprehensive email authentication (SPF, DMARC), ensuring reliability and mail deliverability. Minor deductions reflect the absence of structured data, a sitemap, and certificate transparency verification issues due to external service problems.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 81 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Domain created 1998-12-18T05:00:00Z (27 years, 9 months ago)
Registered through MarkMonitor Inc.
Expires in 235 days
DNSSEC status from WHOIS
Resolves to: 2a02:26f0:1700:382::19b8, 2a02:26f0:1700:384::19b8, 95.100.67.168
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: a11-64.akam.net., a18-65.akam.net., a7-64.akam.net., a20-66.akam.net., a1-23.akam.net., a4-67.akam.net.
Site has a favicon but no social sharing metadata
robots.txt has 37 directives and references a sitemap
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
Web server: AkamaiGHost
No threats detected by Google Web Risk
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
No sitemap found — common for smaller sites
crt.sh returned status 502
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.