Is fiverr.com legit?
Fiverr.com appears to be a trustworthy platform with strong foundational security and infrastructure. While bot protection prevented checking some key transparency and compliance signals, the overall established presence and positive technical indicators suggest it's safe to use.
Marketplace average: 77/100 · based on 15 sites
Checked: April 29, 2026 at 8:35 AM UTC
Is fiverr.com a scam? Here's what we found.
The site uses a valid SSL certificate and a modern TLS version, backed by a clean Google Web Risk report and HSTS enforcement, indicating robust security practices. The SSL expiry is a minor area to watch.
With a domain age of over 16 years, Fiverr has a very well-established online identity. The WHOIS information is publicly available, contributing to clear ownership and accountability.
Fiverr boasts an excellent Tranco rank, indicating high global traffic and widespread recognition. It's clean on all DNS blacklists, though the absence of a Trustpilot profile suggests a missed opportunity for gathering external feedback.
The site has complete branding and a functional robots.txt, providing essential information for search engines. However, bot protection unfortunately prevented direct verification of contact information and social media presence, which are key for user transparency.
While the site is likely compliant given its established nature, bot protection prevented direct inspection of legal pages. This makes it impossible to verify the accessibility and completeness of vital documents like terms of service and privacy policies.
The site benefits from a robust DNS setup, including multiple IPs, well-configured MX records, DMARC, and Cloudflare name servers. The main area for improvement is the unsigned DNSSEC, which is a minor security enhancement.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2009-12-08T20:58:25Z (16 years, 7 months ago)
Registered through GoDaddy.com, LLC
Expires in 223 days
DNSSEC status from WHOIS
Valid certificate, expires in 62 days
Certificate issued by Google Trust Services
Connection uses TLS 1.2
Resolves to: 104.18.114.47, 104.18.113.47
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has DMARC email authentication configured
DNS providers: lucy.ns.cloudflare.com., sid.ns.cloudflare.com.
Site has custom branding and social media metadata
robots.txt has 66 directives and references a sitemap
Not found on any DNS blacklists
crt.sh returned status 429
Site enforces HTTPS via HSTS
Web server: cloudflare
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.