Is goodrx.com legit?
GoodRx.com appears to be a trusted site with strong security and robust infrastructure. While there are a few minor areas for improvement, its long history and consistent operation instill confidence.
Health & Wellness average: 79/100 · based on 17 sites
Checked: April 27, 2026 at 8:19 AM UTC
Is goodrx.com a scam? Here's what we found.
The site has a solid security posture with valid SSL, modern TLS, strong email authentication (DMARC), and no threats detected by Google Web Risk. However, the unsigned DNSSEC is a minor missed opportunity for enhanced domain security.
This domain boasts significant longevity at nearly 15 years, a major trust factor. While the registrar is neutral and there's no Trustpilot, the domain age itself is a strong indicator of a legitimate and established entity.
The site is well-known according to Tranco rank and is clean on DNS blacklists, which is excellent for reputation. The missing favicon is a minor aesthetic issue, and the lack of Trustpilot/Wayback Machine history slightly limits external reputation checks.
GoodRx provides clear contact information and essential legal pages (Privacy & Terms), which demonstrates good transparency. Its limited social media presence is the only minor area for improvement.
The presence of both a privacy policy and terms of service indicates a commitment to legal and user compliance, which is expected for a site of this nature.
The site benefits from robust DNS resolution, multiple mail servers, and effective DMARC email authentication, all signs of a well-maintained infrastructure. The misconfigured sitemap is a minor technical oversight.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
Domain created 2011-07-24T18:35:54Z (14 years, 11 months ago)
Registered through GoDaddy.com, LLC
Expires in 1184 days
DNSSEC status from WHOIS
This business has no Trustpilot presence — not unusual for smaller or newer companies
Resolves to: 151.101.2.49, 151.101.66.49, 151.101.130.49, 151.101.194.49
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has DMARC email authentication configured
DNS providers: ns-1404.awsdns-47.org., ns-1770.awsdns-29.co.uk., ns-411.awsdns-51.com., ns-594.awsdns-10.net.
Valid certificate, expires in 257 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.2
robots.txt has 41 directives and references a sitemap
No favicon found — unusual for an established business
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: AmazonS3
No threats detected by Google Web Risk
Sitemap URL returns non-XML content
crt.sh returned status 502
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to one social media platform
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.