Is gravatar.com legit?
Gravatar.com is a trusted a platform, demonstrating robust security measures and a long-standing online presence. The only minor concerns are the lack of clear contact information and an unsigned DNSSEC record.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 21, 2026 at 7:29 PM UTC
Is gravatar.com a scam? Here's what we found.
Excellent security posture with modern TLS 1.3, valid SSL, and strong content security policies. The site is clean on Google Web Risk, indicating no known malware or phishing threats.
A highly established domain with over two decades of history, registered through a reputable enterprise registrar, which speaks to its legitimacy and stability.
Outstanding reputation, evidenced by its extremely high Tranco rank, extensive web archive history, and being clean on all DNS blacklists. It's a globally recognized and visited website.
While the site has legal pages and some social media presence, the absence of easily accessible contact information on the homepage slightly detracts from full transparency.
Strong compliance foundation with both privacy policy and terms of service readily available, which is essential for user trust and legal adherence.
Solid infrastructure with good DNS resolution, robust email authentication through SPF and DMARC, and fast page load times. The only minor improvement would be enabling DNSSEC.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2004-07-15T20:57:48Z (21 years, 0 months ago)
Registered through MarkMonitor Inc.
Expires in 450 days
DNSSEC status from WHOIS
Resolves to: 192.0.80.242, 192.0.80.240, 192.0.80.241, 192.0.80.239
Mail servers: mx2.ams.automattic.com., mx1.dfw.automattic.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns1.automattic.com., ns2.automattic.com., ns3.automattic.com.
Valid certificate, expires in 79 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Site has a favicon but no social sharing metadata
robots.txt has 56 directives
Sitemap found with 1 entries
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Website is live and responding
No obvious contact information found on homepage
Website has both privacy policy and terms of service pages
Website links to one social media platform
Earliest archive snapshot from 20040806
Not found on any DNS blacklists
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.