Is kraken.com legit?
Kraken.com appears to be a mostly safe platform for cryptocurrency transactions, backed by strong technical foundations and a long-standing domain history. However, users should be aware of the inherent risks of non-reversible payments and the current gap in legal documentation.
Crypto average: 76/100 · based on 25 sites
Checked: April 18, 2026 at 8:12 AM UTC · Refresh
Is kraken.com a scam? Here's what we found.
While the site boasts modern TLS encryption, strong HTTPS enforcement, and no Google Web Risk flags, the unusually high number of external scripts could pose a potential, albeit unconfirmed, risk for sophisticated users.
With a domain age of over 26 years and high traffic, Kraken.com is an established entity in the digital space. Despite the neutral registrar, this longevity points to a verifiable and consistent online presence.
The site's impressive Tranco rank and clean DNS blacklist status speak to its significant web presence and general good standing. Its active social media and comprehensive sitemap reinforce its reputation as a well-managed platform.
Kraken.com offers clear contact information and a strong social media presence, indicating open communication. However, the use of non-reversible payment methods, while standard for crypto, requires users to exercise increased diligence.
The site is missing either a privacy policy or terms of service, which is a significant oversight for a platform managing user funds and personal data. This gap in legal documentation reduces overall compliance assurance.
The technical setup is robust, featuring DNSSEC, proper email authentication (SPF and DMARC), and Cloudflare's reliable infrastructure. These elements confirm a professionally managed and secure backend.
Signals Detected
This is a well-known, high-traffic website
Site uses structured data identifying itself as: Organization, WebSite, BreadcrumbList
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 46 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Domain created 2000-04-03T10:39:06Z (26 years, 5 months ago)
Registered through NameCheap, Inc.
Expires in 1811 days
DNSSEC status from WHOIS
crt.sh returned status 429
robots.txt has 33 directives and references a sitemap
Site has custom branding and social media metadata
Site enforces HTTPS via HSTS
X-Frame-Options: sameorigin
Web server: cloudflare
No threats detected by Google Web Risk
Resolves to: 104.17.187.205, 104.17.186.205, 104.17.189.205, 104.17.185.205, 104.17.188.205
Mail servers: smtp.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: kim.ns.cloudflare.com., art.ns.cloudflare.com.
Mentions non-reversible payment methods: bitcoin
Excessive number of external scripts — may indicate malicious injection
Not found on any DNS blacklists
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Site maintains a proper sitemap with 47522 indexed pages
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.