Is lastpass.com legit?
lastpass.com appears to be a highly trustworthy website. Its strong security measures, long-standing domain, and comprehensive legal and contact information indicate a legitimate and reputable service.
Software & Downloads average: 78/100 · based on 75 sites
Checked: April 18, 2026 at 8:13 AM UTC · Refresh
Is lastpass.com a scam? Here's what we found.
The site boasts a robust security posture, utilizing modern TLS 1.3, HSTS, and Content Security Policy, alongside a clean record with Google Web Risk. It's properly implementing measures to protect user data and prevent common web attacks.
With over two decades in operation and clear registration details through a reputable corporate registrar, LastPass has a well-established and transparent identity. This longevity is a strong indicator of legitimacy.
This is a very well-known, high-traffic website not listed on any blacklists. Its significant web presence and long history solidify its reputation as a major player in its industry.
LastPass is highly transparent, providing clear contact information, comprehensive legal pages, and an active presence across multiple social media platforms, making it easy for users to find support or information.
The site provides both a privacy policy and terms of service, which are essential for any service handling sensitive user data, particularly a password manager.
The infrastructure is generally solid, featuring good email authentication and efficient DNS resolution. The only minor point is the unsigned DNSSEC, which is common but still a potential area for improvement in overall resilience.
Signals Detected
This is a well-known, high-traffic website
Site uses structured data identifying itself as: Organization
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 189 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.3
Site has custom branding and social media metadata
crt.sh returned status 429
Domain created 2005-03-08T22:52:10Z (21 years, 5 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 623 days
DNSSEC status from WHOIS
robots.txt has 29 directives and references a sitemap
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
No threats detected by Google Web Risk
Site maintains a proper sitemap with 7 indexed pages
Not found on any DNS blacklists
Resolves to: 23.52.182.42
Mail servers: lastpass-com.mail.protection.outlook.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: a12-67.akam.net., a18-64.akam.net., a7-67.akam.net., a2-65.akam.net., a3-66.akam.net., a1-208.akam.net.
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.