Is mullvad.net legit?
Mullvad.net appears to be a trusted website with a strong security and infrastructure foundation. While there are minor concerns regarding upcoming certificate and domain expiries, as well as the mention of non-reversible payment methods, these do not significantly detract from its overall trustworthiness.
VPN & Security average: 84/100 · based on 16 sites
Checked: April 27, 2026 at 11:28 PM UTC
Is mullvad.net a scam? Here's what we found.
The site uses a modern TLS 1.3 connection and has HSTS and Content Security Policy configured, indicating a strong commitment to security, though the SSL certificate expiry in 61 days is a minor concern.
With a domain age of 17 years, the site demonstrates significant longevity, but the domain expiry in 73 days is a short window that could be an oversight.
Possessing a high Tranco rank (#4230) and a clean Google Web Risk report provides good reputational standing, though the absence of a Trustpilot profile means less consumer-generated feedback is available.
The site provides clear contact information, legal pages, and a presence on multiple social media platforms, suggesting good transparency about its operations.
Legal pages like a privacy policy and terms of service are present, which is good for compliance. However, the mention of Bitcoin as a payment method introduces a non-reversible payment option that users should be aware of.
The site's DNSSEC is properly signed, and email authentication (SPF/DMARC) is configured, indicating a robust and professionally managed infrastructure.
Signals Detected
Site uses structured data identifying itself as: Organization
This is a well-known, high-traffic website
Mentions non-reversible payment methods: bitcoin
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2008-07-10T20:38:28Z (17 years, 0 months ago)
Registered through Domeneshop AS dba domainnameshop.com
Expires in 73 days
DNSSEC status from WHOIS
Valid certificate, expires in 61 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Site has custom branding and social media metadata
robots.txt has 116 directives and references a sitemap
crt.sh returned status 429
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Resolves to: 45.83.223.209
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns1.mullvaddns.net., ns2.mullvaddns.net., ns3.mullvaddns.net., ns4.mullvaddns.net.
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Site maintains a proper sitemap with 1469 indexed pages
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.