Is paypal.com legit?
PayPal is a highly trusted and established platform, scoring well due to strong infrastructure, security practices, and long domain history. Minor concerns arise from a shorter SSL expiry and the presence of hidden content, which warrants a cautious look for transparency.
Finance average: 80/100 · based on 48 sites
Checked: April 21, 2026 at 1:20 PM UTC
Is paypal.com a scam? Here's what we found.
The site uses modern TLS 1.3 encryption, has a valid certificate from a reputable issuer, and is not flagged by Google Web Risk, indicating a robust security posture, though the certificate expires soon.
With a domain age of over 26 years and registration through a leading corporate registrar like MarkMonitor, PayPal demonstrates a long-standing and well-established online identity.
PayPal is a globally recognized and highly visited site, evidenced by its Tranco rank, and is not listed on any DNS blacklists, reinforcing its strong reputation despite having no Trustpilot profile.
While contact and legal information are clear, the presence of hidden content and a lack of social media links on the homepage detract from an otherwise transparent presentation.
The website clearly provides both privacy policy and terms of service pages, indicating adherence to essential legal and user-focused compliance standards.
The site boasts strong infrastructure with DNSSEC, robust email authentication (SPF/DMARC), and a present robots.txt, although the domain expiry date is a bit close for comfort for a site of this size.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Excessive hidden content found — may indicate cloaking or deceptive content
Domain created 1999-07-15T05:32:11Z (26 years, 1 months ago)
Registered through MarkMonitor Inc.
Expires in 84 days
DNSSEC status from WHOIS
Valid certificate, expires in 77 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Resolves to: 151.101.195.1, 162.159.141.96, 151.101.3.1
Mail servers: mx2.paypalcorp.com., mx1.paypalcorp.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: pdns100.ultradns.com., pdns100.ultradns.net., ns1-pchnet.paypal.com., ns2-pchnet.paypal.com.
robots.txt has 95 directives and references a sitemap
Site has custom branding and social media metadata
crt.sh returned status 502
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
Not found on any DNS blacklists
Could not query Wayback Machine
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
No social media links found on homepage
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.