Is pixpa.com legit?
Pixpa.com appears to be a trusted platform for portfolio website creation, backed by strong technical security and a long-standing domain history. The only notable concern is a higher-than-usual count of hidden content elements, which warrants a minor flag.
Portfolio average: 81/100 · based on 25 sites
Checked: April 18, 2026 at 11:29 AM UTC · Refresh
Is pixpa.com a scam? Here's what we found.
Generally robust security with HTTPS enforcement (HSTS), Content Security Policy, and Google's clean report. The presence of hidden elements is a moderate concern, but not indicative of immediate threat.
A deeply established domain, over 20 years old, through a common registrar, indicates a long-term, stable presence. The site also exhibits clear branding and contact information.
A clean record across DNS blacklists and a very old domain contribute to a good reputation. The lack of a Trustpilot profile is not a red flag, but it means fewer accessible public reviews.
The site clearly provides contact information, legal policies, and links to multiple social media platforms, showing good transparency regarding its operations and presence.
Essential legal pages like Privacy Policy and Terms of Service are present, demonstrating a commitment to basic user compliance and data handling disclosures.
Solid server and DNS setup with proper email authentication (SPF, DMARC) and multiple name servers. The 'unsigned' DNSSEC is a minor missed opportunity for enhanced security.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: WebSite, Organization
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2005-11-03T15:21:12Z (20 years, 9 months ago)
Registered through GoDaddy.com, LLC
Expires in 579 days
DNSSEC status from WHOIS
Excessive hidden content found — may indicate cloaking or deceptive content
robots.txt has 3 directives and references a sitemap
Site has custom branding and social media metadata
Not found on any DNS blacklists
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: ALLOW-FROM *.pixpa.com
Web server: nginx
No threats detected by Google Web Risk
Valid certificate, expires in 264 days
Certificate issued by Amazon
Connection uses TLS 1.2
Site maintains a proper sitemap with 9 indexed pages
Resolves to: 52.200.249.229, 34.232.21.49, 100.50.61.170
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt4.aspmx.l.google.com., alt3.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-1376.awsdns-44.org., ns-1673.awsdns-17.co.uk., ns-8.awsdns-01.com., ns-844.awsdns-41.net.
crt.sh returned status 502
Could not query Wayback Machine
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.