Is plaid.com legit?
Plaid.com appears to be mostly safe, with a strong foundation in terms of age and technical setup. However, concerns about partial legal pages and the mention of non-reversible payment methods like Western Union warrant a closer look.
Finance average: 80/100 · based on 48 sites
Checked: April 18, 2026 at 5:57 PM UTC · Refresh
Is plaid.com a scam? Here's what we found.
While the SSL certificate is valid and the site uses a modern TLS version, the inclusion of Western Union as a payment option raises a red flag regarding transaction safety. Excessive external scripts also present a potential security vulnerability.
With a domain age of over 30 years and clear organizational structured data, the site demonstrates a long-standing and established identity. The domain's detailed WHOIS information further confirms its transparency.
The site has a moderate global traffic rank and a substantial web archive history dating back 29 years, indicating a long and consistent online presence. It also has a complete branding and social media presence, contributing to its reputation despite lacking a Trustpilot profile.
The site provides contact information, maintains an extensive sitemap, and links to social media, contributing to overall transparency. However, the presence of excessive hidden content could be a concern for some users.
The absence of either a privacy policy or terms of service is a significant gap in compliance, potentially leaving users unsure of their rights and how their data is handled. This is a critical component for any legitimate online entity.
The site benefits from a robust infrastructure, including a DMARC record for email authentication, good DNS resolution, and fast page load times. The large number of external scripts, however, could indicate a slightly bloated setup that could affect performance or security.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: Organization
Domain created 1995-08-16T04:00:00Z (30 years, 1 months ago)
Registered through Gandi SAS
Expires in 118 days
DNSSEC status from WHOIS
Mentions non-reversible payment methods: western union
Excessive number of external scripts — may indicate malicious injection
Excessive hidden content found — may indicate cloaking or deceptive content
This business has no Trustpilot presence — not unusual for smaller or newer companies
Valid certificate, expires in 178 days
Certificate issued by Amazon
Connection uses TLS 1.3
Resolves to: 2600:9000:223e:e600:1d:e80d:8080:93a1, 2600:9000:223e:f600:1d:e80d:8080:93a1, 2600:9000:223e:9a00:1d:e80d:8080:93a1, 2600:9000:223e:2200:1d:e80d:8080:93a1, 2600:9000:223e:d200:1d:e80d:8080:93a1, 2600:9000:223e:d600:1d:e80d:8080:93a1, 2600:9000:223e:e000:1d:e80d:8080:93a1, 2600:9000:223e:9c00:1d:e80d:8080:93a1, 52.222.236.70, 52.222.236.16, 52.222.236.67, 52.222.236.125
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has DMARC email authentication configured
DNS providers: ns-1123.awsdns-12.org., ns-1688.awsdns-19.co.uk., ns-309.awsdns-38.com., ns-967.awsdns-56.net.
robots.txt has 20 directives and references a sitemap
Site enforces HTTPS via HSTS
Web server: AmazonS3
No threats detected by Google Web Risk
Earliest archive snapshot from 19961225
Site maintains a proper sitemap with 1902 indexed pages
Site has custom branding and social media metadata
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.