Is plaid.com legit?
This site appears mostly safe, demonstrating a strong technical foundation and good overall practices. However, the mention of non-reversible payment methods and incomplete legal pages are notable concerns consumers should be aware of.
Finance average: 81/100 · based on 48 sites
Checked: April 27, 2026 at 5:28 PM UTC
Is plaid.com a scam? Here's what we found.
While the SSL certificate and TLS version are excellent, the presence of payment red flags and an excessive number of external scripts detract from an otherwise solid security posture. Google Web Risk found no threats.
The domain is very old (30 years) and WHOIS information is fully visible, positively indicating a long-established and transparent entity behind the site.
The site has moderate global traffic and is not on any DNS blacklists, suggesting a generally good reputation despite the lack of a Trustpilot profile.
Contact information is readily available, and there's a good social media presence. However, the significant amount of hidden content raises questions about full transparency.
The site has some legal pages, but the partial presence (missing either a privacy policy or terms of service) is a standard compliance requirement for businesses.
Excellent DNS and email configurations with DMARC present, showing a well-managed and robust hosting and communication infrastructure. DNSSEC is unsigned, which is a minor point.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: Organization
Mentions non-reversible payment methods: western union
Excessive number of external scripts — may indicate malicious injection
Excessive hidden content found — may indicate cloaking or deceptive content
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1995-08-16T04:00:00Z (30 years, 1 months ago)
Registered through Gandi SAS
Expires in 109 days
DNSSEC status from WHOIS
crt.sh returned status 429
Resolves to: 2600:9000:223e:cc00:1d:e80d:8080:93a1, 2600:9000:223e:f000:1d:e80d:8080:93a1, 2600:9000:223e:fa00:1d:e80d:8080:93a1, 2600:9000:223e:3800:1d:e80d:8080:93a1, 2600:9000:223e:e600:1d:e80d:8080:93a1, 2600:9000:223e:da00:1d:e80d:8080:93a1, 2600:9000:223e:8200:1d:e80d:8080:93a1, 2600:9000:223e:c00:1d:e80d:8080:93a1, 52.222.236.125, 52.222.236.67, 52.222.236.16, 52.222.236.70
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has DMARC email authentication configured
DNS providers: ns-1123.awsdns-12.org., ns-1688.awsdns-19.co.uk., ns-309.awsdns-38.com., ns-967.awsdns-56.net.
Valid certificate, expires in 169 days
Certificate issued by Amazon
Connection uses TLS 1.3
robots.txt has 20 directives and references a sitemap
Site enforces HTTPS via HSTS
Web server: AmazonS3
No threats detected by Google Web Risk
Site maintains a proper sitemap with 1904 indexed pages
Site has custom branding and social media metadata
Website is live and responding
Website appears to have contact information
Website is missing either privacy policy or terms of service
Website links to multiple social media platforms
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.