Is revolut.com legit?
Revolut.com appears mostly safe, boasting a long domain history and robust email authentication. However, significant functional and transparency issues, like the 403 error on the homepage and missing contact details, raise concerns that users should be aware of.
Finance average: 80/100 · based on 48 sites
Checked: April 18, 2026 at 8:21 AM UTC · Refresh
Is revolut.com a scam? Here's what we found.
The security posture is strong, with modern TLS 1.3 encryption, a valid SSL certificate from Google, HSTS enforcement, and no detected threats from Google Web Risk. It's a solid foundation for protecting user data.
The domain has been active for over 19 years, showing considerable longevity and establishment. While the favicon is missing, the long history with a reputable registrar suggests a stable identity.
The site holds a high Tranco rank, indicating significant web traffic and recognition. It's clean on DNS blacklists, but the absence of a Trustpilot profile or readily searchable web archive data leaves some gaps in assessing external reputation.
This is a weak point. The lack of clear contact information and social media links on the homepage makes it harder to understand who is behind the site and how to engage with them, which is not ideal for a financial service.
The absence of either a privacy policy or terms of service is a major red flag for a financial institution. These legal documents are paramount for user protection and regulatory compliance.
Positive infrastructure elements include robust DNS resolution, strong email authentication (SPF and DMARC), and Cloudflare's server usage. However, the critical HTTP 403 status on the main domain is a significant operational problem that needs addressing.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2006-05-04T22:01:48Z (19 years, 2 months ago)
Registered through Squarespace Domains II LLC
Expires in 1842 days
DNSSEC status from WHOIS
Valid certificate, expires in 62 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
No favicon found — unusual for an established business
crt.sh returned status 429
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
robots.txt has 65 directives and references a sitemap
No sitemap found — common for smaller sites
Resolves to: 162.159.140.233, 172.66.0.231
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-cloud-d3.googledomains.com., ns-cloud-d1.googledomains.com., ns-cloud-d2.googledomains.com., ns-cloud-d4.googledomains.com.
Website returned status 403
No obvious contact information found on homepage
Website is missing either privacy policy or terms of service
No social media links found on homepage
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.