Is roblox.com legit?
Roblox.com appears mostly safe, demonstrating a strong technical and reputational foundation. However, the absence of crucial legal pages like a privacy policy and terms of service is a significant red flag, and the large number of external scripts warrants caution.
Gaming average: 71/100 · based on 9 sites
Checked: April 21, 2026 at 4:09 AM UTC
Is roblox.com a scam? Here's what we found.
While the SSL/TLS configuration is robust and Google Web Risk shows no threats, the high count of external scripts introduces a notable security concern by increasing potential vulnerabilities.
The domain has excellent longevity, registered over two decades ago through a reputable registrar, indicating a well-established and stable entity. The organization uses structured data to clearly identify itself.
Roblox holds a top global Tranco rank, indicating immense popularity and a strong public presence. It is clean on DNS blacklists, reinforcing a positive reputation, despite the inability to check Trustpilot or Web Archive presence.
The site has complete branding, readily available contact information, and a significant social media presence across multiple platforms, all indicating a high level of openness and accessibility.
The complete absence of a privacy policy and terms of service is a critical compliance issue for a website of this scale, severely impacting user trust and legal standing.
The DNS and email infrastructure are well-configured with DMARC, multiple name servers, and efficient resolution. HTTPS is enforced with HSTS and CSP, ensuring secure data handling.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: Organization
This business has no Trustpilot presence — not unusual for smaller or newer companies
Excessive number of external scripts — may indicate malicious injection
Domain created 2004-01-30T00:08:43Z (22 years, 6 months ago)
Registered through MarkMonitor Inc.
Expires in 283 days
DNSSEC status from WHOIS
Valid certificate, expires in 147 days
Certificate issued by Sectigo Limited
Connection uses TLS 1.3
Resolves to: 128.116.31.3
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt4.aspmx.l.google.com., alt3.aspmx.l.google.com.
Domain has DMARC email authentication configured
DNS providers: dns1.p06.nsone.net., dns2.p06.nsone.net., dns3.p06.nsone.net., dns4.p06.nsone.net., ns01.rbxinfra.net., ns02.rbxinfra.net., ns03.rbxinfra.net., ns04.rbxinfra.net.
Site has custom branding and social media metadata
robots.txt has 31 directives and references a sitemap
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: public-gateway
No threats detected by Google Web Risk
Site maintains a proper sitemap with 35 indexed pages
Website is live and responding
Website appears to have contact information
No privacy policy or terms of service found
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
crt.sh returned status 404
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.