Is stripe.com legit?
Stripe.com is a highly trusted website, demonstrating excellent security and infrastructure. While there are minor concerns regarding payment methods and the number of external scripts, the site largely excels in all other areas.
Finance average: 80/100 · based on 48 sites
Checked: April 21, 2026 at 11:51 AM UTC
Is stripe.com a scam? Here's what we found.
The site features a robust security setup with a valid SSL certificate, modern TLS 1.3, and a clean Google Web Risk report. However, the mention of non-reversible payment methods is a minor concern.
With a 30-year-old domain and clear WHOIS information, the site exhibits strong and established identity credentials, indicating a long-standing and legitimate presence.
The site boasts a very high Tranco Rank and is clean on DNS blacklists, indicating an excellent and widely recognized reputation, though the lack of a Trustpilot profile is a neutral data point.
Stripe.com provides complete branding, clear contact information, and an active social media presence, showcasing strong transparency about its operations.
The presence of comprehensive legal pages, including privacy and terms of service, demonstrates a strong commitment to compliance and user rights.
The site benefits from well-configured DNS, DMARC, and HSTS, though the high number of external scripts presents a modest concern regarding potential vulnerabilities.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: WebSite, Organization
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1995-09-12T04:00:00Z (30 years, 0 months ago)
Registered through SafeNames Ltd.
Expires in 507 days
DNSSEC status from WHOIS
Mentions non-reversible payment methods: bitcoin
Excessive number of external scripts — may indicate malicious injection
Valid certificate, expires in 72 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Resolves to: 52.30.58.64, 52.49.17.168, 18.202.131.124
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., aspmx2.googlemail.com., aspmx3.googlemail.com.
Domain has DMARC email authentication configured
DNS providers: ns-1087.awsdns-07.org., ns-1882.awsdns-43.co.uk., ns-423.awsdns-52.com., ns-705.awsdns-24.net.
Site has custom branding and social media metadata
robots.txt has 26 directives and references a sitemap
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Site maintains a proper sitemap with 7 indexed pages
crt.sh returned status 502
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.