Is surfshark.com legit?
Surfshark.com appears to be a mostly safe and legitimate VPN service. While they have a strong overall technical foundation and transparent contact information, the high number of external scripts raises a minor security caution.
VPN & Security average: 83/100 · based on 16 sites
Checked: April 18, 2026 at 8:26 AM UTC · Refresh
Is surfshark.com a scam? Here's what we found.
The site uses a strong and modern SSL certificate from Google, with an up-to-date TLS version, and passes Google Web Risk scans. However, the unusually high number of external scripts could pose a minor security and privacy concern, especially for a security-focused service.
With a domain almost 19 years old and clear WHOIS information, Surfshark establishes a credible and long-standing online presence. The domain's extended expiry date further reinforces its stability.
This is a well-known, high-traffic website with a good Tranco rank and is clean on all DNS blacklists. The lack of a Trustpilot profile is not uncommon, especially for a company of its size, and doesn't significantly detract from an otherwise solid reputation.
Surfshark provides readily accessible contact information, comprehensive branding, and an active presence across multiple social media platforms, demonstrating a commitment to open communication with its users.
The presence of both a privacy policy and terms of service pages indicates adherence to vital legal and user data handling standards, crucial for a service like a VPN that deals with sensitive user information.
The site benefits from a robust infrastructure, including a fast page load time, secure Cloudflare name servers, proper DNS resolution, and thorough email authentication (SPF/DMARC), ensuring reliability and deliverability.
Signals Detected
This is a well-known, high-traffic website
Site uses structured data identifying itself as: Organization
This business has no Trustpilot presence — not unusual for smaller or newer companies
Excessive number of external scripts — may indicate malicious injection
Valid certificate, expires in 63 days
Certificate issued by Google Trust Services
Connection uses TLS 1.3
Domain created 2007-09-30T09:00:38Z (18 years, 9 months ago)
Registered through TurnCommerce, Inc. DBA NameBright.com
Expires in 1991 days
DNSSEC status from WHOIS
Site has custom branding and social media metadata
robots.txt has 10 directives
Resolves to: 2606:4700::6812:7822, 2606:4700::6812:7922, 104.18.121.34, 104.18.120.34
Mail servers: aspmx.l.google.com., alt2.aspmx.l.google.com., alt1.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: dawn.ns.cloudflare.com., dale.ns.cloudflare.com.
Site enforces HTTPS via HSTS
Web server: cloudflare
No threats detected by Google Web Risk
Site maintains a proper sitemap with 9 indexed pages
Not found on any DNS blacklists
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
Website links to multiple social media platforms
Could not query Wayback Machine
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.