Is taobao.com legit?
This website is mostly safe, but users should be aware of the large number of external scripts which can sometimes be a vector for vulnerabilities, and the absence of clear contact information. Otherwise, it demonstrates a strong track record and robust technical setup.
E-commerce average: 71/100 · based on 28 sites
Checked: April 21, 2026 at 3:04 PM UTC
Is taobao.com a scam? Here's what we found.
While the SSL certificate is valid and employs modern TLS 1.3 with HSTS, the high number of external scripts is a moderate concern that could potentially introduce vulnerabilities if not carefully managed.
The domain is very old, established over 23 years ago, which is a strong indicator of legitimacy and stability. The registrar is Alibaba Cloud, which aligns with the global reach of the entity.
As one of the most visited websites globally, its Tranco rank is excellent, and it is not found on any DNS blacklists, indicating a clean and established reputation. The absence of a Trustpilot profile is not unusual for a platform of this scale and origin.
While legal pages like Privacy and Terms are present, the notable absence of clear contact information on the homepage is a significant drawback for user trust and accessibility. The branding is basic, lacking social sharing metadata.
The presence of both a privacy policy and terms of service pages demonstrates a commitment to legal and user compliance, which is essential for a major online platform.
The site has solid infrastructure, including multiple IP addresses for DNS resolution, robust email authentication (SPF and DMARC), and responsive status. However, the misconfigured sitemap is a minor technical oversight.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
Excessive number of external scripts — may indicate malicious injection
Domain created 2003-04-21T03:50:05Z (23 years, 4 months ago)
Registered through Alibaba Cloud Computing (Beijing) Co., Ltd.
Expires in 1460 days
DNSSEC status from WHOIS
This business has no Trustpilot presence — not unusual for smaller or newer companies
Resolves to: 2401:b180:7003::6b, 2408:4001:f00::87, 2408:4001:f10::6f, 2408:4001:f10::5e, 2401:b180:7003::ed, 2401:b180:7003::aa, 2408:4001:f00::3c, 2401:b180:7003::25, 59.82.122.165, 59.82.121.163, 59.82.43.239, 59.82.122.130, 59.82.43.234, 59.82.122.140, 59.82.44.240, 59.82.43.238
Mail servers: mx1.alibaba-inc.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns7.taobao.com., ns6.taobao.com., ns5.taobao.com., ns4.taobao.com.
Valid certificate, expires in 47 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.3
Site enforces HTTPS via HSTS
Web server: Tengine
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
robots.txt has 4 directives
Website is live and responding
No obvious contact information found on homepage
Website has both privacy policy and terms of service pages
Website links to one social media platform
Sitemap URL returns non-XML content
Not found on any DNS blacklists
Could not query Wayback Machine
Could not query certificate transparency logs
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.