Is wish.com legit?
Wish.com appears to be a mostly safe platform for online shopping, backed by a very old domain and solid infrastructure. However, the lack of crucial legal pages and overt contact information, coupled with aggressive sales tactics, raises some concerns about consumer protection and transparency.
E-commerce average: 71/100 · based on 28 sites
Checked: April 18, 2026 at 8:32 AM UTC · Refresh
Is wish.com a scam? Here's what we found.
The site uses a modern TLS 1.3 encryption, a valid SSL certificate from Amazon, and passes Google's safe browsing checks, indicating a secure technical environment for transactions.
With a domain established over 31 years ago, registered through a reputable registrar like MarkMonitor, Wish.com has a well-established and transparent digital identity, which is a strong indicator of longevity and legitimacy.
While the domain is very old and the site isn't blacklisted, the presence of aggressive urgency tactics could detract from its long-term reputation, suggesting a potentially high-pressure sales environment.
Despite having a complete brand and social media presence, the absence of easily found contact information for customer support is a significant hurdle for users seeking assistance or having issues, which is critical for an e-commerce platform.
The complete lack of privacy policy and terms of service pages is a serious gap in compliance, leaving consumers without clear statements regarding data usage, returns, and dispute resolution – essential for any online retailer.
The site demonstrates a robust technical foundation with secure email authentication, multiple name servers, and a responsive website housed on Cloudflare, though the unsigned DNSSEC is a minor missed opportunity for enhanced security.
Signals Detected
This site has moderate global traffic
Site uses structured data identifying itself as: WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1995-01-03T05:00:00Z (31 years, 8 months ago)
Registered through MarkMonitor Inc.
Expires in 598 days
DNSSEC status from WHOIS
Site uses multiple urgency/scarcity tactics — common in scam sites
Valid certificate, expires in 223 days
Certificate issued by Amazon
Connection uses TLS 1.3
robots.txt has 27 directives and references a sitemap
Site has custom branding and social media metadata
Not found on any DNS blacklists
Site maintains a proper sitemap with 52 indexed pages
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Resolves to: 2600:1f18:2265:c01:747c:5925:5413:7a37, 2600:1f18:2265:c00:9c8a:3236:1f05:399, 100.52.70.117, 18.215.91.173
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-1818.awsdns-35.co.uk., ns-433.awsdns-54.com., ns-760.awsdns-31.net., ns-1071.awsdns-05.org.
Website is live and responding
No obvious contact information found on homepage
No privacy policy or terms of service found
Website links to multiple social media platforms
Could not query Wayback Machine
Could not query certificate transparency logs
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.