Is wish.com legit?
Wish.com is mostly safe, but be aware of some notable transparency and compliance issues. The lack of standard legal pages and readily available contact information are concerning for a major e-commerce platform.
E-commerce average: 73/100 · based on 28 sites
Checked: April 27, 2026 at 7:03 PM UTC
Is wish.com a scam? Here's what we found.
The security posture is strong with a valid SSL certificate, modern TLS 1.3, an HSTS header, and robust clickjacking protection. Google Web Risk also confirms no threats for the site.
The domain is very old and registered with a reputable registrar, indicating a long-standing online presence. WHOIS data is publicly available through MarkMonitor, suggesting a transparent ownership.
The site has moderate global traffic, isn't blacklisted, and has a well-established history based on domain age. However, the lack of a Trustpilot profile prevents external reputation validation.
The site links to social media and has custom branding, but the use of urgency tactics and the complete absence of clear contact information significantly detract from its transparency.
This category is a major weakness due to the complete lack of essential legal pages like a privacy policy or terms of service, which is a significant compliance and trust concern for any online business.
The site boasts solid DNS and email infrastructure with multiple name servers, DMARC, and multiple IPs. These are all signs of a well-maintained and robust backend.
Signals Detected
Site uses structured data identifying itself as: WebSite
This site has moderate global traffic
Site uses multiple urgency/scarcity tactics — common in scam sites
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1995-01-03T05:00:00Z (31 years, 9 months ago)
Registered through MarkMonitor Inc.
Expires in 588 days
DNSSEC status from WHOIS
Resolves to: 2600:1f18:2265:c01:e875:7e5b:e27f:8224, 2600:1f18:2265:c00:e866:c8b3:a71c:9b69, 44.216.229.120, 34.199.26.52
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt4.aspmx.l.google.com., alt3.aspmx.l.google.com.
Domain has DMARC email authentication configured
DNS providers: ns-1071.awsdns-05.org., ns-1818.awsdns-35.co.uk., ns-433.awsdns-54.com., ns-760.awsdns-31.net.
crt.sh returned status 429
Valid certificate, expires in 214 days
Certificate issued by Amazon
Connection uses TLS 1.3
Site has custom branding and social media metadata
robots.txt has 27 directives and references a sitemap
Site maintains a proper sitemap with 52 indexed pages
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Website is live and responding
No obvious contact information found on homepage
No privacy policy or terms of service found
Website links to multiple social media platforms
Not found on any DNS blacklists
Could not query Wayback Machine
Average page load time
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.