Is wp.com legit?
This site is trusted. It exhibits strong security and infrastructure, with a very old, well-established domain, although some aspects of transparency are obscured by bot protection.
Hosting & Domains average: 77/100 · based on 38 sites
Checked: April 21, 2026 at 12:43 PM UTC
Is wp.com a scam? Here's what we found.
The site demonstrates strong security practices, including a valid SSL certificate with modern TLS 1.3, HSTS enforcement, and effective clickjacking protection. Google Web Risk found no threats, indicating a clean and secure browsing environment.
With a domain nearly 30 years old and registered through a reputable enterprise registrar like MarkMonitor, the site's identity is exceptionally well-established and stable. The domain's extended expiry further solidifies its long-term presence.
The site has an excellent global Tranco rank, indicating high popularity and established reputation. It is also clean on DNS blacklists. However, the inability to check the Web Archive slightly impacts a full historical reputation assessment.
While legal pages are present, the bot protection preventing checks for contact info and social media presence slightly hinders full transparency. The site's branding is basic but adequate.
The presence of both a privacy policy and terms of service pages indicates a good adherence to fundamental legal and user compliance standards. This provides essential information for users regarding data handling and site usage.
The site features robust infrastructure, including proper DNS resolution, configured SPF and DMARC records for email authentication, and a robots.txt file. While DNSSEC is unsigned, this is not a major issue for wp.com which redirects quickly to a different domain.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1997-03-28T05:00:00Z (29 years, 5 months ago)
Registered through MarkMonitor Inc.
Expires in 707 days
DNSSEC status from WHOIS
Resolves to: 192.0.78.24, 192.0.78.25
Mail servers: mx1.dfw.wordpress.com., mx1.bur.wordpress.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns3.automattic.com., ns2.automattic.com., ns1.automattic.com.
Valid certificate, expires in 72 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Sitemap found with 1 entries
robots.txt has 45 directives and references a sitemap
Site redirects to https://wordpress.com/
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Website has both privacy policy and terms of service pages
Bot protection prevented page inspection
Could not query Wayback Machine
Not found on any DNS blacklists
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.