Domain Due Diligence
Report for Kmart.com.au
Why we think so
Kmart Australia (kmart.com.au) shows strong signals of a legitimate national retailer: ~21 million monthly visits, a valid DigiCert TLS certificate, well-known payment partners (PayPal, Visa, AfterPay), active Google Places listings and large Australian traffic share. Recent regulatory and news items include a 2024 privacy ruling about in‑store facial‑recognition use and ongoing 2025 legal action over ethical sourcing; these are important but do not indicate the site is a phishing or scam operation. Overall risk is low for consumers buying on kmart.com.au, though you should watch product recalls and recent legal/privacy headlines before making high‑value or sensitive purchases.
Risk Insights
High Australian traffic supports authenticity
Regulatory and reputation issues to watch
Contradictory Signals
Operational trust (site security, payment partners, store presence) is strong, while legal/regulatory issues lower brand trust. Both can coexist.
Signal A: High traffic, verified payments, TLS and physical stores (signals of legitimacy)
Signal B: OAIC privacy ruling and ongoing supplier legal challenge (signals of regulatory/reputational risk)
Category Scores
Red Flags & Warnings
-
Regulatory/privacy concern: OAIC found unlawful use of facial recognition in stores (in‑store privacy breach), which reduces trust in some corporate practices.
-
Ongoing 2025 legal action alleging possible links between some suppliers and forced labour; litigation is active and could affect reputation or product availability.
🔎 Detailed Checks & Analysis
Traffic & Popularity
Traffic & Popularity
"SimilarWeb and SimilarTech both report ~20–22M monthly visits and Australia as the dominant traffic source, which is expected for Kmart Australia."
Reason: High monthly visits and sustained engagement consistent with a major Australian retailer.
Technical Security (TLS, CDN, WAF)
Technical Security (TLS, CDN, WAF)
"SSL issued by DigiCert (valid through 2026‑08‑01) and use of Imperva/Incapsula and Amazon S3 indicate professional infrastructure and active mitigation controls."
Reason: Valid DigiCert TLS and multiple security/CDN solutions present.
Payments & Checkout
Payments & Checkout
"Presence of mainstream payment integrations reduces the chance of fraudulent checkout flows; still verify payment page URL and certificate at purchase time."
Reason: Multiple reputable payment providers integrated (PayPal, Visa, AfterPay, Apple Pay).
Contact & Verifiability
Contact & Verifiability
"Support emails (customer.satisfaction@kmart.com.au, privacy@kmart.com.au) and phone lines are present in site PDFs and contact pages; corporate LinkedIn and YouTube profiles also exist."
Reason: Published customer support emails, phone numbers and active social profiles enable verification and escalation.
Blacklist/Phishing Status
Blacklist/Phishing Status
"Quick checks show no matched threats, which strongly reduces immediate phishing concerns for the official domain."
Reason: No findings in Google Safe Browsing and not flagged on crypto scam lists.
WHOIS & Registrar
WHOIS & Registrar
"Registrar: Corporation Service Company (Aust) Pty Ltd (CSC). WHOIS shows locked statuses and multiple verification TXT records for Google/GlobalSign/Dropbox etc."
Reason: Registrar is a reputable brand protection provider (CSC); DNS records include standard verification TXT entries.
Legal / Regulatory Exposure
Legal / Regulatory Exposure
"OAIC found unlawful facial recognition use in stores (privacy breach). A 2025 court action seeks documents on supplier links to forced labour; both are material reputational/legal issues."
Reason: Recent OAIC privacy ruling and active legal challenge on supplier sourcing lower the legal trust score.
Content Authenticity (brand, catalog)
Content Authenticity (brand, catalog)
"Site contains official store pages, PDF manuals with corporate emails and sequential SKUs which align with a central retail catalogue."
Reason: Product pages, catalog PDFs and store pages are consistent with a single corporate brand and catalogue.
Your Next Steps
-
1If you plan to make a high‑value purchase, use a credit card or a trusted payment provider (PayPal/Apple Pay) that offers dispute protection.
-
2Check the site’s HTTPS certificate and the browser address bar to confirm you are on kmart.com.au before entering payment details.
-
3Search for the specific product model and recent recall notices (news and ACCC/ACCC recall pages) before buying appliances or kids’ toys.
-
4Keep records of order emails and payment receipts and use the published customer support emails/phone lines if issues arise.
-
5If you see unusual payment requests (bank transfer to a third party or requests for crypto), stop and verify via the listed customer service phone numbers.
Evidence & Citations
-
SimilarTech profile for kmart.com.au (traffic, tech stack)
SimilarTech shows ~21M monthly visits, Australia as the leading country, and lists payment/security vendors (AfterPay, PayPal, Imperva).
-
SimilarWeb analytics snapshot for kmart.com.au (visits, engagement)
SimilarWeb estimates ~21M visits (latest months) with ~95% of traffic from Australia; engagement metrics (pages/visit ~4.5) match a retail marketplace.
-
WHOIS, DNS and SSL details for kmart.com.au
Domain uses DigiCert TLS (valid to 2026‑08‑01), authoritative name servers via CSC, and multiple TXT records for third‑party verifications.
-
Website contact scrape for kmart.com.au (support emails, phones, social)
Multiple corporate and support emails (privacy@kmart.com.au, customer.satisfaction@kmart.com.au) and published phone numbers are present on the site and PDFs.
-
Google Safe Browsing check and crypto blacklist scan
No matched threats in Google Safe Browsing and domain not flagged by the crypto scam scanner.
-
News: OAIC privacy ruling & 2025 sourcing legal action
Media and regulator reports describe the OAIC finding on facial recognition (privacy breach) and a 2025 legal challenge over supplier sourcing; these affect reputation but not site authenticity.
🕵🏻 Keep investigating
Run another instant due diligence scan on any website URL. Verify before you trust!
Phishing crews spin up carbon-copy login portals for CRM and finance tools, siphoning credentials before users realize t...
Read playbook →Giveaway pages entice with consoles or flights, then harvest card data and selfies “for verification.” ScamAI checks reg...
Read playbook →