Domain Due Diligence
Report for Surfshark.com
Why we think so
Surfshark.com operates a widely used VPN service with over 7 million monthly visits, primarily from the US and other major countries. It offers strong technical infrastructure, including Cloudflare CDN and secure HTTPS, and uses reputable email domains like support@surfshark.com. The domain is established with WHOIS records dating back to 2007, and it is not found on any scam or blacklist databases. However, it faces several class action lawsuits in California due to allegations about unclear and possibly deceptive auto-renewal billing practices. User complaints primarily center on unexpected renewal charges and difficulties canceling subscriptions, rather than security breaches or hacking. Independent expert reviews generally rate Surfshark VPN positively for security and privacy features, suggesting the core service is legitimate. Consumers should remain cautious around subscription terms and billing disclosures.
Risk Insights
Established Domain with Strong Tech Setup
User Complaints on Billing Practices
Contradictory Signals
The core VPN service is legitimate, but business practices around billing raise red flags.
Signal A: Positive expert security audits and privacy features.
Signal B: Negative user reports and legal actions over billing issues.
Category Scores
Red Flags & Warnings
-
Ongoing class action lawsuits allege deceptive automatic renewal billing practices violating consumer protections.
-
Multiple user complaints report unauthorized billing after cancellation and challenges in obtaining refunds.
🔎 Detailed Checks & Analysis
Domain Age and Registrar
Domain Age and Registrar
"Long domain age reduces likelihood of scam, registrar is legitimate."
Reason: Domain registered since 2007 via reputable registrar TurnCommerce (NameBright.com), indicating an established presence.
Technical Infrastructure
Technical Infrastructure
"Technology stack consistent with reputable companies; no suspicious software detected."
Reason: Uses Cloudflare CDN, valid HTTPS with ECDSA certificate, standard DNS and email configurations.
Contact Information
Contact Information
"Direct contact channels support authenticity."
Reason: Official business emails available with multiple verified sources; active social media accounts corroborate identity.
User Reputation and Reviews
User Reputation and Reviews
"Negative user feedback significantly impacts trust."
Reason: Numerous verified user complaints and fraud allegations, especially concerning billing and subscription renewal practices.
Legal and Compliance Status
Legal and Compliance Status
"Legal disputes suggest systemic issues in business practices."
Reason: Current multiple class action lawsuits alleging deceptive billing and violation of consumer protection laws.
Blacklist and Phishing Status
Blacklist and Phishing Status
"Absence from blacklist databases supports legitimacy of domain."
Reason: No listings found on crypto scam or phishing blacklists; Google Safe Browsing shows no threats.
Your Next Steps
-
1Review Surfshark’s subscription terms carefully before purchase, focusing on auto-renewal and cancellation policies.
-
2Monitor billing statements for unexpected charges and keep records of any cancellation requests.
-
3Consult legal counsel or consumer protection agencies if you experience unauthorized charges.
-
4Consider alternative VPN services if billing transparency is a priority and you want to avoid auto-renewal disputes.
-
5Check for updated user reviews and official responses before subscribing to Surfshark.
Evidence & Citations
-
Class Action Lawsuit Filed Against Surfshark VPN
Detailed legal complaints about unauthorized auto-renewal charges.
-
Surfshark VPN Review by Cybernews, 2025
Independent expert review confirming VPN security and features.
-
Surfshark.com WHOIS and SSL information
Domain registration since 2007 with valid SSL certificates and DNS setup.
🕵🏻 Keep investigating
Run another instant due diligence scan on any website URL. Verify before you trust!
Phishing crews spin up carbon-copy login portals for CRM and finance tools, siphoning credentials before users realize t...
Read playbook →Giveaway pages entice with consoles or flights, then harvest card data and selfies “for verification.” ScamAI checks reg...
Read playbook →