66
out of 100
SUSPICIOUS

Is kiwi.com safe?

Kiwi.com is legitimate and not flagged as malicious by major threat checks. The site is safe to visit, but the 66/100 score and missing security headers justify normal caution when booking.

Google Safe Browsing
URLhaus
Spamhaus DNS BL
SURBL
SSL

Valid · TLSv1.3

Threats

None detected

Registrar

MarkMonitor.

Scanned

March 18, 2026

Website Screenshots

Desktop · 1920×1080
Screenshot of kiwi.com — desktop view
Mobile
Screenshot of kiwi.com — mobile view

Kiwi.com scores 66/100 and is flagged suspicious by the scanner, but the evidence does not point to malware or fraud. The site uses valid TLS 1.3 with a certificate issued by Certainly Intermediate R1, and major threat checks came back clean.

SSL Certificate & HTTPS Security

Kiwi.com is serving a valid SSL certificate over TLSv1.3, issued by Certainly Intermediate R1 (Certainly). HTTPS is enforced with HSTS enabled, which is a positive sign for transport security. The certificate expires in 13 days, so the site is currently protected, but the short remaining validity means the certificate should be renewed soon.

The scan also found that the site responds with HTTP 200 and resolves to the final URL https://www.kiwi.com/en/. That is normal behavior for a legitimate commercial site. The main security gap is not the certificate itself, but the absence of several hardening headers: X-Frame-Options, Referrer-Policy, Permissions-Policy, COEP, CORP, and X-XSS-Protection.

Threat Intelligence Results

The threat checks are clean across the board. Google Safe Browsing shows no issues, URLhaus is clean, and DNS blocklists from Spamhaus and SURBL also show no listings. That means the domain is not currently associated with known phishing, malware distribution, or spam infrastructure.

This is important because malicious travel-booking lookalikes are common. In this case, the scan found no evidence of threat infrastructure, and the domain reputation is marked trusted. The suspicious verdict comes from the overall scoring model, not from any active blacklist hit or malware finding.

Domain History & WHOIS Analysis

Kiwi.com is a known domain with a trusted reputation and a long-standing presence. The scanner identifies it as a legitimate travel booking platform, and the AI summary states the domain has been active for over 30 years with no known malicious history. The registrar is MarkMonitor, Inc., which is commonly used for brand protection by established companies.

The domain creation date is unknown in the scan data, so the exact registration age is not confirmed here. Even so, the combination of known brand status, reputable registrar, and consistent commercial infrastructure supports a legitimate business profile rather than a throwaway scam domain.

Is Kiwi.com Legitimate?

Yes � kiwi.com is a legitimate travel booking platform, and the scan data supports that conclusion. It has valid HTTPS, clean threat intelligence results, trusted domain reputation, and no signs of malicious infrastructure.

The only caution is that the site is not perfect from a security-hardening perspective: several HTTP security headers are missing, and the scanner still assigns a suspicious label with a 66/100 score. That does not make the site unsafe, but it does mean users should still verify bookings, prices, and refund terms carefully before paying.

Scan Details

Safety Score66/100
VerdictSuspicious
SSL ValidYes
SSL IssuerCertainly Intermediate R1 (Certainly)
SSL ProtocolTLSv1.3
SSL Expires in13 days
HSTSEnabled
HTTP Status200
Response Time1148ms
RegistrarMarkMonitor, Inc.
Domain Created
CategoryTravel booking platform
TechnologiesNext.js

Security Headers

HSTS X-Content-Type-Options CSP COOPX-Frame-OptionsReferrer-PolicyPermissions-PolicyCOEPCORPX-XSS-Protection

Frequently Asked Questions

is kiwi com legit?

Yes. The scan shows a trusted domain reputation, valid TLSv1.3 SSL from Certainly Intermediate R1, and no hits on Google Safe Browsing, URLhaus, Spamhaus, or SURBL. The site is legitimate, though the scanner still rates it 66/100 and marks it suspicious because of missing security headers.

Is kiwi.com safe to use for booking flights?

Yes, the scan supports safe use for normal browsing and booking. The domain is clean on major threat intelligence sources and uses HTTPS with HSTS enabled. As with any travel site, you should still review fare rules, baggage terms, and refund conditions before paying.

Why did kiwi.com get a suspicious verdict?

The suspicious verdict comes from the overall scoring model, not from malware or blacklist evidence. The scan found missing headers including X-Frame-Options, Referrer-Policy, Permissions-Policy, COEP, CORP, and X-XSS-Protection, which lowers the score to 66/100.

Does kiwi.com have a valid SSL certificate?

Yes. The site uses a valid TLSv1.3 certificate issued by Certainly Intermediate R1 (Certainly), and HSTS is enabled. The certificate expires in 13 days, so it is currently valid but close to renewal.

Is kiwi.com on any malware or spam blocklists?

No. Google Safe Browsing is clean, URLhaus is clean, and DNS blocklists from Spamhaus and SURBL are also clean. There is no blocklist evidence suggesting malicious activity.

Run your own scan

Check any URL instantly

Private, free, no account required. Your scan results are never made public — unlike VirusTotal.