Skip to main content

Is createsend.com a Scam? Security Check Results - Campaign Monitor (implied) Reviews

C

Is createsend.com Safe? Security Analysis for Campaign Monitor (implied)

Check if createsend.com is a scam or legitimate. Free security scan and reviews.

TechnologyN/amedium
React 18SentryDatadog RUMGoogle Tag ManagerGoogle Analytics+5 more
Analyzed 9/5/2025Completed 8:34:55 AM
51
Security Score
MEDIUM RISK

Security scan incomplete. 3 out of 9 security checks failed to complete. The website may be inaccessible or protected by security measures. Please retry the scan or verify the website is accessible.

AI Summary

The website createsend.com is an established email newsletter software platform, likely associated with Campaign Monitor, providing SaaS solutions for email marketing. The domain is long-standing since 2005, indicating a mature business presence. The site content is minimal on the login page but consistent with a professional SaaS offering targeting businesses and marketers. The technical infrastructure leverages modern JavaScript frameworks such as React, and integrates multiple analytics and marketing tools including Google Analytics, Facebook Pixel, Hotjar, and Segment. Security posture is moderate with HTTPS enforced and use of reCAPTCHA, but lacks DNSSEC and explicit security headers. Privacy and cookie policies are not found on this page, indicating potential compliance gaps. Overall, the site is trustworthy but could improve transparency and security practices.

Detected Technologies

React 18SentryDatadog RUMGoogle Tag ManagerGoogle AnalyticsFacebook PixelHotjarAppcuesSegment AnalyticsreCAPTCHA v3

🧠AI Business Intelligence

Technology stack, business insights, and market analysis powered by AI.

Business Intelligence

Market & Strategic Analysis

Createsend.com operates in the technology sector, focusing on email marketing SaaS. The business model is subscription-based software delivery. The company targets businesses and marketers needing email newsletter tools. The domain age and registrar data support legitimacy. The site integrates with major marketing and analytics platforms, indicating a mature digital marketing ecosystem. No direct contact emails or phone numbers are provided on this page, relying on embedded contact forms. The lack of visible privacy and cookie policies suggests room for compliance improvement. No suspicious domains or partners were identified from the page content.

Security Posture Analysis

Comprehensive Security Assessment

The security maturity level is moderate. HTTPS is enforced, and reCAPTCHA v3 is implemented to prevent abuse. Monitoring tools like Sentry and Datadog RUM are used for error and performance tracking. However, DNSSEC is not enabled, and no explicit security headers were detected in the HTML content. No published security or incident response policies were found, which could impact incident handling readiness. No vulnerabilities or exposed sensitive data were detected in the analyzed content. The site would benefit from enhanced DNS security and published security policies to improve trust and compliance.

Strategic Recommendations

Priority Actions for Security Improvement

1

Enable DNSSEC on the domain to enhance DNS security and prevent spoofing.

Observations

AI-powered comprehensive website and business analysis.

AI-Enhanced Website Analysis

Business Insights

Company:

Campaign Monitor (implied)

Description:

Provides email newsletter software for sending email campaigns.

Key Services:
Email newsletter softwareEmail campaign management
Content Quality:

basic

Branding:

consistent

Technical Stack

Technologies:
React 18SentryDatadog RUMGoogle Tag ManagerGoogle AnalyticsFacebook PixelHotjarAppcuesSegment AnalyticsreCAPTCHA v3
Frameworks:
React
Performance:

moderate

Mobile:

good

Accessibility:

basic

SEO:

basic

Security Assessment

Security Score:
70/100
Best Practices:
  • HTTPS enforced
  • Use of reCAPTCHA v3
  • Use of security monitoring tools (Sentry, Datadog)

Analytics & Tracking

Services:
Google AnalyticsSegment AnalyticsHotjarDatadog RUM
Tracking Level:extensive
Privacy Compliance:poor

Advertising & Marketing

Ad Networks:
Bing AdsFacebook Ads
Tracking Pixels:
Facebook PixelHotjarSegment Analytics
Marketing Tools:
AppcuesOptimizelySegment
Transparency Level:basic

Website Quality Assessment

Design Quality:basic
User Experience:basic
Content Relevance:basic
Navigation Clarity:basic
Professionalism:basic
Trustworthiness:moderate

Key Observations

1

No privacy, cookie, or terms of service policies found on this page.

🛡️Security Headers

HTTP security headers analysis and recommendations.

Security Headers

HTTP security headers analysis

0/100
Score
Analysis failed - content could not be retrieved

👤GDPR Compliance

Privacy and data protection assessment under GDPR regulations.

GDPR Compliance

Privacy and data protection assessment

0/100
Score
Analysis failed - content could not be retrieved

🛡️NIS2 Compliance

Network & Information Security Directive compliance assessment.

NIS2 Compliance

Network & Information Security Directive

0/100
Score
Analysis failed - content could not be retrieved

📧Email Security

SPF, DKIM, and DMARC validation and email security assessment.

Email Security

SPF, DKIM, and DMARC validation

75/100
Score

DMARC not enforcing

MEDIUM

DMARC policy is set to "none"

No DKIM record found

MEDIUM

DKIM adds cryptographic signatures to emails

SPF
Sender Policy Framework
DKIM
DomainKeys Identified Mail
DMARC
Domain-based Message Authentication
MX Records
Mail Exchange Records
BIMI
Brand Indicators
MTA-STS
Mail Transfer Agent Security
TLS-RPT
TLS Reporting
DNSSEC
DNS Security
SPF Details
Record:
v=spf1 include:_spf.createsend.com ~all
DNS Lookups:1/10
Policy:~all
DMARC Details
Policy:none
Aggregate Reports:79bbcc7c@inbox.ondmarc.com
Forensic Reports:79bbcc7c@inbox.ondmarc.com
MTA-STS Details

🏆SSL/TLS Security

Certificate validity and encryption analysis.

SSL/TLS Security

Certificate validity and encryption analysis

82/100
Score

Weak Protocols Supported

HIGH

Server supports weak protocols: TLSv1.1

Certificate Transparency Not Implemented

LOW

Certificate is not logged in Certificate Transparency logs

Partial SSL/TLS Assessment

LOW

Completed 3 of 4 security checks due to time constraints

Protocol Support

TLSv1.3TLSv1.2TLSv1.1

OCSP Status

OCSP Stapling Enabled

📊DNS Health

DNS configuration and security assessment.

DNS Health

DNS configuration and security assessment

85/100
Score

DNSSEC Not Enabled

MEDIUM

DNSSEC is not configured for this domain

DMARC Policy Set to None

LOW

DMARC is configured but not enforcing any policy

Domain Registration Details

Domain Age
20 years(mature)
Expiry Risk
none(655 days)
Protection Level
strongDNSSEC OFF

DNS Records

A Records:54.151.47.231, 54.219.217.117
Name Servers:
ns0.createsend.com
ns1.createsend.com
ns2.createsend.com
ns3.createsend.com
ns4.createsend.com
ns5.createsend.com
MX Records:
5: mx21.inbound.createsend.com
5: mx20.inbound.createsend.com
SOA:Serial: 2009010158, TTL: 180s

DNSSEC Status

DNSSEC Not Enabled

DNS Performance

Resolution Time:53ms

SPF Analysis

SPF Record:
v=spf1 include:_spf.createsend.com ~all

Network Security

Port scanning and network exposure analysis.

Network Security

Port scanning and network exposure analysis

100/100
Score

Good Network Security Posture

LOW

No unnecessary services detected on common risky ports

🔧Technical Analysis

Detailed technical findings and analysis from AI assessment.

Technical Analysis

Comprehensive security assessment findings

Additional Findings

The website uses a modern React-based frontend with integration of multiple third-party analytics and marketing tools including Google Analytics, Facebook Pixel, Hotjar, Segment, and Appcues. The site loads asynchronously many scripts to optimize performance. CSS is preloaded and served from a dedicated subdomain. The domain is registered with MarkMonitor Inc., a reputable registrar. Performance is moderate with good mobile optimization but basic accessibility and SEO features. No CMS was detected. The site lacks DNSSEC and some security headers, representing technical debt in security hardening. Overall, the technical stack is modern but could improve in security and compliance aspects.
Analyze Another Website