Is airbnb.com legit?
Airbnb.com is a highly trusted platform for booking accommodations. While there are minor concerns about the number of external scripts and unsigned DNSSEC, the site demonstrates robust security, a long-standing reputation, and strong compliance measures typical of a leading travel marketplace.
Travel average: 74/100 · based on 25 sites
Checked: April 18, 2026 at 7:54 AM UTC · Refresh
Is airbnb.com a scam? Here's what we found.
The site boasts a strong security foundation with a valid SSL certificate, modern TLS, and robust content security policies, but the large number of external scripts presents a minor, albeit common, attack surface to be aware of.
With nearly 18 years of operation, a clear WHOIS record managed by a corporate registrar, and established branding, Airbnb's identity is exceptionally clear and well-documented.
As one of the most visited global websites, Airbnb has an outstanding reputation, is not blacklisted, and enjoys significant brand recognition, though a lack of a Trustpilot profile is noted (which isn't unusual for large, established platforms managing their own review ecosystem).
Contact information, privacy, and terms pages are readily available, indicating a good level of transparency. However, the absence of directly visible social media links on the homepage is a slight oversight for a consumer-facing brand.
The presence of comprehensive privacy policies and terms of service pages confirms Airbnb's commitment to legal and user data compliance, which is crucial for a global platform handling personal and payment information.
The underlying infrastructure is robust, featuring multiple reliable name servers, strong email authentication, and fast page load times. The primary concern here is the lack of DNSSEC, which is a common but important security enhancement.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2008-08-05T07:29:00Z (17 years, 11 months ago)
Registered through MarkMonitor Inc.
Expires in 108 days
DNSSEC status from WHOIS
crt.sh returned status 429
Excessive number of external scripts — may indicate malicious injection
robots.txt has 863 directives and references a sitemap
Not found on any DNS blacklists
Valid certificate, expires in 81 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.2
Resolves to: 166.117.27.62, 166.117.189.176
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt4.aspmx.l.google.com., alt3.aspmx.l.google.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-1932.awsdns-49.co.uk., ns-1453.awsdns-53.org., ns-474.awsdns-59.com., dns1.p08.nsone.net., dns2.p08.nsone.net., dns3.p08.nsone.net., dns4.p08.nsone.net., ns-558.awsdns-05.net.
Site has custom branding and social media metadata
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
Could not query Wayback Machine
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
No social media links found on homepage
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.