Is airbnb.com legit?
Airbnb is a highly trusted platform, as expected for a global brand. While it shows some minor areas for improvement, like DNSSEC implementation and managing external scripts, its robust security measures, clear identity, and established infrastructure confirm its reliability.
Travel average: 76/100 · based on 25 sites
Checked: April 27, 2026 at 8:03 PM UTC
Is airbnb.com a scam? Here's what we found.
The site benefits from a valid SSL certificate with TLS 1.2, HSTS, and Content Security Policy, all contributing to a strong security posture. The excessive number of external scripts presents a minor concern for potential vulnerabilities.
The domain has a substantial age of almost 18 years and is registered with a reputable registrar, MarkMonitor Inc., indicating a well-established and legitimate entity.
With a high Tranco rank, clean DNS blacklists, and a good domain age, the site commands a strong online reputation. The absence of a Trustpilot profile is a minor neutral point given its global recognition.
Airbnb provides comprehensive contact information, legal pages (Privacy & Terms), and custom branding. The lack of immediately identifiable social media links on the homepage is a slight drawback for user engagement.
The presence of both a privacy policy and terms of service pages demonstrates a commitment to user compliance and legal standards, which is essential for a platform handling sensitive user data and transactions.
The site boasts good DNS resolution, multiple mail servers with DMARC, and robust name servers, indicating a resilient infrastructure. The unsigned DNSSEC and missing sitemap are areas for potential enhancement.
Signals Detected
This is one of the most visited websites globally
Site uses structured data identifying itself as: WebSite
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2008-08-05T07:29:00Z (17 years, 11 months ago)
Registered through MarkMonitor Inc.
Expires in 99 days
DNSSEC status from WHOIS
Excessive number of external scripts — may indicate malicious injection
Resolves to: 166.117.189.176, 166.117.27.62
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has DMARC email authentication configured
DNS providers: dns1.p08.nsone.net., dns2.p08.nsone.net., dns3.p08.nsone.net., dns4.p08.nsone.net., ns-1453.awsdns-53.org., ns-1932.awsdns-49.co.uk., ns-474.awsdns-59.com., ns-558.awsdns-05.net.
Valid certificate, expires in 72 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.2
robots.txt has 863 directives and references a sitemap
crt.sh returned status 429
Site has custom branding and social media metadata
Site enforces HTTPS via HSTS
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: nginx
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
Not found on any DNS blacklists
Could not query Wayback Machine
Website is live and responding
Website appears to have contact information
Website has both privacy policy and terms of service pages
No social media links found on homepage
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.