Is booking.com legit?
Booking.com appears Mostly Safe, although there are some notable gaps in transparency and critical legal pages. While core security and infrastructure are robust, the absence of a privacy policy and terms of service is a significant concern for user trust and operational compliance.
Travel average: 74/100 · based on 25 sites
Checked: April 15, 2026 at 2:29 PM UTC · Refresh
Is booking.com a scam? Here's what we found.
Security measures are generally strong, featuring a valid SSL certificate with modern TLS 1.3 encryption and a clean Google Web Risk report. The HTTP 202 status is peculiar but not a direct security flaw.
The domain boasts a very long history of over 28 years and is registered through MarkMonitor Inc., a reputable registrar commonly used by large corporations. This indicates a well-established and stable identity.
With a high Tranco rank (one of the most visited sites globally) and a clean DNS blacklist status, the site has a strong operational reputation. The lack of a Wayback Machine archive is unusual given its age but doesn't immediately suggest a negative reputation.
Transparency is a weakness, with no obvious contact information, no favicon, and no social media links visible on the homepage. This makes it harder for users to engage or find support.
Compliance is a significant issue due to the complete absence of privacy policy and terms of service pages. This is a critical deficiency for any online business, especially one handling user data and transactions.
The infrastructure is robust, featuring excellent DNS resolution, proper email authentication with SPF and DMARC, and HTTPS enforcement via HSTS. The use of AWS DNS and CloudFront reflects a scalable and reliable setup.
Signals Detected
This is one of the most visited websites globally
No favicon found — unusual for an established business
No sitemap found — common for smaller sites
Valid certificate, expires in 198 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Domain created 1998-04-17T04:00:00Z (28 years, 4 months ago)
Registered through MarkMonitor Inc.
Expires in 365 days
DNSSEC status from WHOIS
No robots.txt file — common for small sites
This business has no Trustpilot presence — not unusual for smaller or newer companies
Resolves to: 54.192.35.7, 54.192.35.113, 54.192.35.29, 54.192.35.46
Mail servers: mxb-0032a201.gslb.pphosted.com., mxa-0032a201.gslb.pphosted.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: ns-1959.awsdns-52.co.uk., ns-508.awsdns-63.com., ns-716.awsdns-25.net., ns-1288.awsdns-33.org.
Site enforces HTTPS via HSTS
Web server: CloudFront
No threats detected by Google Web Risk
Website returned status 202
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
crt.sh returned status 429
Not found on any DNS blacklists
No snapshots found in the Wayback Machine — site may be very new
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.