Is booking.com legit?
Booking.com is Mostly Safe, but with significant concerns in Transparency and Compliance that are very unusual for such a huge, established brand. The missing legal pages (privacy policy, terms of service) are particularly problematic and unexpected for a site of this stature.
Travel average: 75/100 · based on 25 sites
Checked: April 27, 2026 at 11:08 AM UTC
Is booking.com a scam? Here's what we found.
The site has a robust security setup with a valid SSL certificate (TLS 1.3), HSTS enabled, and is clean on Google Web Risk, indicating good baseline protection.
The domain is extremely old and registered with a reputable registrar, MarkMonitor Inc., indicating a long-standing and established entity, though the missing favicon is a minor oversight for such a large brand.
Despite a very high Tranco rank and clean DNS blacklists, the absence of a Web Archive history for such an old domain is a significant and unexpected finding for a prominent site.
Transparency is a major weakness, with no obvious contact information or social media links on the homepage, making it difficult for users to connect or seek support from a major consumer platform.
Compliance is severely lacking, as the absence of a privacy policy and terms of service is a critical red flag for any website involved in online transactions and handling user data, especially one of this magnitude.
The infrastructure includes good DNS resolution, DMARC, and modern name servers on AWS, but the 'HTTP 202' website status is an unusual server response that warrants attention.
Signals Detected
This is one of the most visited websites globally
No structured data markup found
Valid certificate, expires in 186 days
Certificate issued by DigiCert Inc
Connection uses TLS 1.3
Domain created 1998-04-17T04:00:00Z (28 years, 5 months ago)
Registered through MarkMonitor Inc.
Expires in 353 days
DNSSEC status from WHOIS
No favicon found — unusual for an established business
No sitemap found — common for smaller sites
This business has no Trustpilot presence — not unusual for smaller or newer companies
No robots.txt file — common for small sites
Resolves to: 54.192.35.29, 54.192.35.7, 54.192.35.113, 54.192.35.46
Mail servers: mxb-0032a201.gslb.pphosted.com., mxa-0032a201.gslb.pphosted.com.
Domain has DMARC email authentication configured
DNS providers: ns-1288.awsdns-33.org., ns-1959.awsdns-52.co.uk., ns-508.awsdns-63.com., ns-716.awsdns-25.net.
Website returned status 202
No obvious contact information found on homepage
No privacy policy or terms of service found
No social media links found on homepage
Site enforces HTTPS via HSTS
Web server: CloudFront
No threats detected by Google Web Risk
crt.sh returned status 429
No snapshots found in the Wayback Machine — site may be very new
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.