Is cars.com legit?

62
/ 100
Mostly Safe
Industry: Automotive

While Cars.com has a long history and strong underlying technical infrastructure, I recommend using caution due to several critical missing elements. The inability to access the site content via a standard HTTP 403 error, coupled with the absence of essential legal pages and clear contact information, raises serious concerns about transparency and consumer protection.

Automotive average: 73/100 · based on 29 sites

Checked: April 18, 2026 at 7:58 AM UTC · Refresh

Is cars.com a scam? Here's what we found.

Security 90/100

The security posture appears robust with a valid SSL certificate from a reputable issuer, modern TLS, and a clean Google Web Risk report. Clickjacking protection is also in place, indicating a good effort to secure user interaction.

Identity 90/100

This domain boasts an impressive 28-year age registered through a reputable registrar, strongly suggesting a long-established and authentic entity. The only minor quibble is the missing favicon, which is unusual for such a long-standing brand.

Reputation 85/100

With a high Tranco Rank and a decades-old domain, Cars.com has a significant web presence and history. It's clean on DNS blacklists, reinforcing its position as a long-standing, legitimate player in its industry.

Transparency 40/100

The inability to access the site and the complete lack of contact details or social media presence are significant issues. For a well-known entity, this lack of accessibility and clear communication channels is concerning and hinders user trust.

Compliance 30/100

The complete absence of a privacy policy and terms of service is a critical flaw. For any online business, especially one involved in high-value transactions like car sales, these are non-negotiable legal and ethical requirements.

Infrastructure 85/100

The site benefits from a professional infrastructure, including reliable DNS servers, multiple robust mail servers with SPF and DMARC, and Cloudflare. The fast page load time further indicates a well-maintained technical foundation.

Signals Detected

[+]
Tranco Rank: Rank #4146

This is a well-known, high-traffic website

[?]
Structured Data: None found

No structured data markup found

[?]
Trustpilot: No Trustpilot profile

This business has no Trustpilot presence — not unusual for smaller or newer companies

[+]
Domain Age: 28 years, 7 months

Domain created 1998-02-12T05:00:00Z (28 years, 7 months ago)

[?]
Registrar: MarkMonitor Inc.

Registered through MarkMonitor Inc.

[+]
Domain Expiry: 2027-02-11T05:00:00Z

Expires in 298 days

[+]
DNSSEC: unsigned

DNSSEC status from WHOIS

[?]
Certificate Transparency: Unable to check

crt.sh returned status 429

[~]
Branding: Missing

No favicon found — unusual for an established business

[+]
Clickjacking Protection: Present

X-Frame-Options: SAMEORIGIN

[?]
Server: cloudflare

Web server: cloudflare

[+]
Google Web Risk: Clean

No threats detected by Google Web Risk

[~]
Website Status: HTTP 403

Website returned status 403

[~]
Contact Info: Not found

No obvious contact information found on homepage

[-]
Legal Pages: Missing

No privacy policy or terms of service found

[~]
Social Media Presence: None found

No social media links found on homepage

[?]
Sitemap: Not found

No sitemap found — common for smaller sites

[?]
robots.txt: Not found

No robots.txt file — common for small sites

[+]
DNS Blacklists: Clean

Not found on any DNS blacklists

[+]
SSL Certificate: Valid

Valid certificate, expires in 199 days

[?]
Certificate Issuer: GlobalSign nv-sa

Certificate issued by GlobalSign nv-sa

[+]
TLS Version: TLS 1.2

Connection uses TLS 1.2

[+]
DNS Resolution: 2 IP(s)

Resolves to: 3.93.126.98, 54.80.177.85

[+]
Email (MX Records): 5 record(s)

Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt4.aspmx.l.google.com., alt3.aspmx.l.google.com.

[+]
SPF Record: Present

Domain has SPF email authentication configured

[+]
DMARC Record: Present

Domain has DMARC email authentication configured

[+]
Name Servers: 4 server(s)

DNS providers: ns-1142.awsdns-14.org., ns-1879.awsdns-42.co.uk., ns-285.awsdns-35.com., ns-1005.awsdns-61.net.

[?]
Web Archive: Unable to check

Could not query Wayback Machine

[+]
Page Load Time: 553ms

Fast page load

Embed This Badge

Own this site? Show visitors your trust score.

Trust badge for cars.com
<a href="https://verified.fyi/review/cars.com"><img src="https://verified.fyi/badge/cars.com?size=medium&style=full&theme=dark" alt="cars.com trust score — verified.fyi" /></a>
[![cars.com trust score](https://verified.fyi/badge/cars.com?size=medium&style=full&theme=dark)](https://verified.fyi/review/cars.com)

Stay Safe Online

Good habits to protect yourself, no matter the scan result.

Use a password manager

Never reuse passwords across sites.

Enable two-factor authentication

Add a second layer of security to your accounts.

Check before you buy

Always verify unfamiliar stores before entering payment info.

When evaluating an online automotive marketplace like Cars.com, consumers typically look for trustworthiness and ease of use. A major concern here is that the website returned an HTTP 403 Forbidden status, which means visitors can't actually access the content. This is highly unusual for such a well-established company in the automotive industry and immediately poses a significant barrier to trust. Beyond accessibility, a primary red flag for Car.com's current state is the complete absence of fundamental legal pages, such as a privacy policy and terms of service. For a platform facilitating significant financial transactions like car purchases, these documents are not just legal niceties; they are crucial for outlining user rights, data protection, and dispute resolution. Their omission leaves consumers vulnerable and underscores a serious gap in compliance and consumer protection. Despite these critical issues, Cars.com otherwise shows signs of a long-standing, authentic operation. Its domain has existed for nearly three decades, registered through a reputable registrar, and benefits from robust backend infrastructure and email authentication. This combination of a strong historical and technical foundation with severe current accessibility and compliance problems presents a perplexing picture. While its longevity suggests legitimacy, the current operational deficiencies warrant significant caution for anyone considering using the platform.