Is cars.com legit?
This site appears trustworthy overall. While strong bot protection prevented checking some transparency and compliance elements, its long domain age, high traffic, and well-configured infrastructure point to a legitimate and established online presence.
Automotive average: 79/100 · based on 29 sites
Checked: April 27, 2026 at 11:54 PM UTC
Is cars.com a scam? Here's what we found.
The site uses a valid SSL certificate with TLS 1.2 and has a Content Security Policy, indicating a generally secure setup. Google Web Risk confirms no active threats. The upcoming certificate expiry is a minor maintenance point.
A deeply established domain, nearly 29 years old, managed by a reputable registrar (MarkMonitor Inc.) clearly indicates a long-standing and known entity behind the website.
The extremely high Tranco rank (#4099) coupled with a clean DNS blacklist record and significant domain age points to a very well-known and reputable online presence.
The site's bot protection significantly hampered the ability to verify contact information, legal pages, and social media presence, which is a notable gap in assessing transparency.
Due to bot protection, crucial legal pages could not be inspected, making a definitive assessment of compliance difficult. No structured data was found, which could also streamline compliance or information delivery.
Robust email authentication (DMARC, multiple MX records) and reliable DNS resolution showcase a well-managed infrastructure. The lack of DNSSEC is a minor missed opportunity for enhanced security.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
Domain created 1998-02-12T05:00:00Z (28 years, 7 months ago)
Registered through MarkMonitor Inc.
Expires in 289 days
DNSSEC status from WHOIS
This business has no Trustpilot presence — not unusual for smaller or newer companies
crt.sh returned status 429
Resolves to: 54.80.177.85, 3.93.126.98
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt3.aspmx.l.google.com., alt4.aspmx.l.google.com.
Domain has DMARC email authentication configured
DNS providers: ns-1005.awsdns-61.net., ns-1142.awsdns-14.org., ns-1879.awsdns-42.co.uk., ns-285.awsdns-35.com.
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
Valid certificate, expires in 190 days
Certificate issued by GlobalSign nv-sa
Connection uses TLS 1.2
No favicon found — unusual for an established business
Site has Content Security Policy configured
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
No sitemap found — common for smaller sites
No robots.txt file — common for small sites
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.