Is carvana.com legit?
This site appears trustworthy overall. Despite some minor presentation and assessment issues due to bot protection, it demonstrates strong technical fundamentals and a long, established history, aligning with a reliable online presence.
Automotive average: 77/100 · based on 29 sites
Checked: April 27, 2026 at 12:32 PM UTC
Is carvana.com a scam? Here's what we found.
The site uses a modern TLS version, passed Google Web Risk checks, and has clickjacking protection. While the SSL certificate expires soon and CT status is unknown, the core security is sound.
With a domain age of almost 23 years and registration through a corporate registrar, the site's identity is clearly established and legitimate.
Carvana.com has excellent traffic ranking and is not blacklisted, indicating a strong reputation. The missing favicon is a minor aesthetic oversight for a site of this stature.
The heavy bot protection prevented verification of critical transparency elements like contact information and social media presence, which is a notable gap in assessment, though understandable for a large business.
The inability to inspect legal pages due to bot protection means direct compliance verification was not possible. For a site this established, industry best practices imply sufficient compliance, but it remains unconfirmed.
The site boasts robust infrastructure with multiple IP addresses, properly configured email authentication (DMARC), and reliable name servers, all indicative of a well-managed online platform.
Signals Detected
No structured data markup found
This is a well-known, high-traffic website
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 2003-10-18T08:05:21Z (22 years, 10 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 173 days
DNSSEC status from WHOIS
Resolves to: 2a06:98c1:310a::ac40:9157, 2606:4700:4403::6812:2aa9, 104.18.42.169, 172.64.145.87
Mail servers: aspmx.l.google.com., alt1.aspmx.l.google.com., alt2.aspmx.l.google.com., alt4.aspmx.l.google.com., alt3.aspmx.l.google.com.
Domain has DMARC email authentication configured
DNS providers: jake.ns.cloudflare.com., meg.ns.cloudflare.com.
Valid certificate, expires in 43 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
crt.sh returned status 429
No favicon found — unusual for an established business
No sitemap found — common for smaller sites
No robots.txt file — common for small sites
X-Frame-Options: SAMEORIGIN
Web server: cloudflare
No threats detected by Google Web Risk
Website returned HTTP 403 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
Could not query Wayback Machine
Not found on any DNS blacklists
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.