Is expedia.com legit?

78
/ 100
Mostly Safe
Industry: Travel

Expedia.com appears to be a mostly safe platform for booking travel. While it has a very long-standing online presence and robust technical security, the missing legal pages and absence of social media links on the homepage are surprising omissions for such a well-known brand.

Travel average: 74/100 · based on 25 sites

Checked: April 16, 2026 at 4:41 PM UTC · Refresh

Is expedia.com a scam? Here's what we found.

Security 90/100

The site boasts strong security with a modern TLS 1.3 connection, valid SSL certificate, and no detected threats from Google Web Risk. It also enforces HTTPS and clickjacking protection, which is excellent for user data safety.

Identity 95/100

Expedia is an incredibly well-established domain, over 30 years old, registered with a reputable corporate registrar, virtually eliminating concerns about its legitimacy or longevity. This is a clear indicator of a trusted, long-term business.

Reputation 90/100

Its high Tranco Rank and clean DNS blacklist status solidify its reputation as a major, widely recognized travel platform. The domain's extensive history further reinforces its standing in the industry.

Transparency 70/100

While contact information is present, the lack of structured data and an absence of social media links on the homepage are unexpected for a company of this size, making it slightly less transparent than ideal in certain areas.

Compliance 60/100

A significant concern is the reported absence of privacy policy or terms of service pages. For an online travel agency handling personal data and financial transactions, these are fundamental for legal compliance and user trust.

Infrastructure 85/100

The site has a robust DNS setup with multiple IP addresses and advanced email authentication (SPF, DMARC), demonstrating a sophisticated infrastructure. A transient HTTP 429 error is a minor flag in an otherwise strong technical foundation.

Signals Detected

[+]
Tranco Rank: Rank #2122

This is a well-known, high-traffic website

[?]
Structured Data: None found

No structured data markup found

[?]
Trustpilot: No Trustpilot profile

This business has no Trustpilot presence — not unusual for smaller or newer companies

[+]
SSL Certificate: Valid

Valid certificate, expires in 53 days

[?]
Certificate Issuer: Let's Encrypt

Certificate issued by Let's Encrypt

[+]
TLS Version: TLS 1.3

Connection uses TLS 1.3

[+]
Domain Age: 30 years, 10 months

Domain created 1995-11-25T05:00:00Z (30 years, 10 months ago)

[?]
Registrar: CSC Corporate Domains, Inc.

Registered through CSC Corporate Domains, Inc.

[+]
Domain Expiry: 2026-10-12T21:52:56Z

Expires in 179 days

[+]
DNSSEC: unsigned

DNSSEC status from WHOIS

[?]
Certificate Transparency: Unable to check

crt.sh returned status 502

[?]
Branding: Basic

Site has a favicon but no social sharing metadata

[+]
DNS Resolution: 4 IP(s)

Resolves to: 2a02:26f0:3400::1703:5820, 2a02:26f0:3400::1703:5828, 2.16.241.212, 2.16.241.222

[+]
Email (MX Records): 2 record(s)

Mail servers: mxb.expediagroup.com., mxa.expediagroup.com.

[+]
SPF Record: Present

Domain has SPF email authentication configured

[+]
DMARC Record: Present

Domain has DMARC email authentication configured

[?]
Name Servers: 10 server(s)

DNS providers: dns2.p09.nsone.net., dns3.p09.nsone.net., dns4.p09.nsone.net., pdns1.ultradns.net., pdns2.ultradns.net., pdns3.ultradns.org., pdns4.ultradns.org., pdns5.ultradns.info., pdns6.ultradns.co.uk., dns1.p09.nsone.net.

[+]
robots.txt: Present

robots.txt has 77 directives

[+]
DNS Blacklists: Clean

Not found on any DNS blacklists

[+]
HSTS Header: Present

Site enforces HTTPS via HSTS

[+]
Clickjacking Protection: Present

X-Frame-Options: SAMEORIGIN

[?]
Server: istio-envoy

Web server: istio-envoy

[+]
Google Web Risk: Clean

No threats detected by Google Web Risk

[?]
Sitemap: Not found

No sitemap found — common for smaller sites

[~]
Website Status: HTTP 429

Website returned status 429

[+]
Contact Info: Found

Website appears to have contact information

[-]
Legal Pages: Missing

No privacy policy or terms of service found

[~]
Social Media Presence: None found

No social media links found on homepage

[?]
Web Archive: Unable to check

Could not query Wayback Machine

[+]
Page Load Time: 196ms

Fast page load

Embed This Badge

Own this site? Show visitors your trust score.

Trust badge for expedia.com
<a href="https://verified.fyi/review/expedia.com"><img src="https://verified.fyi/badge/expedia.com?size=medium&style=full&theme=dark" alt="expedia.com trust score — verified.fyi" /></a>
[![expedia.com trust score](https://verified.fyi/badge/expedia.com?size=medium&style=full&theme=dark)](https://verified.fyi/review/expedia.com)

Stay Safe Online

Good habits to protect yourself, no matter the scan result.

Use a password manager

Never reuse passwords across sites.

Enable two-factor authentication

Add a second layer of security to your accounts.

Check before you buy

Always verify unfamiliar stores before entering payment info.

When evaluating an online travel giant like Expedia.com, consumers expect a high degree of reliability and transparency. This platform has been a cornerstone of online travel for over three decades, a longevity that is almost unheard of in the digital world. This extensive history is a significant trust signal, indicating a well-established and enduring business. However, even industry leaders can have unexpected gaps. For a multi-billion dollar company handling vast amounts of user data and transactions, the reported absence of easily accessible privacy policy or terms of service documents is a notable concern. These legal pages are crucial for consumers to understand their rights, data usage, and the platform's liabilities—they're not just regulatory checkboxes, but essential elements of user trust. While Expedia's technical security, like its modern SSL and email authentication, is robust, users should still actively look for these legal documents, perhaps in the footer or a dedicated 'Help' section, if not immediately apparent. Overall, your travel plans are likely in safe hands with Expedia, given its vast operational scale and strong technical infrastructure. Just be sure to locate and review their legal policies before making significant commitments, as transparent communication about user rights is paramount for any online service.