Is hotels.com legit?
Hotels.com appears to be a legitimate and established travel booking platform, but a critical issue with site accessibility significantly lowers its current trustworthiness. While its long domain history and robust email security are strong positive indicators, you currently cannot access the service.
Travel average: 74/100 · based on 25 sites
Checked: April 18, 2026 at 8:10 AM UTC · Refresh
Is hotels.com a scam? Here's what we found.
The site uses a modern TLS 1.3 encryption, ensuring secure connections, and Google's Web Risk scanner found no threats, which are solid security practices.
The domain has an impressive age of over 32 years, establishing a strong historical presence, and is registered with a reputable corporate registrar, indicating stability.
Despite not having a Trustpilot profile, which is odd for such a prominent brand, the high Tranco rank confirms it as a widely recognized and trafficked website, showing significant market presence.
The missing favicon is a minor oversight for a site of this stature, but the critical issue of the site being unreachable severely impacts its current usability and therefore perceived openness.
No specific red flags regarding compliance were found, which, combined with its established nature, suggests typical adherence to necessary legal frameworks for a large travel booking site.
While DNS resolution and email configurations (SPF, DMARC) are excellent, the fundamental problem of the website being unreachable is a critical infrastructure failure that needs immediate attention.
Signals Detected
This is a well-known, high-traffic website
Could not load website: Get "http://hotels.com": context deadline exceeded (Client.Timeout exceeded while awaiting headers)
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1994-03-30T05:00:00Z (32 years, 6 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 346 days
DNSSEC status from WHOIS
Valid certificate, expires in 80 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
crt.sh returned status 429
No favicon found — unusual for an established business
Could not reach site: Head "https://hotels.com": stream error: stream ID 7; INTERNAL_ERROR; received from peer
No threats detected by Google Web Risk
Resolves to: 2a02:26f0:1700:384::277d, 2a02:26f0:1700:383::277d, 23.209.209.213
Mail servers: mxa.expediagroup.com., mxb.expediagroup.com.
Domain has SPF email authentication configured
Domain has DMARC email authentication configured
DNS providers: pdns4.ultradns.org., pdns5.ultradns.info., dns1.p09.nsone.net., dns2.p09.nsone.net., dns3.p09.nsone.net., dns4.p09.nsone.net., pdns6.ultradns.co.uk., pdns1.ultradns.net., pdns2.ultradns.net., pdns3.ultradns.org.
No sitemap found — common for smaller sites
Not found on any DNS blacklists
Could not query Wayback Machine
No robots.txt file — common for small sites
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.