Is hotels.com legit?
Hotels.com is a trusted and well-established platform, presenting strong security and infrastructure. While bot protection prevented some transparency and compliance checks, its long history and robust technical setup inspire confidence.
Travel average: 76/100 · based on 25 sites
Checked: April 28, 2026 at 11:00 AM UTC
Is hotels.com a scam? Here's what we found.
Security is strong with a valid SSL certificate, modern TLS 1.3, and clean Google Web Risk results, although the lack of DNSSEC is a minor point to consider.
The domain boasts an impressive age of over 32 years and is registered with a reputable corporate registrar, firmly establishing its long-standing identity.
With a high Tranco rank and clean DNS blacklist status, Hotels.com demonstrates a well-established and positive online reputation.
While the site has a basic branding setup, the inability to verify contact information and social media due to bot protection slightly impacts transparency.
The inability to access legal pages due to bot protection means the extent of the site's compliance cannot be fully verified, leading to a moderate, unavoidable deduction.
The robust infrastructure includes multiple IP resolutions, proper email server configuration with DMARC, HSTS, and clickjacking protection, ensuring a reliable and secure technical foundation.
Signals Detected
This is a well-known, high-traffic website
No structured data markup found
This business has no Trustpilot presence — not unusual for smaller or newer companies
Domain created 1994-03-30T05:00:00Z (32 years, 6 months ago)
Registered through CSC Corporate Domains, Inc.
Expires in 336 days
DNSSEC status from WHOIS
Valid certificate, expires in 70 days
Certificate issued by Let's Encrypt
Connection uses TLS 1.3
Resolves to: 2a02:26f0:3500:58d::277d, 2a02:26f0:3500:588::277d, 23.209.209.213
Mail servers: mxa.expediagroup.com., mxb.expediagroup.com.
Domain has DMARC email authentication configured
DNS providers: dns1.p09.nsone.net., dns2.p09.nsone.net., dns3.p09.nsone.net., dns4.p09.nsone.net., pdns1.ultradns.net., pdns2.ultradns.net., pdns3.ultradns.org., pdns4.ultradns.org., pdns5.ultradns.info., pdns6.ultradns.co.uk.
robots.txt has 402 directives
Site enforces HTTPS via HSTS
X-Frame-Options: SAMEORIGIN
Web server: istio-envoy
No threats detected by Google Web Risk
Site has a favicon but no social sharing metadata
Website returned HTTP 429 — likely WAF or bot protection blocking automated checks. The site is online but restricts non-browser access.
Bot protection prevented page inspection
Bot protection prevented checking legal pages
Bot protection prevented page inspection
No sitemap found — common for smaller sites
Could not query Wayback Machine
Not found on any DNS blacklists
Could not query certificate transparency logs
Fast page load
Stay Safe Online
Good habits to protect yourself, no matter the scan result.
Never reuse passwords across sites.
Add a second layer of security to your accounts.
Always verify unfamiliar stores before entering payment info.