HomeDirectory Ccarvana.com

carvana.com

HTTPS HTTP/2 Gzip Cloudflare Crawled in 12,860ms · June 27, 2026 13:57 UTC

carvana.com Website Overview & Technology Report

🤖 AI Summary
We performed a comprehensive analysis of carvana.com on 2026-06-27. The website returned an HTTP 403 status code with a server response time of 8976ms. The page is served over HTTP/2 protocol with Gzip compression enabled, achieving approximately 60.0% size reduction. The total page weight is 5 KB, and the site is served behind a CDN (Content Delivery Network). Warning: The website does not have a valid SSL certificate. Visitors may see security warnings in their browser, and data transmitted to and from this website is not encrypted. The security headers analysis reveals a score of 30/100 (below average). The following security headers are properly configured: X-Frame-Options and Referrer-Policy. However, the site is missing Content-Security-Policy, Strict-Transport-Security (HSTS), X-Content-Type-Options, and Permissions-Policy, which could expose the site and its users to cross-site scripting (XSS), clickjacking, and other web-based attacks. Our technology detection scan identified 1 technologies across 1 categories powering carvana.com. The detected stack includes Cloudflare. Based on our comprehensive analysis of domain age, SSL configuration, email authentication, security headers, and blacklist status, carvana.com receives an overall trust score of 68/100, classified as "Likely Safe".
68
/ 100
Trust Score
30
/ 100
Security Headers
HTTP Response
Status403
Response Time8976ms
ProtocolHTTP/2
Page Size5 KB
CompressionGzip
Compression Savings~60.0%
CDNYes ✓
Servercloudflare
Total Requests4
3rd Party Domains1
RedirectNone
Detected Technologies (1)
☁️ Cloudflare
Security Headers
Content-Security-Policy
Not set
Strict-Transport-Security (HSTS)
Not set
X-Frame-Options
Set ✓
X-Content-Type-Options
Not set
Referrer-Policy
Set ✓
Permissions-Policy
Not set
SSL Certificate
IssuerLet's Encrypt
Issuer FullcountryName=US, organizationName=Let's Encrypt, commonName=E7
SubjectcommonName=carvana.com
Type
TLS VersionTLS 1.3
Cipher SuiteTLS_AES_256_GCM_SHA384
Algorithm
Issued
Expires— (? days)
SANs

carvana.com Trust Score & Safety Analysis

🤖 AI Summary
After conducting a thorough safety and legitimacy analysis, carvana.com receives a trust score of 68/100, which places it in the "Likely Safe" category. This score is calculated by evaluating multiple factors including SSL certificate validity, domain registration history, email authentication protocols, security header configuration, and blacklist status across major threat intelligence databases. The analysis identified several positive trust signals: a valid HTTPS connection protecting data in transit, SPF (Sender Policy Framework) email authentication preventing email spoofing, DMARC email authentication with a reject policy — the strongest available setting, and DKIM (DomainKeys Identified Mail) providing cryptographic email verification. Areas of concern include: the absence of a Content-Security-Policy header, which leaves the site more vulnerable to cross-site scripting (XSS) attacks, the domain's WHOIS information is hidden behind a privacy service, making it harder to verify the owner's identity, and DNSSEC is not enabled, leaving DNS queries vulnerable to spoofing attacks. While these issues don't necessarily indicate malicious intent, they represent areas where the website's security posture could be improved. We checked carvana.com against 8 major blacklist databases including Google Safe Browsing, Phishtank, Urlhaus, Openphish, Dnsfilter, Spamhaus Dbl, Surbl, and Virustotal. The domain passed all 8 checks with a clean status, meaning it has not been flagged for phishing, malware distribution, spam, or other malicious activities by any of the tested threat intelligence providers.
68
/ 100
Likely Safe
Trust Signals
Valid HTTPS
SPF configured
DMARC configured (p=reject)
DKIM configured
⚠️ DNSSEC not enabled
⚠️ Missing Content-Security-Policy
Blacklist Checks (8/8 clean)
Google Safe Browsing clean
Phishtank clean
Urlhaus clean
Openphish clean
Dnsfilter clean
Spamhaus Dbl clean
Surbl clean
Virustotal clean

carvana.com Technology Stack & Detected Technologies

🤖 AI Summary
Our technology detection engine scanned carvana.com and identified 1 distinct technologies across 1 categories. This analysis is performed by examining HTTP response headers, HTML source code patterns, JavaScript library fingerprints, CSS framework signatures, and DNS records. CDN: Cloudflare — accelerates content delivery by caching assets at edge locations worldwide for carvana.com.
CDN
☁️ Cloudflare(100%)

carvana.com Performance, Speed & Core Web Vitals

🤖 AI Summary
carvana.com delivers its homepage in 8976ms (server response time), which is considered slow by industry standards. The total page weight is 5 KB, and we detected 4 resource requests loading assets from 1 third-party domains. A high number of third-party domains can significantly impact page load time due to additional DNS lookups and TLS handshakes required for each domain. The website uses Gzip compression for text-based assets, achieving an estimated 60.0% reduction in transfer size. This reduces bandwidth usage and improves page load times, especially for visitors on slower connections. Asset minification status: 0 out of 1 CSS files and 0 out of 0 JavaScript files are minified. Minifying the remaining 1 unminified file(s) could further reduce page weight by 10-30% for those assets. Minification is a best practice that reduces download sizes without affecting functionality. The site is served through a Content Delivery Network (CDN), which caches static assets at edge servers around the world. This means visitors from different geographic regions receive content from the nearest edge server, significantly reducing latency. CDN usage is particularly important for websites with a global audience, as it can reduce page load times by 40-60% for distant visitors. From an environmental perspective, each page view of carvana.com produces approximately 0.0g of CO₂, earning a carbon rating of A. This places the website among the cleanest on the web, demonstrating efficient use of server resources and optimized content delivery. For reference, the average web page produces about 0.5g of CO₂ per page view. The page weight of 5 KB is the primary factor in this calculation. Core Web Vitals data from the Chrome User Experience Report (CrUX) is not available for carvana.com. This typically means the site doesn't have enough real-world Chrome user traffic to generate statistically significant field data, or the domain is not included in the CrUX dataset. Core Web Vitals (LCP, INP, CLS) are important Google ranking factors that measure real user experience.
Core Web Vitals data not available
Requires CrUX API key configuration
Carbon Footprint
CO₂ per page view0.0g
RatingA
Page Weight & Optimization
HTML Size5 KB
CompressionGzip
Compression Savings~60.0%
CDNYes ✓
Total Requests4
3rd Party Domains1
CSS Minified0/1
JS Minified0/0

carvana.com DNS Records, Email Authentication & Domain Registration

🤖 AI Summary
carvana.com resolves to the IPv4 address 104.18.42.169 and also supports IPv6 (2606:4700:4403::6812:2aa9), demonstrating modern network infrastructure readiness. The domain has 2 A record(s) configured. The domain name system is managed by 2 name servers: jake.ns.cloudflare.com and meg.ns.cloudflare.com. Having 2 name servers provides good redundancy — if one fails, the others can continue serving DNS queries. The choice of name servers often indicates the DNS hosting provider or CDN service being used. Email for carvana.com is handled by Google Workspace with 5 MX records configured: aspmx.l.google.com, alt1.aspmx.l.google.com, and alt2.aspmx.l.google.com and 2 more. Multiple MX records provide failover redundancy — if the primary mail server is unavailable, email will be routed to the next available server. SPF (Sender Policy Framework) is configured, which specifies which mail servers are authorized to send email on behalf of this domain. This helps prevent email spoofing and improves email deliverability. DMARC (Domain-based Message Authentication, Reporting and Conformance) is configured with a reject policy — the strongest setting, instructing receiving servers to reject unauthorized emails entirely. DKIM (DomainKeys Identified Mail) is configured, adding a cryptographic signature to outgoing emails that receiving servers can verify to confirm the email hasn't been tampered with in transit. DNSSEC is not enabled for carvana.com. While not critical for most websites, DNSSEC adds an important security layer by ensuring DNS responses haven't been tampered with during transit. Enabling DNSSEC is recommended for domains handling sensitive data or financial transactions. Our subdomain enumeration scan discovered 4 active subdomains for carvana.com: api.carvana.com, help.carvana.com, partners.carvana.com, and www.carvana.com. Active subdomains can reveal the organization's infrastructure, including development environments, API endpoints, and third-party service integrations.
DNS Records
A
104.18.42.169
172.64.145.87
AAAA
2606:4700:4403::6812:2aa9
NS
jake.ns.cloudflare.com
meg.ns.cloudflare.com
MX
aspmx.l.google.com
alt1.aspmx.l.google.com
alt2.aspmx.l.google.com
alt3.aspmx.l.google.com
alt4.aspmx.l.google.com
Email & Authentication
SPF
DMARC p=reject
DKIM
DNSSEC
MX ProviderGoogle Workspace
Registrar
Organisation
Country
Contact
Registered
Expires
Domain Age
IPv6 SupportYes ✓
Subdomains (4 found)
api.carvana.com help.carvana.com partners.carvana.com www.carvana.com

carvana.com Page Content, Images & Accessibility

🤖 AI Summary
The homepage of carvana.com contains 127 words of visible text content. This is a relatively short page — adding more descriptive content could improve search engine visibility. The page is structured with 3 H2 headings, 0 H3 headings, 0 H4 headings. The link structure consists of 0 internal links pointing to other pages on the same domain and 1 external link pointing to third-party websites. There are 0 external JavaScript files, 1 CSS stylesheets, and 0 iframes on the page. Notable missing features: XML Sitemap, robots.txt, and Schema.org structured data. Adding these could improve search engine discoverability and rich result eligibility.
127
Words
0
Images
100%
Alt Text Score
5
Page Size (KB)
Content Structure
H1Sorry, you have been blocked
H2 Tags3
H3 Tags0
H4 Tags0
H5 Tags0
H6 Tags0
Internal Links0
External Links1
Assets & Features
JavaScript Files0
JS Minified0/0
CSS Files1
CSS Minified0/1
Iframes0
Images0
Missing Alt0
SitemapNo
Robots.txtNo
PWANo
AMPNo
RSS FeedNo

carvana.com SEO Analysis, Meta Tags & Open Graph

🤖 AI Summary
The title tag for carvana.com is well-optimized at 32 characters: "Attention Required! | Cloudflare". The length falls within the ideal range for Google search results, ensuring the full title is displayed without truncation. No meta description is configured for carvana.com. This is a critical SEO oversight — without a meta description, Google will auto-generate a snippet from page content, which may not accurately represent the page or entice users to click. Adding a unique, compelling meta description of 120-155 characters is strongly recommended. The page language is declared as en-us and the meta robots directive is set to noindex, nofollow. No Open Graph tags are configured. When someone shares a link to carvana.com on social media, the platform will have to guess the title, description, and image — often producing unattractive or inaccurate previews. Adding OG tags is essential for social media marketing.
Google SERP Preview
Attention Required! | Cloudflare
https://carvana.com
Meta Tags
TitleAttention Required! | Cloudflare...
Title Length32 chars
Meta Desc Length0 chars
H1Sorry, you have been blocked
Languageen-US
Canonical
Meta Robotsnoindex, nofollow
Meta Keywordsnot set
Schema.org & Social
Schema Types
OG Type
OG ImageNot set
Twitter Card
FaviconNot set