Home / Scam Alerts / Website Legitimacy Check
9-POINT WEBSITE CHECK

How to tell if a website is legit.

Quick answerDo not trust a website because it looks polished or shows a padlock. Read the exact domain, check when it was registered, verify contact details outside the site, inspect refund and privacy policies, search for independent complaints, check Google Safe Browsing, and use a payment method with dispute rights. One green signal is never enough.

A fake website can copy a real logo, clone a storefront, buy convincing reviews, and obtain HTTPS in an afternoon. The question is not whether one part looks legitimate. The question is whether the site's identity, history, policies, reputation, and payment behavior tell the same story.

Use the checks below before you enter a password, card number, identity document, bank login, or crypto wallet. If the site is creating urgency, that is a reason to slow down, not a reason to skip a step.

The nine checks

1. Read the exact domain, one character at a time

Ignore the logo and page title. Read the address bar. Scammers use misspellings, extra words, unexpected subdomains, and look-alike characters. In bank.example-login.com, the registered domain is example-login.com, not bank.

If a message claims to be from a bank, retailer, government agency, or delivery company, do not use its link. Open the official app or type the known address yourself.

2. Ask how you arrived

An unexpected text, social ad, direct message, QR code, or sponsored search result deserves extra scrutiny. A paid search placement is advertising, not verification. The FTC advises contacting a company through information you looked up independently when a request is unexpected.

3. Check the domain's registration history

Use ICANN Lookup to view available domain registration data. Compare the creation date with the story on the site. A store claiming "20 years in business" on a domain registered last week has a credibility problem.

Registration privacy is common and is not proof of fraud. Old domains can be hacked or sold. Domain age is one clue that must agree with the rest of the evidence.

4. Verify the business outside its own page

Check the address on an independent map, call a number found through a trusted source, and search the legal business name in the relevant government registry. A contact page containing only a form, a free email address, or a messaging-app handle gives you little recourse.

For a regulated financial company, verify registration with the actual regulator. A regulator logo in the footer is just an image until the regulator's database confirms the business.

5. Read the return, shipping, privacy, and dispute policies

Look for specific timeframes, costs, exclusions, a return address, and a working contact method. Search a distinctive sentence from the policy in quotation marks. Scam networks often paste the same policy across unrelated stores and forget to replace another company's name.

A missing policy is bad. A policy that says every sale is final, gives no return address, or requires expensive international shipping can make a technically delivered product almost impossible to return.

6. Test the offer against reality

Compare the price with established sellers. A scarce product at 80% below every legitimate market price is not a secret wholesale connection. It is often bait. Reverse-search product photos when an expensive item appears to use catalog images or pictures copied from another listing.

7. Search for complaints without trusting the star average

Search the domain and company name with terms such as scam, complaint, refund, and review. Read dates and details across multiple sources. The FTC warns that reviews and ratings can be fake or misleading.

Do not treat the absence of complaints as proof. A disposable site may be too new to have victims posting under the current name.

8. Check for known security warnings

Use the Google Safe Browsing site status tool and pay attention to browser warnings. A clean result means the site was not identified by that system at that moment; it does not certify the business, product, or seller.

Do not download an app, browser extension, security update, or remote-access tool because an unfamiliar page tells you to.

9. Judge the payment method

The FTC says paying by credit card generally provides the best protection when shopping online. Treat demands for gift cards, wire transfers, cryptocurrency, cash, or payment-app transfers as high risk, especially when the seller contacted you unexpectedly or refuses normal checkout methods.

Never connect a crypto wallet and approve a transaction you do not understand. A wallet connection can authorize access to assets even when the page calls the action a free verification.

The padlock is not a character reference. HTTPS means the connection is encrypted. The FTC explicitly notes that scammers use encrypted sites too. Require HTTPS, but do not confuse it with proof that the business behind the site is legitimate.

Leave immediately when you see these combinations

New domain + impossible discountA brand-new store claims exclusive stock at a fraction of the normal market price.
Urgency + irreversible paymentA timer or threat pushes you toward crypto, wire, gift card, or payment-app transfer.
Support message + remote accessA supposed fraud or tech-support agent wants control of your phone or computer.
Investment dashboard + withdrawal feeYour balance rises on screen, but every withdrawal requires a new tax, insurance, or unlock payment.
Copied identity + different domainThe page looks like a known company, while the actual registered domain belongs to something else.
No address + no usable refund pathThe seller gives you no realistic way to identify it or recover money.

What to do if you already entered information

If you entered a password, change it immediately on the real site and anywhere else you reused it. Secure the associated email account and enable multi-factor authentication. If you entered card or bank information, call the institution using the number on the card, official app, or statement.

If you paid, follow our first 30 minutes after a scam checklist. If you shared identity information, use IdentityTheft.gov and consider a free credit freeze with all three bureaus.

Know the next fake site pattern

Get one weekly scam alert with the setup, the red flags, and the action to take.

Free. Double opt-in. One-click unsubscribe.

Frequently asked questions

Does HTTPS mean a website is legitimate?

No. HTTPS encrypts data between your browser and the site, but scammers can also obtain certificates. Treat it as a basic requirement, not proof that the business is honest.

How can I check when a website was created?

Use ICANN Lookup to view available registration data. A domain registered very recently can be a warning sign when a site claims a long history, but age alone does not prove legitimacy.

What is the safest way to pay on an unfamiliar website?

A credit card generally offers stronger dispute rights than gift cards, wire transfers, cryptocurrency, or payment apps. Never use a payment method solely because an unexpected seller demands it.