How to tell if a website is legit.
A fake website can copy a real logo, clone a storefront, buy convincing reviews, and obtain HTTPS in an afternoon. The question is not whether one part looks legitimate. The question is whether the site's identity, history, policies, reputation, and payment behavior tell the same story.
Use the checks below before you enter a password, card number, identity document, bank login, or crypto wallet. If the site is creating urgency, that is a reason to slow down, not a reason to skip a step.
The nine checks
1. Read the exact domain, one character at a time
Ignore the logo and page title. Read the address bar. Scammers use misspellings, extra words, unexpected subdomains, and look-alike characters. In bank.example-login.com, the registered domain is example-login.com, not bank.
If a message claims to be from a bank, retailer, government agency, or delivery company, do not use its link. Open the official app or type the known address yourself.
2. Ask how you arrived
An unexpected text, social ad, direct message, QR code, or sponsored search result deserves extra scrutiny. A paid search placement is advertising, not verification. The FTC advises contacting a company through information you looked up independently when a request is unexpected.
3. Check the domain's registration history
Use ICANN Lookup to view available domain registration data. Compare the creation date with the story on the site. A store claiming "20 years in business" on a domain registered last week has a credibility problem.
Registration privacy is common and is not proof of fraud. Old domains can be hacked or sold. Domain age is one clue that must agree with the rest of the evidence.
4. Verify the business outside its own page
Check the address on an independent map, call a number found through a trusted source, and search the legal business name in the relevant government registry. A contact page containing only a form, a free email address, or a messaging-app handle gives you little recourse.
For a regulated financial company, verify registration with the actual regulator. A regulator logo in the footer is just an image until the regulator's database confirms the business.
5. Read the return, shipping, privacy, and dispute policies
Look for specific timeframes, costs, exclusions, a return address, and a working contact method. Search a distinctive sentence from the policy in quotation marks. Scam networks often paste the same policy across unrelated stores and forget to replace another company's name.
A missing policy is bad. A policy that says every sale is final, gives no return address, or requires expensive international shipping can make a technically delivered product almost impossible to return.
6. Test the offer against reality
Compare the price with established sellers. A scarce product at 80% below every legitimate market price is not a secret wholesale connection. It is often bait. Reverse-search product photos when an expensive item appears to use catalog images or pictures copied from another listing.
7. Search for complaints without trusting the star average
Search the domain and company name with terms such as scam, complaint, refund, and review. Read dates and details across multiple sources. The FTC warns that reviews and ratings can be fake or misleading.
Do not treat the absence of complaints as proof. A disposable site may be too new to have victims posting under the current name.
8. Check for known security warnings
Use the Google Safe Browsing site status tool and pay attention to browser warnings. A clean result means the site was not identified by that system at that moment; it does not certify the business, product, or seller.
Do not download an app, browser extension, security update, or remote-access tool because an unfamiliar page tells you to.
9. Judge the payment method
The FTC says paying by credit card generally provides the best protection when shopping online. Treat demands for gift cards, wire transfers, cryptocurrency, cash, or payment-app transfers as high risk, especially when the seller contacted you unexpectedly or refuses normal checkout methods.
Never connect a crypto wallet and approve a transaction you do not understand. A wallet connection can authorize access to assets even when the page calls the action a free verification.
Leave immediately when you see these combinations
What to do if you already entered information
If you entered a password, change it immediately on the real site and anywhere else you reused it. Secure the associated email account and enable multi-factor authentication. If you entered card or bank information, call the institution using the number on the card, official app, or statement.
If you paid, follow our first 30 minutes after a scam checklist. If you shared identity information, use IdentityTheft.gov and consider a free credit freeze with all three bureaus.
Know the next fake site pattern
Get one weekly scam alert with the setup, the red flags, and the action to take.
Free. Double opt-in. One-click unsubscribe.
Frequently asked questions
Does HTTPS mean a website is legitimate?
No. HTTPS encrypts data between your browser and the site, but scammers can also obtain certificates. Treat it as a basic requirement, not proof that the business is honest.
How can I check when a website was created?
Use ICANN Lookup to view available registration data. A domain registered very recently can be a warning sign when a site claims a long history, but age alone does not prove legitimacy.
What is the safest way to pay on an unfamiliar website?
A credit card generally offers stronger dispute rights than gift cards, wire transfers, cryptocurrency, or payment apps. Never use a payment method solely because an unexpected seller demands it.