Before you type a password, a card number, or your home address into any website, spend a few seconds checking who is actually on the other side. This quick checklist will not catch every scam, but it will stop most of the obvious ones before you lose money or your identity.
1. Check the URL spelling for lookalike domains
Typosquatting is cheap and extremely common. Scammers register addresses that look like a real brand at a glance: amozon.com, paypa1.com, or a brand name glued to an unrelated word like "secure" or "help." Read the address bar letter by letter before you proceed. Look for extra letters, swapped letters, or a trusted brand appearing where it does not belong. If the domain does not match the address you intended to visit, treat the site as a fake shopping site until it proves otherwise.
2. Check the padlock and what HTTPS does and does not prove
Now look at the padlock icon in the address bar. It means the connection between your browser and the server is encrypted, which is good — that is all it means. A padlock does not tell you that the business is honest, that the product exists, or that you will get what you pay for. Anyone can buy a certificate for a fake domain within minutes. If you want the details, read our guide to what the padlock icon actually means. A private connection to a scammer is still a connection to a scammer.
3. Run Google's Safe Browsing check
Google scans billions of pages daily for phishing and malware. You can check one page in seconds. Open the Google Transparency Report's Safe Browsing site status page, paste the full URL, and read the result. If the report flags the site as unsafe or deceptive, do not continue. A clean result is not a guarantee that a site is trustworthy, but a warning is a definite reason to close the tab.
4. Look for a real contact page and business information
A genuine business wants you to be able to find it. Click through to the contact page and look for a physical address, a working phone number, or at least a real support email. Scam sites often hide behind a web form that goes nowhere or a mailto link no one answers. Check the about page too. If the company description is vague, if the address points to a mail forwarding service, or if there is no way to reach a human, that is a red flag worth respecting.
5. Check how long the domain has existed
Use a WHOIS lookup to see when a domain was registered and by whom. Most legitimate businesses keep their domains for years, sometimes decades. A store that was registered two weeks ago and is already selling expensive goods deserves deep suspicion. Scammers cycle through cheap new domains because they burn through them quickly. A recent creation date is not proof of a scam, but it is a strong reason to slow down and run the rest of this checklist.
Trust the evidence you can verify, not the badges the site shows you.
6. Watch for extreme discounts, timers, and odd payment methods
Scammers create urgency on purpose. Watch for discounts of 80 percent or more on everything, countdown timers that quietly reset after they hit zero, and "only two left" messages that never change. These are pressure tactics, not bargains. The clearest tell is how the site wants to be paid. Gift cards, cryptocurrency, and wire transfers are almost impossible to reverse, which is exactly why scammers ask for them. A legitimate store accepts a card or a trusted payment service. If a site insists on an irreversible payment method, stop.
7. Check reviews from a separate search
Testimonials on the site prove nothing. Anyone can write those, and scammers do, by the dozens. Instead, open a new tab and search for the site's name plus words like "review," "scam," or "complaints." Read what real people say on forums, social media, and consumer protection sites you already trust. A pattern of reports about goods that never arrived or refunds that never happened is exactly the warning you were hoping to find before checkout.
8. Which safety checks are actually myths
Some habits people treat as safety checks do not work. A padlock does not make a site trustworthy, as covered above. A long and professional looking URL is not proof of legitimacy, because scammers use lookalikes. Trust badges, "secure checkout" logos, and seals from companies you have never heard of are easy to copy and prove nothing. Even a website that ranks on the first page of results can be a paid ad for a scam. Treat these signals as decoration, and rely on the concrete checks above instead. When in doubt, our Scam Guard tool can give you a second opinion before you commit to an unfamiliar store.
Quick answers
Does a padlock icon mean a website is safe? No. It only means the connection is encrypted. Any site, including a scam, can get HTTPS. Treat the padlock as a basic requirement, never as proof of trust.
Can I trust a website if Google Safe Browsing does not flag it? A clean report is good news, but it is not a guarantee. New scam sites are often flagged only after the first victims report them. Use the tool, then run the rest of the checklist.
What is the single biggest sign of a fake shopping site? The payment method. If a store only accepts gift cards, cryptocurrency, or wire transfer, it is designed so you cannot get your money back.
What should I do if I already entered my payment details on a suspicious site? Contact your bank or card issuer immediately and ask to block the card and dispute any charges. Change the password on any account you reused, and report the site to the FTC.
Sources and further reading
- Google Transparency Report: Safe Browsing site status
- Google Chrome help: Safe Browsing
- FTC: Recognize and avoid phishing scams
Written by Hassan Arshad, founder of UsefulOrbit. Last updated August 31, 2026.