Security & Privacy
How to Recognize a Fake Website: A Calm Guide
A friendly, jargon-free guide to spotting fake websites, covering the warning signs in links and pages, and the simple habits that keep you safe online.
Security & Privacy
A friendly, jargon-free guide to spotting fake websites, covering the warning signs in links and pages, and the simple habits that keep you safe online.
The fastest reliable check on any website is the registrable domain: the single label immediately to the left of .com, .co.uk, or .org, read right-to-left from the last dot before the first single slash. Everything else on the page can be faked in minutes, but a scammer can never own the real domain, so that one string is where the truth lives.
Take a URL like paypal.com.secure-login-verify.ru/account. Most people scan left to right, see "paypal.com" first, and relax. But paypal.com here is just a subdomain; the actual owner is secure-login-verify.ru. The rule that never fails: find the last dot before the first single slash, then read backward. The label directly before the public suffix (.ru in this case) is the true owner.
paypa1.com (a digit 1 for an l), arnazon.com (r+n reads as m at small sizes), microsoft-support.net. These rely on you not looking character by character.apple-verify.com, netflix-billing.net, hmrc-refund-gov.co.uk. Real companies almost never hang your login on a bolt-on word like -secure, -verify, or -login.apple.com on screen. Modern browsers defend against this by showing the raw Punycode form instead, so if the address bar reads xn--80ak6aa92e.com where you expected a normal word, that is a genuine red flag, not a glitch.On a phone, press and hold a link to preview the destination before tapping. On a desktop, hover and read the real URL in the bottom-left status bar. If the preview and the visible link text disagree, stop.
Here is the single most out-of-date piece of safety advice still in circulation: "look for the padlock." The padlock and the https:// prefix mean the connection is encrypted using TLS, so data in transit can't be casually read. That protects the pipe, not the person at the other end.
The reason this matters today is that certificates became free and instant. Services like Let's Encrypt issue a Domain Validated (DV) certificate to anyone who can prove they control a domain, in under a minute, at no cost. A criminal who registers netflix-billing.net gets a valid padlock for it just as easily as Netflix does for the real one. As a result, the large majority of phishing pages now run on HTTPS. The padlock has become table stakes, not a trust signal.
There used to be a stronger tier — Extended Validation (EV) certificates that printed the company's legal name in green in the address bar. Browsers removed that display years ago (Chrome dropped it in version 77, back in 2019), because studies showed it fooled more people than it helped. So the padlock's absence is a real warning, especially on any page asking for a password or card number, but its presence tells you only that the connection is private.
Encryption is easy to buy. History and reputation are not. These are the checks that actually separate a real business from a two-week-old fake.
Most scam storefronts are days or weeks old. Look up the registration date with a free WHOIS tool such as whois.com or ICANN Lookup, or run the URL through urlscan.io. A "20-year-old established retailer" whose domain was registered last month is lying about one of those facts. Anything under a few months old that is asking for payment deserves heavy skepticism.
Paste the address into Google Safe Browsing's transparency report or VirusTotal, both free, and see whether security vendors already flag it. If your browser throws a full-page red "Deceptive site ahead" warning, that is Safe Browsing doing exactly this — do not click through it.
This is the clearest tell of all for shopping scams. Legitimate merchants accept credit cards, which carry chargeback rights (in the UK, Section 75 of the Consumer Credit Act covers purchases roughly £100–£30,000; in the US, the Fair Credit Billing Act backs card disputes). Fraudulent sites steer you toward irreversible methods: bank transfer, wire, cryptocurrency, gift cards, or peer-to-peer apps like Zelle and Cash App. If checkout suddenly insists on "bank transfer only for this deal," walk away.
Run a reverse image search on the product photos and the "team" headshots. Scam sites routinely lift images from the real brand or from stock libraries, and increasingly generate the "About Us" text with AI, so it reads fluent but strangely generic. Genuine contact details — a working phone number, a real postal address, a company registration number — are the things fakes most often omit or fabricate.
The highest-value habit is refusing to reach a sensitive site by clicking a link at all. When an email or text pushes you to "verify your account," don't tap it. Open a fresh tab and type the address yourself, or use a bookmark you saved when you first signed up. This single move defeats most phishing outright, because the fake page only works if you arrive through the attacker's link.
Two tools make you structurally harder to phish:
paypa1.com, it simply won't offer to autofill — and that silence is a warning your eyes might have missed.Act promptly and without panic. If you typed a password, change it on the real site immediately, and change it anywhere you reused it — then turn on two-factor authentication there. If you entered card or bank details, call the number on the back of your card and ask them to watch the account or reissue the card; card payments can often be disputed. Report the page to your browser and to the relevant fraud body, and watch your statements for the next few weeks.
No. HTTPS only encrypts the connection, and free certificates mean scam sites get a padlock as easily as real ones do. Treat a missing padlock as a warning, but never treat its presence as proof the business is genuine. Judge the domain name and the site's history instead.
Use a free WHOIS lookup like whois.com or ICANN Lookup, or paste the URL into urlscan.io, and read the registration date. A brand claiming decades of history on a domain that was created weeks ago is a strong sign of a scam.
Only cautiously. Fake sites plant glowing reviews and can display any Trustpilot-style widget they like. Search the company name alongside the word "scam" on independent forums, and be suspicious of a flood of five-star reviews all posted within the same few days.
Type the address yourself or use a bookmark you saved earlier, and never follow a login link from an email or text. Better still, use the bank's official app, and turn on passkeys or two-factor authentication so a stolen password alone can't unlock your account.
Keep reading
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.