Security & Privacy

How to Recognize a Fake Website: A Calm Guide

A friendly, jargon-free guide to spotting fake websites, covering the warning signs in links and pages, and the simple habits that keep you safe online.

A laptop screen showing a web browser address bar being inspected closely
Photograph via Unsplash

The fastest reliable check on any website is the registrable domain: the single label immediately to the left of .com, .co.uk, or .org, read right-to-left from the last dot before the first single slash. Everything else on the page can be faked in minutes, but a scammer can never own the real domain, so that one string is where the truth lives.

Read the Domain the Way an Attacker Hopes You Won't#

Take a URL like paypal.com.secure-login-verify.ru/account. Most people scan left to right, see "paypal.com" first, and relax. But paypal.com here is just a subdomain; the actual owner is secure-login-verify.ru. The rule that never fails: find the last dot before the first single slash, then read backward. The label directly before the public suffix (.ru in this case) is the true owner.

The three tricks that fool almost everyone#

  • Typosquatting: paypa1.com (a digit 1 for an l), arnazon.com (r+n reads as m at small sizes), microsoft-support.net. These rely on you not looking character by character.
  • Extra words: apple-verify.com, netflix-billing.net, hmrc-refund-gov.co.uk. Real companies almost never hang your login on a bolt-on word like -secure, -verify, or -login.
  • Homograph (IDN) attacks: a domain that uses a Cyrillic "а" or Greek "ο" in place of the Latin letter, producing something that looks identical to apple.com on screen. Modern browsers defend against this by showing the raw Punycode form instead, so if the address bar reads xn--80ak6aa92e.com where you expected a normal word, that is a genuine red flag, not a glitch.

On a phone, press and hold a link to preview the destination before tapping. On a desktop, hover and read the real URL in the bottom-left status bar. If the preview and the visible link text disagree, stop.

Why HTTPS and the Padlock Prove Almost Nothing#

Here is the single most out-of-date piece of safety advice still in circulation: "look for the padlock." The padlock and the https:// prefix mean the connection is encrypted using TLS, so data in transit can't be casually read. That protects the pipe, not the person at the other end.

The reason this matters today is that certificates became free and instant. Services like Let's Encrypt issue a Domain Validated (DV) certificate to anyone who can prove they control a domain, in under a minute, at no cost. A criminal who registers netflix-billing.net gets a valid padlock for it just as easily as Netflix does for the real one. As a result, the large majority of phishing pages now run on HTTPS. The padlock has become table stakes, not a trust signal.

There used to be a stronger tier — Extended Validation (EV) certificates that printed the company's legal name in green in the address bar. Browsers removed that display years ago (Chrome dropped it in version 77, back in 2019), because studies showed it fooled more people than it helped. So the padlock's absence is a real warning, especially on any page asking for a password or card number, but its presence tells you only that the connection is private.

Check the Signals a Scammer Can't Cheaply Fake#

Encryption is easy to buy. History and reputation are not. These are the checks that actually separate a real business from a two-week-old fake.

Domain age#

Most scam storefronts are days or weeks old. Look up the registration date with a free WHOIS tool such as whois.com or ICANN Lookup, or run the URL through urlscan.io. A "20-year-old established retailer" whose domain was registered last month is lying about one of those facts. Anything under a few months old that is asking for payment deserves heavy skepticism.

A reputation check on the domain itself#

Paste the address into Google Safe Browsing's transparency report or VirusTotal, both free, and see whether security vendors already flag it. If your browser throws a full-page red "Deceptive site ahead" warning, that is Safe Browsing doing exactly this — do not click through it.

How they want to be paid#

This is the clearest tell of all for shopping scams. Legitimate merchants accept credit cards, which carry chargeback rights (in the UK, Section 75 of the Consumer Credit Act covers purchases roughly £100–£30,000; in the US, the Fair Credit Billing Act backs card disputes). Fraudulent sites steer you toward irreversible methods: bank transfer, wire, cryptocurrency, gift cards, or peer-to-peer apps like Zelle and Cash App. If checkout suddenly insists on "bank transfer only for this deal," walk away.

Borrowed content#

Run a reverse image search on the product photos and the "team" headshots. Scam sites routinely lift images from the real brand or from stock libraries, and increasingly generate the "About Us" text with AI, so it reads fluent but strangely generic. Genuine contact details — a working phone number, a real postal address, a company registration number — are the things fakes most often omit or fabricate.

The Habit That Beats Nearly Every Fake#

The highest-value habit is refusing to reach a sensitive site by clicking a link at all. When an email or text pushes you to "verify your account," don't tap it. Open a fresh tab and type the address yourself, or use a bookmark you saved when you first signed up. This single move defeats most phishing outright, because the fake page only works if you arrive through the attacker's link.

Two tools make you structurally harder to phish:

  1. A password manager (Bitwarden, 1Password, or your browser's built-in one) binds each saved login to an exact domain. On a look-alike like paypa1.com, it simply won't offer to autofill — and that silence is a warning your eyes might have missed.
  2. Passkeys / WebAuthn, now offered by Google, Apple, Microsoft, and many banks, are phishing-resistant by design: the credential is cryptographically tied to the real domain and cannot be handed to an impostor site even if you try.

Common mistakes people make#

  • Trusting the padlock or HTTPS as proof of honesty. It proves neither.
  • Reading the domain left-to-right and stopping at the first familiar word.
  • Trusting the top search result. Scammers buy search ads on brand names (malvertising), so the sponsored link above the real one can be the fake. Scroll to the genuine organic result or type the URL.
  • Assuming "it looks professional, so it's real." AI cloning has made a polished, pixel-perfect copy cheap. Appearance is now the weakest signal, not the strongest.

If You've Already Entered Details#

Act promptly and without panic. If you typed a password, change it on the real site immediately, and change it anywhere you reused it — then turn on two-factor authentication there. If you entered card or bank details, call the number on the back of your card and ask them to watch the account or reissue the card; card payments can often be disputed. Report the page to your browser and to the relevant fraud body, and watch your statements for the next few weeks.

FAQ#

Is a website safe if it has HTTPS and a padlock?#

No. HTTPS only encrypts the connection, and free certificates mean scam sites get a padlock as easily as real ones do. Treat a missing padlock as a warning, but never treat its presence as proof the business is genuine. Judge the domain name and the site's history instead.

How can I tell how old a domain is?#

Use a free WHOIS lookup like whois.com or ICANN Lookup, or paste the URL into urlscan.io, and read the registration date. A brand claiming decades of history on a domain that was created weeks ago is a strong sign of a scam.

Are online reviews and star ratings reliable?#

Only cautiously. Fake sites plant glowing reviews and can display any Trustpilot-style widget they like. Search the company name alongside the word "scam" on independent forums, and be suspicious of a flood of five-star reviews all posted within the same few days.

What is the safest way to reach my bank's website?#

Type the address yourself or use a bookmark you saved earlier, and never follow a login link from an email or text. Better still, use the bank's official app, and turn on passkeys or two-factor authentication so a stolen password alone can't unlock your account.

Theo Vance
Written by
Theo Vance

Theo writes about online safety the way a good friend would — clearly, calmly, and without trying to scare you. He's interested in the simple habits that stop most problems, and he thinks staying private online is a skill anyone can learn.

More from Theo