Security & Privacy
How to Spot a Fake Online Store Before You Pay
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
Security & Privacy
A reassuring, jargon-free guide to spotting fake online stores, covering the warning signs in prices, contact details, payment options, and reviews.
A fake online store almost always fails at least one of five checks: an impossibly low price, a domain registered weeks ago, no verifiable business identity, a demand for an irreversible payment, and a total absence of independent reviews. You can run all five in roughly three minutes, before you type a single digit of your card number, and most scam sites collapse under the first two.
Scam sites can look flawless because the storefront is usually a stolen Shopify or WooCommerce template with real product photos lifted from the genuine brand. The design tells you almost nothing. The domain's history tells you a lot.
Type the store's domain into ICANN Lookup (lookup.icann.org) or who.is and read the "Creation Date." A retailer advertising premium electronics on a domain registered 18 days ago is the single most reliable red flag there is. Legitimate shops accumulate a registration history measured in years; disposable scam domains are spun up, run for a few weeks of ad spend, and abandoned before the chargebacks land. If the WHOIS record is hidden behind a privacy service and the site is new and pushing steep discounts, treat that combination as a warning rather than a coincidence.
Look closely at the exact spelling. Scammers register look-alikes using cheap TLDs (.shop, .top, .buzz, .store) or homoglyph tricks such as "adidaas", "nike-outlet-sale", or a Cyrillic "а" that renders identically to the Latin one. If you arrived from a Facebook or Instagram ad, do not trust the display name; hover the link or check the address bar. The real brand almost never sells flagship gear from a hyphen-stuffed subdomain like "official-clearance-nike.shop".
A padlock in the address bar only means the connection is encrypted, not that the seller is honest. Anyone can get a free HTTPS certificate from Let's Encrypt in minutes, so the padlock protects your data in transit and says nothing about who receives it. Verify the human beings behind the store instead.
Open the "Contact Us" and "About" pages and look for a physical address, a phone number, and a company name. Then check them:
Read the returns and refund pages too. Genuine merchants spell out a clear window (commonly 14 or 30 days) and a return address. Fakes either omit these pages, paste boilerplate that names a different company, or list a return address in a country that contradicts their "local warehouse" claims, the classic dropship tell.
Right-click the main product photo and use Google Lens or TinEye to search for it. If the identical image appears on AliExpress, the real manufacturer's site, or hundreds of other stores, you are likely looking at recycled stock imagery wrapped around an inflated or fake listing. This trick alone exposes a large share of dropship-scam and counterfeit shops in seconds.
The most common lure is a price that switches off your caution. Compare the exact item on two or three established retailers to establish the going rate, then judge the gap. A genuine seasonal sale rarely exceeds 30 to 50 percent off; a brand-new PlayStation, GPU, or designer bag at 80 to 90 percent below everyone else is not a deal, it is bait. Ignore countdown timers and "only 1 left" banners, they are scripted urgency that resets when you refresh the page, engineered to stop you comparing.
Your payment method is your safety net, so this is the check that actually gets your money back if everything else fails.
If a checkout steers you toward a bank/wire transfer, Zelle, Venmo, Cash App, cryptocurrency, or store gift cards, close the tab. Scammers prefer these precisely because they are effectively final; once sent, there is no chargeback mechanism to claw the money back. A legitimate store will always offer a normal card or PayPal Goods and Services option, and a real checkout typically hands you off to a recognizable processor such as Stripe, Shopify Payments, or PayPal rather than a plain form that just emails your card details somewhere.
Reviews displayed on the store's own site can be invented or cherry-picked, so search away from the site. Google the shop's name plus "review", "scam", or "legit", and check ScamAdviser and Trustpilot.
Most people check for the padlock, see HTTPS, and stop. That is the one signal scammers most easily fake, and relying on it is exactly how careful shoppers still get caught. The padlock validates the tunnel, never the merchant. Judge the seller by domain age, a verifiable identity, a reversible payment method, and independent reviews instead.
No. HTTPS only encrypts the connection between your browser and the site, and free certificates from providers like Let's Encrypt take minutes to obtain. A scam site can display a perfect padlock. Use it to confirm your data is not being intercepted, then verify the seller separately.
Contact your card issuer or PayPal immediately and open a dispute or chargeback, ideally the same day. Keep every order confirmation, email, and screenshot as evidence. Then report the site to your national consumer body, such as the FTC at reportfraud.ftc.gov in the US or Action Fraud in the UK.
Enter the domain at lookup.icann.org or who.is and read the "Creation Date" field. A domain only days or weeks old, paired with heavy discounting and paid social ads, is a strong warning sign. Established retailers almost always show registration dates going back years.
Not automatically; paid ads are not vetted for honesty. Click the three dots on the ad and use "Page transparency" to see when the page was created and where its admins are based. A page opened last month, run from an unrelated country, selling luxury goods at a fraction of retail, deserves every check above before you buy.
Keep reading
A calm, jargon-free guide to protecting your privacy on your phone, covering app permissions, location sharing, lock screens, and trimming back data tracking.
A reassuring, jargon-free guide to reducing your personal data online, covering data brokers, old accounts, search results, and lasting privacy habits.