A scam website can have a polished design, a familiar logo, and a padlock in the address bar. Those details don't establish who runs the site.
Before entering a password, payment detail, Social Security number, or one-time code, pause. Check the controlling domain, open the business through an official app or bookmark, and confirm its contact details somewhere independent. If the page uses urgency, asks for an unusual payment method, or wants information unrelated to the transaction, close it.
No single warning proves that a site is fraudulent. A combination of mismatched details is a good reason not to proceed.
22 red flags on scam websites
Use these signs as a stop-and-check list. One minor problem may have an innocent explanation, especially for a small business. Several problems together deserve caution.
- An unexpected link brought you there. The message may claim to be from your bank, a delivery company, a government agency, an employer, or a retailer.
- The domain is misspelled or uses a lookalike character. Watch for an extra letter, a number replacing a letter, or an added hyphen.
- A misleading subdomain makes the address look official.
bank-login.example.comis controlled byexample.com, not by a bank, unlessexample.comis the bank's actual domain. - The address contains an
@sign or several unexplained redirects. These features can obscure the destination that receives your information. - The site uses HTTP instead of HTTPS. Information sent over an HTTP connection may be more vulnerable to interception.
- The padlock is being used as the only proof of safety. HTTPS helps protect the connection; it doesn't establish that the site operator is honest.
- A login page appears after you click an unsolicited message. Phishing pages commonly use this setup to collect usernames and passwords.
- The page unexpectedly requests a one-time code or account-recovery information. Don't enter a security code into a page reached through a suspicious message.
- The branding doesn't agree with itself. Logos, colors, fonts, support addresses, or product names may vary from one part of the site to another.
- The wording is awkward or full of spelling errors. One typo means little, but repeated errors in payment or account instructions are concerning.
- Product descriptions or photos appear copied. Search an unusual phrase or image to see whether it belongs to another retailer.
- Testimonials are vague and repetitive. Generic praise without dates, details, or verifiable customers is weak evidence.
- The business has no independently verifiable contact information. A contact form alone makes it difficult to confirm who operates the site.
- The return, privacy, shipping, or terms pages are missing or name another company. Copied policy text can indicate a hastily assembled store.
- A new domain is impersonating an established brand. A recently created domain isn't automatically fraudulent, but it calls for extra verification.
- A countdown timer or low-stock message pushes you to act immediately. Pressure is meant to leave less time for checking.
- The price is far below normal, or the site promises guaranteed income. Unrealistic discounts, effortless jobs, and guaranteed investment returns are high-risk claims.
- The total changes at checkout. Shipping, membership charges, subscriptions, or unexplained fees appear only at the last step.
- The seller insists on gift cards, cryptocurrency, a wire transfer, or a peer-to-peer payment. These payment methods can be difficult to reverse.
- The site asks for more information than the transaction requires. An ordinary retail purchase shouldn't require your bank login or Social Security number.
- "Verification" requires a download, browser extension, remote access, a command, or notification permission. Close the page instead of following the instruction.
- Support avoids basic questions or tells you to keep the transaction secret. Secrecy and evasive answers are strong social-engineering signals.
Check the web address before the page design
Scammers can copy a company's colors, photographs, and layout. Start with the address bar instead.
Look for the controlling domain, not merely the first familiar word:
https://store.example.com/accountis controlled byexample.com.https://example.com.bad-domain.test/accountis controlled bybad-domain.test.https://[email protected]/accountis also controlled bybad-domain.test.
On a computer, hover over a link to preview its destination. On a phone, use the link preview when available. For a bank, government agency, or major retailer, the safer route is to open the official app, use a saved bookmark, or type an address you already know rather than following a link in a message.
A .com, .org, .net, or country-code ending doesn't prove that a site is genuine. Scammers and legitimate organizations use many domain endings. Exact spelling and independent confirmation matter more than the extension.
A domain's registration date can add context. A site created recently while claiming to be a long-established company deserves scrutiny. That date isn't a verdict: a legitimate business can have a new domain, and an old domain can be compromised or repurposed.
Recognize phishing and fake login pages
Phishing sites impersonate trusted organizations to collect passwords, payment details, or identity information. The FTC's phishing guidance describes messages that pressure people to click, confirm information, make a payment, or open an attachment. CISA's social-engineering guidance explains how attackers use trust and urgency to obtain information.
Before signing in, check the basics:
- Did you start at the service's official app or a trusted bookmark?
- Does the controlling domain exactly match the organization?
- Is the page asking for information that fits the action?
- Did an email, text, advertisement, or social media post send you there?
- Does your password manager recognize the domain?
A cloned login page may have perfect branding, so a lack of spelling errors doesn't make it safe. Don't enter credentials merely to test the page. If you already entered a password, change it through the real service and update any other account where you reused it.
Never give a one-time verification code to someone who contacted you unexpectedly. A legitimate service may use codes during a normal login, but a code request after a suspicious message can help an attacker take over your account.
Treat pressure and unusual payment requests as stop signs
Scam pages often create a short decision window: "claim now," "only two left," or "your account closes today." A real retailer may run a sale, but a timer shouldn't replace normal verification.
Compare the offer elsewhere using the exact product name, model number, or service terms. Before paying, confirm:
- the complete price, including shipping and taxes
- whether a trial becomes a recurring subscription
- the seller's identity and return process
- the delivery estimate
- the currency and billing descriptor
- whether checkout remains on the expected domain
Be particularly careful if the seller insists on a gift card, cryptocurrency, wire transfer, or peer-to-peer payment. The payment method alone doesn't prove a scam, but insisting on a hard-to-reverse method removes useful protection. A credit card may offer a billing-dispute process, but it doesn't guarantee a refund. Ask the card issuer or payment provider what options apply before sending money.
The FDIC's online shopping guidance warns that suspicious links can lead to sites that collect card or personal information and may also download malware. Don't open unexpected attachments described as coupons, rebates, invoices, or payment forms.
Verify the business, reviews, and policies
An "About us" page is a claim made by the website. Confirm important details somewhere else.
Search for the business name, phone number, physical address, and unusual wording from its policies. Look for independent sources that show a consistent company identity. A search ranking, paid advertisement, social media follower count, or badge displayed on the site isn't proof of legitimacy.
Reviews can help, but they need checking too:
- Look for specific experiences rather than repeated generic praise.
- Check whether the dates and writing styles look natural.
- Compare reviews on more than one independent platform.
- Be cautious when every review is five stars or complaints mention non-delivery, unexpected charges, or unreachable support.
- Treat reviews hosted only on the seller's site as marketing, not verification.
Stock photos, professional design, and a small number of reviews don't prove fraud. They simply provide less evidence than a business history you can confirm independently.
Read the privacy, refund, shipping, subscription, and terms pages before checkout. Look for a different company name, currency, broken links, copied wording, or an address that cannot be verified. A detailed policy still doesn't guarantee that the seller will honor it, but it shows what the site is promising and gives you records to keep.
Extra checks for investment and trading websites
Investment sites warrant a higher level of verification because a convincing page can lead to a large transfer. Before depositing money, follow the CFTC's fraud-recovery and prevention guidance. Verify the platform's registration and disciplinary history with the appropriate official regulator, such as the CFTC, NFA, SEC, FINRA, or a state regulator.
A regulator logo, "guaranteed return" statement, or online testimonial is not proof that a platform is registered.
A quick verification routine
When a site feels questionable, take these steps in order:
- Stop using the page. Don't enter more information, download files, or reply to the message.
- Reach the organization through a trusted route. Use its official app, a bookmark, or an address you type independently.
- Inspect the domain. Check spelling, subdomains, redirects, and the domain after any
@sign. - Confirm the business elsewhere. Use contact details you find independently, not the phone number or email supplied by the suspicious page.
- Review the transaction. Check for recurring billing, shipping costs, return terms, and the final total before entering payment information.
- Choose the payment method carefully. Prefer a method that creates clear records and has a provider you can contact. Don't assume a dispute will automatically succeed.
- Leave if questions remain. Missing a deal is less costly than losing control of an account or sending money that can't be recovered.
If you clicked, submitted information, or paid
Act quickly. Use contact details from your card, bank statement, official app, or a trusted bookmark - not the suspicious website.
- You only opened the page: Close it without downloading anything. Update your operating system, browser, and security software. If you downloaded a file, don't open it; run a security check with trusted software.
- You entered a password: Go directly to the real service, change the password, change reused passwords elsewhere, and enable multi-factor authentication. Contact the service if you can't regain control.
- You entered card details or see a charge: Call the card issuer using the number on the card or statement. Report the transaction, ask which dispute or replacement steps apply, and keep the confirmation number.
- You used a debit card, bank transfer, wire, or peer-to-peer service: Contact the bank or provider immediately. Ask about its fraud, cancellation, or reversal process. Options depend on the payment method and how quickly you report the transaction.
- You shared identity information: Use the FTC's consumer scam resources promptly and monitor your accounts for unfamiliar activity.
- You received a phishing email or text: For U.S. consumers, the FTC advises forwarding phishing emails to
[email protected], forwarding suspicious texts toSPAMat7726, and reporting the attempt through ReportFraud.ftc.gov.
Keep the website address, screenshots, emails, receipts, order numbers, payment records, transaction IDs, and dates. Don't include passwords, full account numbers, or other unnecessary sensitive information in a report.
An FTC report helps document and route information about scams. It isn't a payment dispute or reversal request. When money or account access is involved, contact the payment provider first.
What does not prove a website is legitimate?
These features can appear on both real and fraudulent sites:
- an HTTPS connection or padlock
- an attractive layout and professional photographs
- a high search ranking or paid advertisement
- social media profiles and follower counts
- testimonials displayed on the site
- an old domain registration
- a familiar payment logo
- a customer service chatbot
Stronger evidence comes from several checks agreeing with one another: the exact domain matches the organization, contact details check out, policies identify the same business, the offer is realistic, and the payment process is clear. Even then, don't send information the transaction doesn't require.
Common questions
Is an HTTPS website safe?
Not necessarily. HTTPS helps encrypt the connection between your browser and the site, but it doesn't verify who operates the site or whether the offer is honest. Check the domain and business independently.
Is a new domain automatically a scam?
No. New businesses create new domains. A recent registration becomes more concerning when the site impersonates an established brand, uses copied content, or combines the new domain with pressure and unusual payment demands.
Can online reviews prove that a store is genuine?
No. Reviews can be copied, selectively displayed, or fabricated. Use them as one clue, then verify the seller through independent business information and a payment method with a clear support process.
Will reporting a scam get my money back?
Reporting is useful, but it doesn't automatically reverse a payment. Contact the card issuer, bank, wire service, or payment app immediately and ask which recovery or dispute process applies to that transaction.
If you're still looking at a questionable page, close it without entering test information. Reopen the business through its official app, a trusted bookmark, or an address you type yourself.