A scam website can have a polished design, a familiar logo, and a padlock in the address bar. Those details don't establish who runs the site.

Before entering a password, payment detail, Social Security number, or one-time code, pause. Check the controlling domain, open the business through an official app or bookmark, and confirm its contact details somewhere independent. If the page uses urgency, asks for an unusual payment method, or wants information unrelated to the transaction, close it.

No single warning proves that a site is fraudulent. A combination of mismatched details is a good reason not to proceed.

22 red flags on scam websites

Use these signs as a stop-and-check list. One minor problem may have an innocent explanation, especially for a small business. Several problems together deserve caution.

  1. An unexpected link brought you there. The message may claim to be from your bank, a delivery company, a government agency, an employer, or a retailer.
  2. The domain is misspelled or uses a lookalike character. Watch for an extra letter, a number replacing a letter, or an added hyphen.
  3. A misleading subdomain makes the address look official. bank-login.example.com is controlled by example.com, not by a bank, unless example.com is the bank's actual domain.
  4. The address contains an @ sign or several unexplained redirects. These features can obscure the destination that receives your information.
  5. The site uses HTTP instead of HTTPS. Information sent over an HTTP connection may be more vulnerable to interception.
  6. The padlock is being used as the only proof of safety. HTTPS helps protect the connection; it doesn't establish that the site operator is honest.
  7. A login page appears after you click an unsolicited message. Phishing pages commonly use this setup to collect usernames and passwords.
  8. The page unexpectedly requests a one-time code or account-recovery information. Don't enter a security code into a page reached through a suspicious message.
  9. The branding doesn't agree with itself. Logos, colors, fonts, support addresses, or product names may vary from one part of the site to another.
  10. The wording is awkward or full of spelling errors. One typo means little, but repeated errors in payment or account instructions are concerning.
  11. Product descriptions or photos appear copied. Search an unusual phrase or image to see whether it belongs to another retailer.
  12. Testimonials are vague and repetitive. Generic praise without dates, details, or verifiable customers is weak evidence.
  13. The business has no independently verifiable contact information. A contact form alone makes it difficult to confirm who operates the site.
  14. The return, privacy, shipping, or terms pages are missing or name another company. Copied policy text can indicate a hastily assembled store.
  15. A new domain is impersonating an established brand. A recently created domain isn't automatically fraudulent, but it calls for extra verification.
  16. A countdown timer or low-stock message pushes you to act immediately. Pressure is meant to leave less time for checking.
  17. The price is far below normal, or the site promises guaranteed income. Unrealistic discounts, effortless jobs, and guaranteed investment returns are high-risk claims.
  18. The total changes at checkout. Shipping, membership charges, subscriptions, or unexplained fees appear only at the last step.
  19. The seller insists on gift cards, cryptocurrency, a wire transfer, or a peer-to-peer payment. These payment methods can be difficult to reverse.
  20. The site asks for more information than the transaction requires. An ordinary retail purchase shouldn't require your bank login or Social Security number.
  21. "Verification" requires a download, browser extension, remote access, a command, or notification permission. Close the page instead of following the instruction.
  22. Support avoids basic questions or tells you to keep the transaction secret. Secrecy and evasive answers are strong social-engineering signals.

Check the web address before the page design

Scammers can copy a company's colors, photographs, and layout. Start with the address bar instead.

Look for the controlling domain, not merely the first familiar word:

On a computer, hover over a link to preview its destination. On a phone, use the link preview when available. For a bank, government agency, or major retailer, the safer route is to open the official app, use a saved bookmark, or type an address you already know rather than following a link in a message.

A .com, .org, .net, or country-code ending doesn't prove that a site is genuine. Scammers and legitimate organizations use many domain endings. Exact spelling and independent confirmation matter more than the extension.

A domain's registration date can add context. A site created recently while claiming to be a long-established company deserves scrutiny. That date isn't a verdict: a legitimate business can have a new domain, and an old domain can be compromised or repurposed.

Recognize phishing and fake login pages

Phishing sites impersonate trusted organizations to collect passwords, payment details, or identity information. The FTC's phishing guidance describes messages that pressure people to click, confirm information, make a payment, or open an attachment. CISA's social-engineering guidance explains how attackers use trust and urgency to obtain information.

Before signing in, check the basics:

A cloned login page may have perfect branding, so a lack of spelling errors doesn't make it safe. Don't enter credentials merely to test the page. If you already entered a password, change it through the real service and update any other account where you reused it.

Never give a one-time verification code to someone who contacted you unexpectedly. A legitimate service may use codes during a normal login, but a code request after a suspicious message can help an attacker take over your account.

Treat pressure and unusual payment requests as stop signs

Scam pages often create a short decision window: "claim now," "only two left," or "your account closes today." A real retailer may run a sale, but a timer shouldn't replace normal verification.

Compare the offer elsewhere using the exact product name, model number, or service terms. Before paying, confirm:

Be particularly careful if the seller insists on a gift card, cryptocurrency, wire transfer, or peer-to-peer payment. The payment method alone doesn't prove a scam, but insisting on a hard-to-reverse method removes useful protection. A credit card may offer a billing-dispute process, but it doesn't guarantee a refund. Ask the card issuer or payment provider what options apply before sending money.

The FDIC's online shopping guidance warns that suspicious links can lead to sites that collect card or personal information and may also download malware. Don't open unexpected attachments described as coupons, rebates, invoices, or payment forms.

Verify the business, reviews, and policies

An "About us" page is a claim made by the website. Confirm important details somewhere else.

Search for the business name, phone number, physical address, and unusual wording from its policies. Look for independent sources that show a consistent company identity. A search ranking, paid advertisement, social media follower count, or badge displayed on the site isn't proof of legitimacy.

Reviews can help, but they need checking too:

Stock photos, professional design, and a small number of reviews don't prove fraud. They simply provide less evidence than a business history you can confirm independently.

Read the privacy, refund, shipping, subscription, and terms pages before checkout. Look for a different company name, currency, broken links, copied wording, or an address that cannot be verified. A detailed policy still doesn't guarantee that the seller will honor it, but it shows what the site is promising and gives you records to keep.

Extra checks for investment and trading websites

Investment sites warrant a higher level of verification because a convincing page can lead to a large transfer. Before depositing money, follow the CFTC's fraud-recovery and prevention guidance. Verify the platform's registration and disciplinary history with the appropriate official regulator, such as the CFTC, NFA, SEC, FINRA, or a state regulator.

A regulator logo, "guaranteed return" statement, or online testimonial is not proof that a platform is registered.

A quick verification routine

When a site feels questionable, take these steps in order:

  1. Stop using the page. Don't enter more information, download files, or reply to the message.
  2. Reach the organization through a trusted route. Use its official app, a bookmark, or an address you type independently.
  3. Inspect the domain. Check spelling, subdomains, redirects, and the domain after any @ sign.
  4. Confirm the business elsewhere. Use contact details you find independently, not the phone number or email supplied by the suspicious page.
  5. Review the transaction. Check for recurring billing, shipping costs, return terms, and the final total before entering payment information.
  6. Choose the payment method carefully. Prefer a method that creates clear records and has a provider you can contact. Don't assume a dispute will automatically succeed.
  7. Leave if questions remain. Missing a deal is less costly than losing control of an account or sending money that can't be recovered.

If you clicked, submitted information, or paid

Act quickly. Use contact details from your card, bank statement, official app, or a trusted bookmark - not the suspicious website.

Keep the website address, screenshots, emails, receipts, order numbers, payment records, transaction IDs, and dates. Don't include passwords, full account numbers, or other unnecessary sensitive information in a report.

An FTC report helps document and route information about scams. It isn't a payment dispute or reversal request. When money or account access is involved, contact the payment provider first.

What does not prove a website is legitimate?

These features can appear on both real and fraudulent sites:

Stronger evidence comes from several checks agreeing with one another: the exact domain matches the organization, contact details check out, policies identify the same business, the offer is realistic, and the payment process is clear. Even then, don't send information the transaction doesn't require.

Common questions

Is an HTTPS website safe?

Not necessarily. HTTPS helps encrypt the connection between your browser and the site, but it doesn't verify who operates the site or whether the offer is honest. Check the domain and business independently.

Is a new domain automatically a scam?

No. New businesses create new domains. A recent registration becomes more concerning when the site impersonates an established brand, uses copied content, or combines the new domain with pressure and unusual payment demands.

Can online reviews prove that a store is genuine?

No. Reviews can be copied, selectively displayed, or fabricated. Use them as one clue, then verify the seller through independent business information and a payment method with a clear support process.

Will reporting a scam get my money back?

Reporting is useful, but it doesn't automatically reverse a payment. Contact the card issuer, bank, wire service, or payment app immediately and ask which recovery or dispute process applies to that transaction.

If you're still looking at a questionable page, close it without entering test information. Reopen the business through its official app, a trusted bookmark, or an address you type yourself.