A scam website can look as polished as a major retailer. Before you buy, independently verify the exact domain, the business operating it, its shipping and return terms, and the payment route. If you can't confirm those details, don't enter payment or account information.
A credit card may offer a billing-dispute process that some other payment methods don't, but it doesn't guarantee a refund. If you've already entered information, contact the relevant provider promptly. The steps below are for U.S. consumers; bank, card, and payment-app procedures vary.
Why a convincing design proves little
Fake websites can copy brand names, logos, product photographs, reviews, checkout pages, and customer-service language. Scammers may also use AI-generated images or copy. You don't need to identify how a page was made. Check the business and payment details independently instead.
| Site feature | What it may show | What it does not prove |
|---|---|---|
| HTTPS or a padlock | The connection is encrypted | That the seller is honest or will deliver |
| Brand logo or trust badge | The site wants to appear familiar | That the badge is genuine or authorized |
| Professional mobile design | The page was built to look credible | That the business exists |
| Positive reviews | People appear to recommend the seller | That the reviews are real or independent |
A domain ending in .com |
Only the domain extension | That the site belongs to the named brand |
| A privacy or refund policy | The site has posted terms | That the terms are accurate or enforceable |
A legitimate business can have an unattractive website, while a fraudulent one can have excellent design. Treat appearance as a weak signal.
Design and copy warning signs
Look for a combination of signals rather than treating one typo or unusual color scheme as conclusive:
- A countdown timer, "only a few left" message, or repeated pop-up that pressures you to pay immediately.
- A price far below what the manufacturer or established retailers charge.
- Product descriptions that are vague, copied, or inconsistent about shipping and returns.
- Reviews that repeat the same phrases, use generic names, or describe benefits without specific details.
- A familiar logo paired with a domain that doesn't belong to the organization.
- Trust badges that can't be opened, verified, or connected to the issuing organization.
- Customer support available only through a contact form, messaging app, or free email address.
- A checkout page that changes to a different, unrelated domain without a clear explanation.
- Requests for information that an ordinary purchase doesn't need, such as an email password, bank login, or an unexpected one-time verification code.
- Pressure to pay with a gift card, cryptocurrency, wire transfer, ACH transfer, or peer-to-peer payment app.
Scammers may also use fake news stories, celebrity images, copied customer testimonials, and convincing reviews. If a page appears to represent a bank, carrier, government agency, or well-known store, open that organization through an independently verified website or app instead.
How to check a website before you buy
1. Start from a trusted source
Don't use a shopping, delivery, banking, or account-recovery link from an unexpected email, text message, social-media post, or advertisement. Type the known address yourself, use a saved bookmark, or open the organization's official app.
For a package message, go directly to the carrier's website and enter the tracking number there. For a bank message, use the phone number on your card or the bank's official app rather than the number in the message.
2. Read the entire domain
Look beyond the first familiar word in the address bar. For example, store.example.com is under the registered domain example.com, while example-store.com is a separate domain that may have no connection to the brand. A brand name appearing in a subdomain doesn't establish that the brand owns the site.
Check for:
- Misspellings, substituted characters, extra hyphens, or added words.
- A domain that puts the brand name in a subdomain while the registered domain belongs to someone else.
- An unusual extension that doesn't fit the organization you intended to visit.
- A shortened link or redirect that hides the final address.
- A checkout address that doesn't match the merchant or a payment processor the merchant clearly identifies.
HTTPS helps protect data in transit, but it doesn't confirm the identity of the site operator. The padlock is not a business-verification badge.
3. Verify the seller outside the website
Look for the business's legal or trading name, physical address, customer-service phone number, shipping information, and return process. Verify those details through an independent source rather than relying on the site's contact page.
Search for the business name separately and compare the address and phone number with established listings. Be cautious if results show several slightly different names or if every contact detail leads back only to the suspicious site. Scammers sometimes copy a real company's address, so a matching address alone isn't enough.
A domain-registration lookup can provide context, such as when a domain was created. A new domain isn't automatically fraudulent, and privacy-protected registration isn't proof of wrongdoing. Use registration information as one clue, not as a final verdict.
4. Read the terms before entering payment details
Open the shipping, return, refund, privacy, and subscription pages. Look for specific information about:
- How long delivery takes and where products ship from.
- The return address and who pays return shipping.
- Recurring charges, membership fees, or automatic renewals.
- The company responsible for processing the payment.
- How to cancel an order or contact the seller.
Broken links, copied text, contradictory company names, and terms that never identify the seller are meaningful warning signs. A policy page can still be fabricated, so treat it as evidence to check rather than proof that the business is legitimate.
5. Examine the payment request
A secure-looking checkout doesn't make an unsafe payment method safe. Be especially careful if a seller insists on gift cards, cryptocurrency, wire transfers, ACH transfers, or a peer-to-peer app instead of offering a normal card checkout. BOK Financial's guidance on fake websites also identifies these payment demands as warning signs.
If you decide to purchase from an unfamiliar merchant, a credit card may provide a billing-dispute process that some other methods don't. That isn't a guarantee of reimbursement, and the issuer will assess the transaction under its procedures. Save the order confirmation, seller details, promised delivery date, and every payment record.
What to do if you used a scam website
If you already paid or entered sensitive information, act quickly. Keep the facts organized and don't wait for the website operator to respond.
- Stop interacting with the site. Don't send more money or documents. Don't pay anyone who contacts you unexpectedly and promises to recover your money.
- Save evidence. Keep the full web address, screenshots, emails, text messages, receipts, order numbers, transaction IDs, dates, and the name of any person or company involved. If you suspect the page downloaded malware, don't revisit it just to collect more screenshots.
- Contact the payment provider. For a credit or debit card, call the number on the back of the card or use the bank's official app. Describe the transaction accurately and ask what fraud-reporting, billing-dispute, card-replacement, or account-monitoring options apply. The Office of the Comptroller of the Currency's fraud guidance also recommends contacting your financial institution through an official channel.
- Use the payment-specific recovery route. If you used a gift card, contact the company that issued it and keep the card and receipt. For a wire transfer, contact the transfer company immediately and ask whether the transfer can be reversed. For a peer-to-peer payment app, report the fraudulent transaction to the app company and ask whether it can be reversed. If the app drew money from a bank account or card, contact that provider too. The FTC's scam-response guidance explains these steps.
- Secure your accounts. Change any password you entered or reused, starting with your email account, through the real provider's website or app. Turn on multifactor authentication where available. Monitor your bank, card, email, and shopping accounts for unfamiliar activity.
- Protect your identity if necessary. If you provided a Social Security number or other identity information, contact one of the three major credit-reporting agencies through its official channel and ask about a fraud alert. Keep notes about every call and case number.
- Report the incident. You can submit an online-fraud complaint to the Internet Crime Complaint Center. IC3 collects and shares reports with law-enforcement partners, but it can't respond directly to every complaint and a report doesn't automatically recover money. The FBI's cyber guidance lists additional reporting routes for ongoing crimes and other serious threats.
Contact the bank, card issuer, or payment company even if the amount seems small. Its ability to investigate or stop a transaction may depend on how soon you report it and which payment method was used.
What controls the outcome after a scam
The website's design doesn't determine whether a payment can be reversed. The payment rail and the provider's procedures matter more:
- Credit and debit cards: The card issuer or bank handles the report and explains its investigation or billing-dispute process. Tell it whether you entered the card details, approved a transaction, or saw an unauthorized charge.
- Gift cards: The card issuer controls the response. Keep the card and receipt and report the incident promptly.
- Wire transfers: Contact the wire company immediately and request a reversal, although recovery isn't guaranteed.
- Peer-to-peer apps: Report the transaction to the app and follow its fraud process. If the app drew money from a bank account or card, contact that provider as well.
- Passwords and identity information: The affected account provider controls account recovery. Changing reused passwords and enabling multifactor authentication can limit further access.
Don't assume that reporting a website will cancel a charge. Also, don't describe a transaction inaccurately: providers may distinguish between an unauthorized charge and a payment you made after being deceived.
Common questions
Does HTTPS mean a website is safe?
No. HTTPS encrypts the connection between your browser and the website. It doesn't verify the seller's identity, product quality, refund policy, or willingness to deliver.
Can I trust reviews on a suspicious website?
Not by themselves. Reviews can be copied, manufactured, or selectively displayed. Compare the seller across independent sources and look for specific, varied experiences rather than a page filled with identical praise.
Is a very new domain automatically a scam?
No. New businesses create new domains. A recent registration is only a clue, and an older domain can also be compromised or used for fraud. Combine domain information with independent seller verification, realistic terms, and a payment method with a possible dispute process.
What if a website impersonates my bank or a government agency?
Close the page and contact the organization through its official app, website, or a phone number you already trust. Don't use contact information supplied by the suspicious page. If you entered credentials, change them through the real service and contact the institution's fraud team immediately.
If you're about to buy, close the page when it creates pressure and verify the domain and seller independently before paying. If you've already paid, contact the payment provider now and preserve the transaction records.