If you can't confirm a website on your own, don't enter a password, card number, or other personal details. Close the tab. Open the company's official app, type an address you already know, or use a phone number from a statement, the back of your card, or official mail. A slick design, a familiar logo, a high search ranking, and even https in the address bar still don't prove the site is legitimate.

HTTPS encrypts information between your browser and the page. It does not tell you who runs that page. Scammers can get certificates for their own domains.

This is for U.S. consumers. Your bank, card issuer, payment app, or merchant may use different steps and deadlines.

What scam websites are after

The page is usually trying to make a risky action feel ordinary: signing in, paying an invoice, claiming a coupon, downloading a file, or sending money.

Fake stores push popular products at prices that don't match the market, take payment, then send nothing, send a counterfeit, or disappear. Phishing pages copy a bank, retailer, delivery company, government agency, or email provider so you'll type a username, password, security code, or card number. Payment traps claim you owe a toll, invoice, fee, fine, or delivery charge and send you to a fake checkout. Other pages present a file as a coupon, rebate, receipt, payment form, browser update, or security tool. The FDIC warns that links and attachments like those can install malware. Investment and cryptocurrency pitches promise guaranteed returns and press you to send funds to a wallet, exchange account, or someone you can't verify.

The site may be invented from scratch, or a real site may have been compromised. You don't need to name the technical trick before you protect yourself. The useful question is whether you can confirm the business and the transaction through a separate channel you already trust.

Red flags that should stop you

One odd detail isn't always enough. Several together are a reason to leave, not a reason to keep poking around on the same page.

Lookalike addresses. A misspelled domain, an extra word, a hyphen, or a swapped character can imitate a brand you know. Type the company's known address or use its official app.

Unexpected links. A text, email, ad, or social post can hide a different destination, and ads can send you to a brand-new site. Don't use that link. Find the organization yourself.

Deals that override caution. Extreme discounts and guaranteed returns are there to rush you. Compare the total price with established sellers. Pressure tactics do the same job: countdown timers, account-closure threats, and claims of legal trouble are meant to stop you from checking. A real company can explain the request through its normal support channel.

Hard-to-reverse payment. Gift cards, cryptocurrency, wire transfers, and unfamiliar peer-to-peer accounts are difficult to unwind and often come with weak buyer protection. Don't pay until you can verify both the seller and the recipient.

Thin identity. If the site won't clearly say who is selling, where the business is, or how returns work, you have little to hold onto later. Look for a business name, address, email, phone number, shipping terms, and refund policy. Copied product text, stock photos, and glowing reviews that exist only on that site are easy to fake. Search for the same business outside its own pages.

Pop-ups and browser warnings. A demand to download software, allow remote access, or call "support" can lead to malware or a second impersonation. Close the tab. Don't install anything or call a number from that pop-up. If your browser or a security service already flags the page, leave. Don't bypass the warning.

A stale copyright line or clumsy grammar can add to the picture, but neither proves fraud. Scammers buy professional templates. Small legitimate shops can have messy sites. HTTPS with a padlock belongs in the same bucket: it is a connection feature, not a business check.

How to check a site before you buy

Skip payment and login links from unexpected messages. Start from a bookmark you made earlier, the retailer's official app, or an address you type yourself. For a bank, card issuer, delivery company, or government agency, use the number on your statement, card, or official correspondence, not a number on the suspicious page.

Read the full domain before you sign in or pay. What matters is the registered domain, not a comforting word at the front. secure.brand.example.com sits under example.com. secure-brand.example.net belongs to example.net, even if the page wears the brand's logo. On a computer, hover to preview a link. On a phone, press and hold only if your device shows a preview without opening the page. Don't enter credentials just to "test" it. A new domain isn't automatically a scam, and an older one isn't automatically safe. Age is one clue.

Then verify the seller, not just the layout. You want a real business name, working contact details, shipping information, return conditions, and a privacy policy. Check whether that same business shows up independently in reputable search results or established marketplaces. Reviews that live only on the seller's site don't count as proof.

The FTC's online shopping guidance recommends well-known comparison-shopping sites and the complete cost of an offer, including shipping, handling, taxes, and other fees. Read the deal itself: the item, quantity, recurring charges, delivery date, cancellation terms, and return process. Be wary of a "free" offer that quietly starts a subscription or forces an extra purchase.

If a seller doesn't promise a shipping time, the FTC says it generally must ship within 30 days after receiving the information needed to complete the order and permission to charge your account. That rule is about fulfillment. It does not prove an anonymous store is genuine, and it does not guarantee you'll recover money from a scammer.

Pick a payment method you understand and can actually follow up on. A credit card may give you a billing-dispute path, but the issuer decides whether the charge qualifies and may set time limits. Don't send gift-card numbers or cryptocurrency just because the site says those are the only options. A request for a wire, a direct bank transfer, or payment to a personal account is a reason to verify the business again.

Before you finish the order, keep the product page, terms, promised delivery date, receipt, seller details, and confirmation emails. Screenshot the page if it might vanish. That record is what a card issuer, bank, marketplace, or law-enforcement agency can use later.

Website checkers help, but they don't certify a store

You can see whether a link has already been flagged with Google Safe Browsing. A warning is a strong reason to leave immediately.

A clean result is not a green light. New scam domains may not be listed yet, and a site can be dishonest without delivering malware. Don't paste a private link that contains a password-reset token, account number, or other personal information into a public scanner.

Use a checker next to independent verification, not instead of it: confirm the address, reach the business through an official app or a known website, read the terms and total cost, and use a payment method with a realistic dispute route. Stop if the site wants you to skip any of that.

If you already used the site

Move quickly, but don't go back to argue or ask the scammer for a refund. Use official contact details for your bank, card issuer, or payment provider.

Save the full web address, screenshots, receipts, transaction IDs, emails, texts, ads, and any promised shipping or refund terms. If a file downloaded, keep it only if you can store it safely. Don't open it again.

What happens next depends on how the money moved.

Credit card. Call the number on the back of the card. Say whether the charge was unauthorized, the item never arrived, the item was counterfeit, or the seller misrepresented the sale. Ask about replacing the card, starting the right billing dispute, the deadline, and what documents they need.

Debit card. Contact the bank or credit union immediately. Say whether you authorized the payment or someone used the card without permission. Ask about blocking or replacing the card and about the bank's dispute process.

Bank transfer, wire, or peer-to-peer payment. Contact the sending bank or payment app at once and ask whether a recall, reversal, or recipient hold is still possible. Recovery isn't guaranteed, especially after the recipient withdraws the funds.

Gift card. Contact the issuer immediately. Keep the card, receipt, and messages. Ask whether the balance can be frozen or the transaction investigated.

Cryptocurrency. Contact the exchange or wallet service involved, give the transaction details, and ask what they can still do. Be skeptical of anyone who promises recovery for an upfront fee.

The FTC's scam recovery guidance walks through payment-specific steps. Don't wait on the website's customer service before you call your bank or issuer.

If you created an account on the fake site, change that password on the real service. If you reused it, change it everywhere, starting with email. Use the official app or type the legitimate address yourself, and turn on multifactor authentication. If you entered card details, ask whether the card should be replaced. Watch statements and alerts. If you handed over sensitive identity information, consider a fraud alert or credit freeze and watch for unexpected accounts or bills.

Downloaded a file, installed software, allowed remote access, or typed information after a security warning? Avoid banking on that device until it has been checked. Disconnect it from the internet if that's safe, run reputable security software, install updates, and get qualified technical help if you need it. Change passwords from a different, trusted device.

Where to report it

A report won't guarantee a refund. It can still create a record and help platforms and agencies connect related complaints.

Use the FTC's consumer guidance and reporting process. Submit a complaint to the FBI's Internet Crime Complaint Center when the incident involves cyber-enabled crime. IC3 explains that it receives a large volume of complaints and may not respond directly to every submission, so don't wait for a reply before you contact your payment provider. Report the ad, message, profile, or listing to the platform where you found it, and tell the real brand if someone is impersonating it. Keep confirmation numbers and copies of what you send.

Don't pay a "recovery agent" who contacts you after the loss. That is often a second scam aimed at people who already sent money.

None of these, on its own, proves a site is safe to buy from: a padlock or HTTPS, a top search result, a well-known logo or copied product photos, glowing reviews, a phone number or street address, a checker that hasn't listed the site, or a professional look. Independent confirmation is the check that matters: reach the organization through a known channel, confirm the exact domain, understand the terms, and use a payment method that fits the purchase.

Frequently asked questions

Is a website with HTTPS safe?

Not necessarily. HTTPS helps encrypt the connection. Scammers can use it too. Check the domain, the seller, the offer, the payment request, and any browser warning.

Can I get my money back from a scam website?

Possibly, but there is no universal refund. Your options depend on the payment method, how fast you report, the evidence you have, and the provider's rules. Contact the provider immediately and ask which dispute or recovery process applies.

Should I trust a website that appears in a search ad?

No. Search placement is not proof of legitimacy. Open the company's official app or type a known domain instead of relying on the ad.

What should I do if an online order never arrives?

Save the order and the delivery promises, contact the payment provider promptly, and review the FTC's online shopping guidance. If the seller promised a shipping date, keep that promise as evidence. If no time was stated, the FTC generally describes a 30-day shipping requirement for covered online orders.

If that suspicious page is still open, don't test it with a card or password. Close it, then reach the business through its official app or a number you already trust.