Scam websites usually want one of three things: your payment, your account credentials, or personal data they can exploit later. Before you enter anything, verify the web address independently, inspect the seller, read the transaction terms, and pick a payment method with a recovery option.
A padlock, polished logo, or professional-looking design isn't proof that a site is legitimate.
A 60-second scam website check
Stop and investigate if you notice any of these signs:
- The link came from an unexpected email, text message, social-media post, or pop-up.
- The address contains misspellings, substituted characters, extra words, or an unfamiliar domain.
- The price is far below what reputable sellers charge.
- A countdown timer or warning says you must act immediately.
- The seller's address, phone number, or return policy is missing or can't be verified.
- Reviews appear only on the website or use repetitive, generic language.
- The site insists on gift cards, cryptocurrency, wire transfers, or a direct payment app.
- A page asks for a password, payment card, or one-time security code in an unusual context.
- Your browser displays a security warning or the page pushes an unexpected download.
One strong warning sign is enough to leave. Don't keep going simply because you've already spent time comparing products.
Read the web address, not just the logo
Scammers copy brand colors, photographs, login screens, and customer-service language. The address bar is harder to fake, but only if you read the entire domain.
Watch for:
- Lookalike spelling, such as
paypa1.cominstead of the real domain. - Added words that imply affiliation, such as
support-paypal.com. - A trusted name placed inside a longer domain. In
example.com.bad-site.com, the controlling domain isbad-site.com. - A familiar name used as a folder.
bad-site.com/example.comis still controlled bybad-site.com. - Unusual combinations of letters, numbers, hyphens, or domain endings.
A .com address isn't automatically safe, and another domain ending isn't automatically fraudulent. The question is whether the address matches the organization you intended to visit.
If a message says your account has a problem, don't use its sign-in link. Open the company's official app, use a bookmark you created earlier, or type the known address yourself. The Cybersecurity and Infrastructure Security Agency's online shopping advice recommends checking the address and using secure connections before submitting information.
Check the seller before buying
A real store should make it possible to understand who is selling, what you'll pay, and what happens if the order goes wrong.
Confirm the business identity
Look for a business name, working customer-service channel, physical address, and clear shipping and return information. Verify contact details independently instead of relying only on a phone number or email shown on the suspicious page. A scammer can copy a real company's address or create a convincing support chat.
A new domain isn't proof of fraud, but a recently created site selling expensive products under a familiar brand deserves extra scrutiny. Domain-registration information can provide context, although private registration and domain age aren't conclusive evidence either way.
Calculate the full price
Check the total cost, including:
- Shipping and handling
- Delivery charges
- Taxes
- Service or processing fees
- Required memberships or subscriptions
- Add-ons or minimum-purchase conditions
Read the exact terms of an advertised deal. A low price may depend on enrolling in recurring billing, buying unwanted products, or accepting a difficult return process. The FTC's online shopping guidance recommends comparing the total cost and reading the terms before ordering.
Check shipping, returns, and refunds
Save the advertised delivery date, return window, refund conditions, and any restocking or return-shipping terms before paying.
The FTC says sellers must ship merchandise as promised. If no shipping time was promised, its guidance says the seller has to ship within 30 days after receiving your name, address, and payment or permission to charge your account. That rule won't make a fake seller deliver an order or guarantee that you'll recover money, so keep your records and act quickly if the seller misses its promise.
Treat reviews as evidence, not proof
Look for independent reviews and complaints from more than one source. Pay attention to specific details about delivery, product quality, customer service, and refunds. A page filled with perfect reviews, vague praise, or testimonials posted within a short period isn't reliable by itself.
Reverse-image searching a product photograph can also help. If the same image appears on unrelated stores selling different products, ask why before ordering.
HTTPS protects the connection, not the seller
HTTPS means information is encrypted while it travels between your browser and the website. That helps protect data in transit, but it doesn't prove that the business is honest, that the product exists, or that the login page belongs to the company it claims to represent.
A scammer can operate a site with HTTPS. Think of the padlock as a locked envelope addressed to a particular website: the envelope may be protected during delivery, but you still need to confirm who is receiving it.
Use this rule:
- If the browser shows a certificate or security warning, don't enter information.
- If the site uses HTTPS, continue checking the domain, seller, policies, and payment method.
- Don't treat trust badges or security logos as proof. Those images can be copied.
Use safety tools, but understand their limits
Browser protections and website scanners can identify known harmful pages, malware, or phishing attempts. They can't certify that an unknown seller will ship your order or honor a refund.
- Check a suspicious address with Google Safe Browsing. A warning is a reason to leave immediately. A clean result isn't a guarantee, because a new scam may not have been reported or detected yet.
- Pay attention to browser warnings rather than clicking through them.
- Search for the business name, address, and phone number separately from the site. Watch for unrelated businesses using the same information.
- Use a domain-registration lookup as one clue, not a verdict.
- For an expensive product, compare photographs, descriptions, and prices with established retailers.
Don't upload passwords, identity documents, or payment records to an unfamiliar "verification" service. A tool that asks for sensitive information may be another scam.
Choose a payment method with a recovery path
Payment choice affects what you can do after a problem.
| Payment method | Safer approach |
|---|---|
| Credit card | Ask the card issuer promptly about disputing an unauthorized charge or merchandise that never arrives. Follow the issuer's evidence requirements and deadlines. |
| Debit card | Contact your bank or credit union immediately if you were tricked into paying or see an unauthorized transaction. |
| Digital wallet | It may limit how much card information you share, but it doesn't make the seller legitimate. Check the wallet and underlying card's dispute process. |
| Gift card or cryptocurrency | Treat a seller's demand for either as a major warning. If you paid, contact the gift card issuer or cryptocurrency exchange immediately. |
| Wire transfer or person-to-person payment | Don't use it with an unfamiliar seller when you have another option. Recovery may be difficult. |
The FTC's guidance on what to do after a scam recommends contacting the company used to send the money as soon as possible. Save the receipt, transaction ID, wallet address, gift card number, or other payment details.
Never share a one-time authentication code with someone who contacted you by phone, text, email, or social media. If a legitimate service needs you to approve a login or payment, complete the process through its official app or website. The Office of the Comptroller of the Currency's online scam guidance also recommends verifying websites before providing sensitive information and using two-factor authentication on your accounts.
What to do if you entered information or paid
Act based on what the site received.
If you entered a password
Go to the real service through its official app or manually entered address and change the password. Change it anywhere else you reused it. Then sign out of other sessions and enable two-factor authentication.
If you gave a one-time code or approved an unexpected login, contact the account provider immediately and explain what happened.
If you entered card or bank details
Call the card issuer, bank, or credit union using the number on your card or statement, not a number from the suspicious website. Ask whether the card or account should be blocked or replaced, report unauthorized activity, and ask about the provider's dispute process. Continue checking statements and account alerts.
If you paid with a gift card or cryptocurrency
Contact the gift card company or cryptocurrency exchange immediately. Keep the card, receipt, messages, wallet address, and transaction details. Recovery isn't guaranteed, but delay makes it harder for the provider to investigate or stop remaining funds.
If you downloaded a file or installed an extension
Stop using the device for banking or password changes until you've checked it. Remove suspicious extensions or software, update the device, and run its reputable security tools. If you see unfamiliar logins, pop-ups, or account activity, use a different trusted device to change passwords and contact the affected providers.
Preserve evidence
Save screenshots showing the full address, product page, checkout page, order confirmation, promised delivery date, messages, advertisements, and payment records. Don't revisit the site to pay a supposed "refund" or "recovery" fee. A second request for money is often another scam.
Report the website and the loss
These routes are for U.S. consumers:
- Report the fraud to the Federal Trade Commission and include the website address, messages, payment information, and dates.
- File an internet-crime report through the IC3 complaint form. The IC3 information page explains that reports are shared with law-enforcement partners, although IC3 may not respond directly to every submission.
- Report the fake listing, account, advertisement, or message to the marketplace, social network, email provider, or ad platform where you found it.
- Use Google Safe Browsing and your browser's reporting tools if the site appears to be phishing or distributing malware.
- Contact your payment provider separately. A fraud report doesn't replace a request to block, replace, or dispute a transaction.
- Contact local law enforcement if you lost money, exposed identity information, or face an ongoing threat.
Reporting won't guarantee a refund, but accurate evidence can help providers and investigators identify related activity.
Common questions
Can an HTTPS website still be a scam?
Yes. HTTPS encrypts the connection but doesn't establish that the seller is genuine. Check the domain, business identity, policies, reviews, and payment method together.
Is a newly registered domain automatically fraudulent?
No. New businesses can have new domains, and older domains can be compromised. Domain age is only a warning signal when combined with other concerns such as copied branding, extreme discounts, or missing contact information.
What should I do if an online order never arrives?
Save the order and delivery records, contact the seller once through independently verified contact information, and contact your card issuer, bank, or payment provider promptly. The FTC's shipping guidance may apply, but a fake seller may not cooperate, so don't wait to ask about payment protections.
Should I report a scam website if I didn't lose money?
Yes. Report suspicious phishing, fake-store, or malware activity to the FTC, IC3, the platform that displayed it, and relevant browser safety tools. Include the full address and screenshots if possible.
Scam website checklist
Before you buy or log in, confirm:
- [ ] I opened the site through a known address, bookmark, or official app.
- [ ] The domain is spelled correctly and belongs to the organization I intended to visit.
- [ ] My browser shows no security warning.
- [ ] The price and urgency don't pressure me into skipping checks.
- [ ] I can verify the seller and its contact information.
- [ ] I know the full cost, delivery promise, return rules, and refund terms.
- [ ] Independent information supports the seller's reputation.
- [ ] The payment method gives me a reasonable way to report a problem.
- [ ] The site isn't asking for an unnecessary password, one-time code, or download.