Skip to content

Check something

How to Check if a Website Is a Scam

A convincing website is cheap to build. A convincing history is not — and that is the gap these checks work in. None of them requires any technical skill.

6 min readUpdated 7 steps

Start with the address bar, not the page

How a site looks tells you almost nothing. Templates, product photography and stock “about us” copy are all available to anyone for the price of an afternoon. The address is harder to fake, because there is only one of each.

Read it precisely, and read it right to left. The domain that owns the page is the last two labels before the first single slash — everything to the left of that is a subdomain the owner chose freely. So a link reading paypal.com.account-verify.example is not PayPal; the owner is account-verify.example, and they simply named a subdomain after the brand they are borrowing.

  • Character swaps that survive a glance: rn for m, a zero for an o, a lowercase L for a capital I, or a doubled letter.
  • A real brand plus a plausible extra word — brand-support, brand-refunds, brand-secure, my-brand.
  • The right name on a different ending, where the brand you know trades on a .com and the page you are looking at does not.
  • A very long address whose recognisable part is all in the path, after the slash, where it means nothing.

Check how old the domain is

This is the single most useful check, because it is the one claim a new site cannot manufacture. Domain registration dates are public: look the domain up in any WHOIS or domain-age lookup and read the creation date.

Then compare it with the story the site tells about itself. A shop whose footer says “trusted since 2011” on a domain registered five weeks ago has answered your question. Storefronts built for a single seasonal run are often only weeks old, and the ones built around a fake sale are frequently days old.

Age on its own does not clear a site — domains are bought expired, precisely to inherit a history — but a mismatch between the registration date and the claimed history is close to conclusive.

Look for a way to reach a human

Real businesses are reachable, and reachable in ways that cost money to maintain. Look for a postal address, a company registration number where the jurisdiction issues them, and a phone number. Then test them instead of counting them.

  • Search the postal address. A residential flat, a virtual-office block or a wholly unrelated business is worth knowing about.
  • Look up the company number in the relevant national register. A number that does not resolve, or resolves to a different name, is a straight answer.
  • Call the phone number. A number that never connects, or reaches a voicemail with no business name, is not customer service.
  • Copy a distinctive sentence from the contact or returns page and search it in quotes. Fraudulent storefronts are cloned in bulk, and the same paragraph turning up on twenty unrelated shops is the template showing through.

A contact form and nothing else is not disqualifying on its own, but it means every check above is unavailable to you — and that is itself worth weighing before you send money.

Look at how they want to be paid

Payment method is the most reliable signal on this list, because it is the one thing a fraudulent seller cannot compromise on. The whole point is to receive money you cannot claw back, so they must steer you towards methods that make that true.

Card payments carry dispute and chargeback rights. Bank transfers, peer-to-peer app payments sent as personal transfers, wires, gift-card codes and cryptocurrency generally do not — once sent, getting the money back depends on the recipient's cooperation, which is exactly what you do not have.

  • A checkout that shows card logos but fails at the last step, then offers you a bank transfer “because the card system is down”.
  • A discount conditional on paying by transfer, crypto or gift card.
  • A request to pay a person's name rather than the business.
  • Any instruction to send a peer-to-peer payment as “friends and family” for something you are buying, which is the setting that removes purchase protection.
  • Gift cards, in any form, for any reason. No legitimate seller, utility, tax authority or law-enforcement body is paid in gift-card codes.

Read reviews somewhere the site does not control

Testimonials on a site's own pages are copy, not evidence. Look for the business name on independent review platforms, in forums, and on social media — and read how the reviews are distributed rather than the average.

  • A cluster of five-star reviews all posted within a few days, from accounts with no other history.
  • Praise that never mentions a specific product, or that reads as though translated from a template.
  • A pattern where the early reviews are glowing and the recent ones all describe an order that never arrived.
  • No independent footprint at all for a business claiming to be established.

Search the domain next to the word scam

Search the exact domain alongside scam, review, refund and “not received”. This is crude and it works, because someone is usually a few weeks ahead of you.

Read what comes back with some care. Pages that promise to recover money for a fee are themselves a well-established follow-on scam, and “is X a scam?” pages that conclude with a link to buy something are advertising.

Check it against community reports

A search engine surfaces what somebody wrote up. A report database surfaces what people filed, which is a much larger set — most people who lose money never blog about it.

Check the domain, and check every other identifier the site has given you: the payment handle, the phone number in the order confirmation, the email the receipt came from. Operators reuse infrastructure across storefronts far more often than they change it, so the domain may be new while the payment account behind it is already reported.

Frequently asked questions

Does a padlock or https mean a website is safe?
No. It means the connection between your browser and the site is encrypted. Certificates are free and take minutes to obtain for any domain, so fraudulent sites have them as a matter of course. The padlock protects your data in transit; it says nothing about who receives it.
Is a .com domain safer than other endings?
Not inherently. Some endings are cheaper and are consequently used more heavily for disposable sites, but plenty of fraud runs on .com and plenty of legitimate businesses do not use it. The registration date and the payment methods tell you far more than the ending does.
The site looks completely professional. Can it still be a scam?
Yes, and the good ones do. Design is the cheapest part of the operation, and entire storefronts are cloned from real retailers including the photography and the policy pages. Judge the things that cost time to build — domain history, an independent review footprint, reachable contact details — rather than the things that cost an afternoon.
I have already paid. What can I do?
Contact your bank or payment provider straight away and use the word fraud, because what is possible depends heavily on the method used and on how quickly you raise it. There is more detail in our guide on what to do if you have been scammed.
Reported websitesDomains and web addresses that have been reported for suspicious or fraudulent activity.

Related guides

The app

Check before you send money

Look up a website, phone number, payment account or crypto wallet against what the community has already reported.

Download Exposing Scams — free

Store links appear here as soon as the app is published in your region.