What makes a site safe to use

A safe site has three things working together: it uses encryption to scramble what you send, it proves who it actually is, and it doesn't leak your data to third parties. You can check all three in under a minute using tools built into your browser. The most important one — encryption — shows up as a padlock icon next to the web address. If you don't see that padlock, stop and leave the site, especially if it's asking for a password, credit card, or personal information.

Encryption alone isn't enough, though. A scammer can buy encryption too. That's why the second check matters: verifying the site actually belongs to who it claims to be. Your browser does some of this automatically, but you can dig deeper by looking at the certificate — the digital ID the site uses to prove its identity. The third check is harder because it happens behind the scenes, but you can spot red flags by reading the privacy policy and watching what the site asks for.

Key Takeaways

  • Look for the padlock icon next to the web address in your browser's address bar — if it's not there, the site is not encrypted and you should not enter sensitive information.
  • Click the padlock to see the site's security certificate and confirm the domain name matches what you typed — scammers often use addresses that look similar but are spelled differently.
  • Check the privacy policy to see what data the site collects and whether it sells information to other companies — this is usually linked at the bottom of the page.
  • Be suspicious of sites that ask for information they don't need, like your Social Security number when you're just signing up for a newsletter.
  • Use your browser's built-in tools rather than third-party security apps, which often sell the data they collect about your browsing.

How to spot the padlock and what it means

The padlock appears in your browser's address bar — the long field at the top where the web address lives. In Chrome, Firefox, Safari, and Edge, it's on the left side of the address bar. Click it and your browser shows you the certificate information. The padlock means the connection between your computer and the server is encrypted, so no one on your network can see what you're typing or what the site sends back to you.

A padlock does not mean the site is trustworthy or that the owner is honest. It means the data in transit is scrambled. A phishing site — a fake copy of your bank's website designed to steal your password — can have a padlock too. That's why you also need to check the domain name. Look at the address bar and make sure it says exactly what you expect. If you're logging into your bank, the address should start with your bank's actual domain, like chase.com or wellsfargo.com, not something close like chase-secure.com or wellsfargo-login.net.

Reading the security certificate

Click the padlock icon and select "Certificate" or "Connection is secure" (the exact wording varies by browser). A window opens showing who issued the certificate and what domain it covers. The Common Name or Subject field should match the domain you're visiting. If you're on amazon.com, the certificate should say amazon.com, not amazon-deals.com or amazon.co.uk (unless you intentionally went to the UK site).

The certificate also shows an expiration date. Expired certificates are a red flag — it means the site owner didn't renew it, which suggests either carelessness or abandonment. Most legitimate sites renew automatically, so an expired certificate is unusual. You'll also see who issued the certificate, usually a company like DigiCert, Let's Encrypt, or Sectigo. These are certificate authorities, trusted organizations that verify the site owner's identity before issuing a certificate. If the issuer is unknown or misspelled, that's suspicious.

What to look for in a privacy policy

The privacy policy is a legal document that tells you what data the site collects, how it uses that data, and who it shares it with. It's usually linked at the bottom of the page in small text. Read it before you create an account or enter personal information. You're looking for three things: what they collect, whether they sell it, and how long they keep it.

Most sites collect your email address, name, and browsing behavior. That's normal. What matters is what they do with it. If the policy says they share your data with "partners" or "third parties" without your permission, that's a sign the site makes money by selling information about you. Some sites are transparent about this — they'll say something like "We share your data with advertising partners to show you relevant ads." Others bury it in dense legal language. If you can't understand the policy after reading it twice, that's a sign the site is hiding something.

Also check how long they keep your data. If you delete your account, do they delete your information immediately, or do they keep it for years? Reputable sites usually delete or anonymize your data within 30 to 90 days. If the policy doesn't say, that's a red flag.

Red flags that a site might not be safe

Some warning signs are obvious. If a site asks for your Social Security number, mother's maiden name, or full credit card number when you're just browsing, leave immediately. Legitimate sites ask for the minimum information they need. A shopping site needs your address and card number at checkout, but not before. A news site doesn't need your phone number to read articles.

Watch out for sites that pressure you to act fast. Phrases like "limited time offer," "act now," or "only three spots left" are common on scam sites because they make you skip the thinking step. Real companies don't need artificial urgency. Also be suspicious of sites with poor spelling, grammar, or design. Legitimate companies hire people to proofread. A site full of typos and broken images is often a scam or a site that doesn't care about quality.

Another red flag is a site that won't let you use a password manager. Password managers like Bitwarden, 1Password, or the one built into your browser fill in login forms automatically. Scam sites often block this because they want you to type your password by hand, which makes it easier for malware on your computer to capture it. If a site says "password managers not supported," that's suspicious.

How to check a site's reputation

Before you enter sensitive information on a site you've never used before, spend two minutes checking what other people say about it. Search the site's name plus the word "scam" or "review" in Google. If dozens of people report losing money or having their identity stolen, you have your answer. If you find nothing but positive reviews from the site itself, that's also suspicious — real sites have mixed reviews because no company pleases everyone.

You can also check whether a site is new or established. A site that's been around for five years and has thousands of customer reviews is lower risk than one that launched last month. Use a tool like WHOIS (available free at whois.com) to see when the domain was registered. Scammers often register domains just days before launching a fake site. If the domain is less than a month old and it's asking for money, be very careful.

Another check is to see if the site has a physical address and phone number. Legitimate businesses usually list this information. If you can't find an address or phone number anywhere on the site, that's a warning sign. You don't have to call them, but knowing they have a real location makes it easier to pursue them if something goes wrong.

What to do if you're not sure

If you're unsure whether a site is safe, the safest choice is to not use it. There's almost always another way to do what you need. If you need to contact a company, go to their official website directly by typing the address into your browser, not by clicking a link in an email or text message. Scammers send emails that look like they're from your bank or PayPal, with links to fake sites that look identical to the real ones.

If you've already entered information on a site you now think is unsafe, act quickly. If you entered a credit card number, call your card issuer and ask them to cancel the card and issue a new one. If you entered a password, change that password immediately on the real site. If you entered your Social Security number or other identity information, consider placing a fraud alert with the three credit bureaus (Equifax, Experian, and TransUnion) by calling 1-888-5-OPTOUT or visiting IdentityTheft.gov.

Frequently Asked Questions

Does a green padlock mean a site is definitely safe?

No. A green padlock means the connection is encrypted, but it doesn't mean the site is trustworthy or that the owner is honest. Phishing sites and scams can have padlocks too. You still need to check the domain name, read the privacy policy, and verify the site's reputation.

What's the difference between http and https?

HTTPS is the encrypted version of HTTP. The "S" stands for secure. If a site's address starts with http (not https), the connection is not encrypted and you should not enter sensitive information. Most modern browsers show a warning if you try to enter a password on an http site.

Is it safe to use public WiFi on a site with a padlock?

Yes, as long as the site has a padlock. Encryption protects your data even on public WiFi. However, public WiFi can expose other things, like your location or the sites you visit. If you're concerned, use a VPN, but know that VPNs have their own privacy trade-offs — some VPN companies sell data about your browsing.

Can I trust a site just because it has good reviews?

Not entirely. Some sites post fake reviews, and scammers sometimes create fake review sites to look legitimate. Look for reviews on independent platforms like Trustpilot or Google Reviews, not just reviews on the company's own website. Mix of positive and negative reviews is more trustworthy than all five-star ratings.

What should I do if a site asks for my password over email?

Never give your password to anyone, even if they claim to be from the company. Legitimate companies never ask for passwords via email. This is a phishing attempt. Delete the email and go directly to the company's website to change your password if you're concerned.