Start with the domain name and the padlock
A real website's address tells you something about who runs it. Look at the domain — the part after "www." and before the first slash. Scam sites often use addresses that look almost like real ones: "amaz0n.com" instead of "amazon.com", or "paypa1-verify.com" instead of "paypal.com". The difference is usually one letter swapped for a number that looks similar.
Next, check for the padlock icon in your browser's address bar, to the left of the web address. This means the connection between your computer and the site is encrypted — your data is scrambled so others cannot read it. A padlock does not mean the site is trustworthy, only that the connection is secure. But the absence of a padlock on a site asking for passwords or payment information is a red flag.
Click the padlock to see who owns the certificate. The certificate name should match the site's purpose. If you are on a bank's website, the certificate should be issued to that bank, not to a generic hosting company or an unrelated business.
Key Takeaways
- Check the domain name letter by letter — scammers use addresses that look similar to real ones but swap one character for a number or letter.
- Look for the padlock icon in your address bar; its absence on a login or payment page is a warning sign.
- Search the site name plus "scam" or "reviews" in a search engine to see if others have reported problems.
- Hover over links before clicking them to see where they actually lead — the address shown in your browser's status bar should match what you expect.
- Be suspicious of sites that ask for passwords, credit card numbers, or Social Security numbers without a clear business reason.
Search for the site's reputation before you interact with it
Type the site's name into a search engine along with the word "scam" or "reviews". Real businesses have reviews on multiple platforms; scam sites often have none, or only glowing reviews posted on the same day. Look for complaints about money not being refunded, accounts being hacked, or personal information being sold.
Check whether the site appears on known scam lists. The Better Business Bureau (bbb.org) maintains a searchable directory of businesses and complaints. The Federal Trade Commission (ftc.gov) publishes alerts about active scams. Neither of these sites is perfect, but if a business appears on both with multiple complaints, that is a strong signal to avoid it.
Look at when the site was created. Use a tool like WHOIS lookup (you can search "WHOIS lookup" in any search engine) to see the domain's registration date. Very new domains combined with requests for money or personal information are suspicious. Legitimate businesses often have domains registered years ago.
Watch for common scam tactics in the site's design and language
Scam sites often have poor spelling and grammar, especially in important sections like payment pages or account login areas. Real companies hire people to proofread these pages. If you see repeated misspellings or awkward phrasing, that is a warning.
Look at the site's contact information. Real businesses list a physical address, a phone number you can call, and an email address. Scam sites often have only an email, or a contact form with no way to reach anyone by phone. Try calling the number or visiting the address in a search engine map — if the address does not exist or the phone number is disconnected, the site is not legitimate.
Be suspicious of sites that create artificial urgency. Phrases like "Act now before this offer expires", "Limited spots available", or "Verify your account immediately" are common on phishing sites designed to make you click without thinking. Real companies do not pressure you this way.
Verify links before you click them
Hover your mouse over any link on the site without clicking it. At the bottom left of your browser window, you will see the actual address the link points to. If you are on a bank's website and a link says "Update Your Account" but the address shown at the bottom starts with a different domain, do not click it. That link is trying to send you somewhere else.
This technique catches a common scam tactic: a fake site that looks like a real one, with links that send you to a page designed to steal your login information. The page might say "Your session has expired, please log in again" — but you are actually on a fake login page controlled by the scammer.
If you are unsure about a link, do not click it. Instead, go directly to the company's official website by typing the address into your browser yourself, or by calling their customer service number from your phone bill or bank statement.
Check what information the site is asking for
Legitimate companies rarely ask for certain pieces of information online. Your full Social Security number, your mother's maiden name, your PIN, or your full credit card number should never be requested by email or on a site you found through a search. If a site asks for these things, assume it is a scam.
Banks and payment companies do ask for passwords and partial card information to verify your identity, but they do this on their official website after you initiated contact. They do not send you links via email asking you to "verify" your account. If you receive an email claiming to be from your bank asking you to click a link and log in, go directly to the bank's website instead — do not use the link in the email.
Real companies also do not ask for payment via gift cards, wire transfer, or cryptocurrency. If a site or email is asking you to pay this way, it is a scam. These payment methods cannot be reversed once sent.
Use your browser's built-in security tools
Most modern browsers — Chrome, Firefox, Safari, Edge — have built-in warnings for sites known to host malware or phishing pages. If your browser shows a red warning page before you can access a site, trust that warning. The site may be trying to steal your information or install malicious software on your computer.
You can also check a site's safety using Google Safe Browsing (search "Google Safe Browsing" to access it). Type in the web address and it will tell you if Google has flagged the site as unsafe. This is not a perfect system — new scam sites appear faster than they can be flagged — but it catches many known threats.
Keep your browser and operating system updated. Security updates patch holes that scammers use to break into sites or inject malware. If your computer is asking you to update, do it.
What to do if you think you have found a scam site
If you believe a site is a scam, do not use it. Do not enter any information, do not click any links, and do not download anything from it. Close the browser tab and move on.
If you have already entered information on a scam site, act quickly. If you entered a password, change that password on the real site immediately. If you entered a credit card number, call your card issuer right away — the number is on the back of your card. If you entered your Social Security number, consider placing a fraud alert with the three major credit bureaus (Equifax, Experian, TransUnion) by visiting annualcreditreport.com.
Report the scam site to the Federal Trade Commission at reportfraud.ftc.gov. You can also report phishing emails by forwarding them to the company being impersonated — most large companies have a phishing report email address listed on their website.
Frequently Asked Questions
Is a site with a padlock always safe?
No. The padlock means your connection is encrypted, but it does not mean the site is legitimate. A scam site can have a padlock too. Use the padlock as one check among several, not as proof that a site is trustworthy.
Can I trust sites with good reviews?
Reviews help, but scammers can fake them. Look for reviews on multiple independent platforms — Google, Trustpilot, the Better Business Bureau — rather than relying only on reviews on the site itself. Be suspicious if all reviews are positive or if they all appear within a short time period.
What if a site looks exactly like a real company's website?
Check the domain name character by character. Scammers often register domains that are one letter off from the real one. When in doubt, do not click any links in an email or ad. Instead, open a new browser tab, type the company's name into a search engine, and go to their official website directly.
Should I be worried if a site asks for my email address?
Asking for an email address is normal for many legitimate sites. Be concerned only if the site is asking for an email along with passwords, payment information, or personal identification numbers without a clear reason. If you are unsure whether a site needs that information, contact the company directly by phone.
How do I know if an email claiming to be from a company is real?
Do not click links in emails, even if they look official. Instead, call the company using a phone number from your statement or bill, or go to their website by typing the address yourself. Real companies understand this and do not take it personally when you verify their identity this way.