How do I check if a website is safe?

Short answer

Check the domain first: read it right to left, up to the first single slash, and confirm it is exactly the company's real address rather than a lookalike. Ignore the padlock — scam sites have it too. Then look for a real phone number and address, normal payment options, and reviews found outside the site. Anything demanding gift cards, wire transfers, or crypto is not safe.

Reviewed and updated by the Safe Retire Watch Research Team.

Part of our Phishing & email scams hub.

How do I read a web address correctly?

The important part of a web address is what appears immediately before the first single slash. Read backwards from that point. In 'account-secure.paypal.verify-login.com/help', the real domain is verify-login.com, not PayPal. Scammers pack trusted brand names into subdomains and paths because most people read left to right and stop at the first familiar word.

  • Watch for hyphens and extra words added to a brand name.
  • Watch for character swaps: rn for m, l for I, 0 for o.
  • Be cautious with unusual endings on shopping sites, especially newly created ones.
  • Shortened links hide the destination entirely — expand them with a link checker before visiting.

What else should I check before buying?

  1. 1Find a real phone number and physical address, then verify them independently — fake sites reuse stock addresses.
  2. 2Check payment methods. Legitimate retailers accept credit cards; requests for Zelle, wire, crypto, or gift cards are disqualifying.
  3. 3Search the store's name plus 'scam' or 'reviews' in a separate tab. Reviews on the site itself are worthless.
  4. 4Look at prices. Deep discounts on hard-to-find items are the oldest bait there is.
  5. 5Read the returns and shipping pages. Fake stores often have vague, copied, or missing policies.
  6. 6Check how old the site is — a brand-new domain selling premium goods deserves suspicion.

Safer habits that prevent the problem

  • Reach sites by typing the address or using a bookmark rather than clicking links in email or ads.
  • Pay with a credit card, which offers the strongest dispute rights.
  • Use a password manager — if it does not offer to fill your password, you may be on a lookalike domain.
  • Keep your browser updated so its built-in warnings work.
  • Check unfamiliar links with our free link checker before opening them.

Frequently asked questions

Does HTTPS mean a website is legitimate?

No. HTTPS and the padlock indicate only that the connection is encrypted. Certificates are free and instant, so most phishing sites now have them. Judge a site by its domain name, its contact details, its payment methods, and independent reviews — never by the padlock.

How can I tell a fake store from a real one?

Look for a verifiable phone number and address, credit card payment options, clear return policies, and reviews found through a separate search. Warning signs include prices far below market, pressure countdown timers, payment only by Zelle, crypto, or gift card, and a domain registered very recently.

What should I do if I already entered my card on a fake site?

Call your card issuer's fraud line, report the charge as fraud, and request a new card number. Then change any password you entered there and anywhere you reused it, and enable two-factor authentication. Report the site at ReportFraud.ftc.gov so others are warned.

Sources and further reading

Guidance on this page is based on current advisories from these authorities.

More questions answered