A website can look professional and still be fake.
Logos, photographs, product descriptions, security symbols and familiar brand names can all be copied.
Checking whether a website is safe therefore requires more than looking at its design.
You need to examine the address, browser warnings, how you reached the site, what the site is asking you to do and whether you can verify the organization independently.
Start with the website address
The address shown in your browser is one of the most useful things to inspect.
Scam websites often use addresses that are similar to a real organization's address without being identical.
Look carefully for:
- misspelled words
- extra words
- unexpected letters or numbers
- an unfamiliar ending
- a completely different organization name
Similar does not mean identical
Imagine that a company's known website is:
example.invalid
These would be different addresses:
examplehelp.invalid
secureexample.invalid
examplesupport.invalid
They may contain the same familiar word, but they are not the same website address.
The addresses above use the reserved invalid ending only as safe examples.
Do not judge an address from one familiar word
A scammer can include the name of a real company somewhere in a web address.
The presence of that word does not prove that the company controls the site.
Compare the complete address with an address you already know is genuine.
Be especially careful with links from messages
A message can display text that looks like a familiar website while sending you somewhere else.
If an unexpected email, text or direct message says you must sign in, update payment information or fix an urgent account problem, do not rely on the link in the message.
Open the real service independently.
You can use:
- a trusted bookmark
- the official application
- a website address you already know
Then check the account from there.
Search results can also lead to scams
Search engines are useful, but the first result is not automatically the official organization.
Some results are advertisements.
Scammers can create advertisements or pages designed to appear when people search for well known companies, government services or customer support.
Read the destination carefully before using a search result.
Type a known address directly when possible
If you already know the real website address for your bank, school, government service or another important organization, entering that known address directly can reduce the chance of following an impersonation link.
A saved trusted bookmark can also be useful for services you visit regularly.
What does HTTPS tell you?
Modern websites commonly use HTTPS to protect information while it travels between your browser and the website.
This is important.
Without a protected connection, another party on the network may have greater opportunity to observe or alter information travelling between you and the site.
HTTPS does not prove that the website is honest
A fraudulent website can also use HTTPS.
HTTPS tells you about the protection of the connection.
It does not by itself prove that the organization operating the website is trustworthy.
You still need to check that you are connected to the correct site.
Do not use the padlock as your only test
Older online safety advice often encouraged people to look for a padlock.
A protected connection remains important, but a connection indicator should not be treated as proof that a business, login page or offer is genuine.
Check the website name as well.
Pay attention to browser warnings
Modern browsers can warn you about dangerous pages, insecure connections or certificate problems.
Do not automatically bypass these warnings simply because you want to reach the page.
A warning deserves investigation.
A dangerous site warning is different from an ordinary page error
Your browser may display different kinds of warnings.
A page may fail to load because of an ordinary technical problem.
Another page may be specifically identified as dangerous or deceptive.
Read the warning rather than clicking through automatically.
Do not enter information on a site your browser identifies as dangerous
If the browser displays a strong warning that a website is dangerous, avoid entering:
- passwords
- payment information
- personal information
- verification codes
Return to a trusted route to the organization instead.
Look at how you arrived at the website
The same page deserves more caution when you reached it through:
- an unexpected email
- an unexpected text message
- a social media direct message
- a pop up claiming something is wrong
- an advertisement promising an extreme offer
- a QR code from an unknown source
The route to a site provides useful context.
A familiar logo proves very little
Logos and brand colours are easy to copy.
A scam login page may look almost identical to the real company's page.
Do not use appearance alone to decide whether the page is genuine.
Professional design is not proof either
Modern website templates allow almost anyone to build a polished looking site.
Good spelling, attractive photographs and professional graphics are positive presentation features, but they are not proof of legitimacy.
Check what the website is asking you to do
A site's behaviour can provide important warning signs.
Be cautious if a website unexpectedly asks you to:
- enter an account password
- enter an authentication code
- provide banking information
- upload an identity document
- download unfamiliar software
- grant remote access to your device
- send money immediately
The more sensitive the request, the more important independent verification becomes.
Unexpected login pages deserve attention
Suppose you click a link to read a document and unexpectedly receive a login page.
Do not automatically enter your email password.
Ask:
- Why does this page need my account?
- Which organization owns the website?
- Did I expect to sign in?
- Can I reach the same document through the official service?
Never provide an authentication code because a website tells you to send it to someone
A legitimate authentication code is normally used inside the login process you deliberately started.
A site or person asking you to copy a code into a chat, message or support conversation is a serious warning sign.
Be careful with downloads
A website may try to persuade you to install a program, browser extension or mobile application.
Before downloading software, ask whether you expected the download and whether it comes from the official provider.
Be especially careful when a page says that you urgently need:
- a security update
- a video player
- a browser extension
- a support tool
- a document viewer
Real security warnings should not require you to call a random number
Scam websites sometimes display alarming messages claiming that your computer has a virus or that your account has been blocked.
The page may tell you to call a telephone number immediately.
Do not grant remote access or provide payment information because of an unexpected website warning.
Close the page when it is safe to do so and use the device or software provider's official support route if you genuinely need assistance.
Research an unfamiliar business independently
If you are considering buying from a website you have never used before, do some research away from the site itself.
Search for the business name together with terms such as:
- scam
- review
- complaint
Look for information from more than one independent source.
Reviews can help, but they are not perfect proof
Reviews can be fake, manipulated or selectively displayed.
A large number of positive reviews on the seller's own website should not be your only reason for trusting it.
Use reviews as one part of a wider check.
Check whether the company can be verified independently
For an unfamiliar organization, look for evidence outside the website.
This may include:
- a known official directory
- an established public profile
- independent news coverage where relevant
- contact information confirmed somewhere else
- information from a regulator or government service where appropriate
The appropriate verification method depends on the organization.
A contact page is not proof by itself
Anyone can create a contact page.
A physical address, telephone number or company name written on a website may still be false or copied.
If the transaction matters, verify important information independently.
A privacy policy is useful but not proof either
A legitimate service should explain relevant privacy practices where required.
However, text can be copied from another website.
The existence of a privacy policy does not automatically make a site trustworthy.
Be suspicious of deals that are dramatically different from everywhere else
An unusually low price does not automatically mean a scam.
But an offer that appears impossible compared with every established seller deserves investigation.
Scammers often use extreme discounts to make people act before checking the seller.
Urgency is another warning sign
Be cautious when a website says:
You have only two minutes left.
Pay now or your account will disappear.
This offer is available only if you act immediately.
Real offers can have deadlines, but artificial pressure is a common scam technique.
Watch how the seller wants to be paid
The requested payment method can provide another clue.
Be cautious when an unfamiliar seller insists that payment can only be made using a difficult to reverse method.
Examples that commonly deserve extra caution include:
- gift cards
- cryptocurrency sent directly to a stranger
- wire transfers
- other unusual payment arrangements
Investigate the seller before sending money.
Do not move payment outside a trusted platform without understanding why
A seller may try to move a transaction away from a marketplace or booking platform.
Doing so can remove protections offered by the original platform.
Understand the consequences before agreeing.
Redirects deserve attention
A website may send you automatically to another address.
Redirects are common and often legitimate.
However, if you expected one organization and suddenly find yourself on an unrelated website asking for credentials or payment details, stop and verify the destination.
Shortened links hide the destination
Short link services can be useful, but the shortened address may hide where the link ultimately goes.
When the message is unexpected or the action is sensitive, avoid relying on a shortened link.
Open the organization independently instead.
QR codes are links too
A QR code can send your device to a website just like a clickable link.
Do not assume a QR code is safe because it appears on printed material, a poster or a screen.
After scanning, review the destination before entering personal information or signing in.
Look for unexpected changes in the address
If you begin on a familiar website and the address suddenly changes before a login or payment step, check where you are.
Some legitimate services use separate payment or authentication providers.
But an unexpected change should be understood before you enter sensitive information.
Do not guess whether an unfamiliar payment page is genuine
If you do not recognize a payment provider, investigate it before entering card or banking information.
For an important purchase, use the seller's official support information if clarification is needed.
Browser saved passwords can provide a useful clue
A password manager commonly associates a saved login with the website for which it was created.
If your usual credential is unexpectedly not offered, do not treat that as proof of a scam, but consider it a reason to check the address carefully.
Never manually paste a password into an unfamiliar page merely because autofill did not appear.
Use independent navigation when anything feels wrong
This is one of the safest general habits.
If a site claims that your bank account, email account, delivery or subscription needs attention:
- do not continue through the suspicious page
- open the real organization's application or known website independently
- sign in through the normal route
- check whether the claimed problem actually exists
A safe website check does not rely on one clue
No single clue proves that every website is safe.
Instead, combine several checks:
- the exact address
- browser warnings
- how you reached the site
- what information the site requests
- whether the organization can be verified independently
- whether the offer and payment method make sense
A useful five step check
Step 1: Pause
Do not enter information immediately.
Step 2: Read the address
Compare it with the website you expected.
Step 3: Check browser warnings
Do not casually bypass security or danger warnings.
Step 4: Verify independently
Use a known website, official application or trusted contact route.
Step 5: Decide whether the request makes sense
Ask why the website needs the information, payment or download it is requesting.
Example 1: An account warning message
You receive a message saying:
Your account will be suspended today. Sign in now.
The message contains a link.
A safer response is:
- do not use the link
- open the service through its normal application or known address
- check the account directly
- report the suspicious message if appropriate
Example 2: An unfamiliar online shop
You find an expensive product advertised at a price far below every established seller.
Before paying:
- check the website address
- research the business independently
- look for complaints or scam reports
- consider whether the payment method provides reasonable protection
- do not allow urgency to stop you checking
Example 3: A browser warning
You visit a site and your browser displays a strong dangerous site warning.
Do not enter personal information or credentials.
Return to a trusted source and verify the website independently.
Example 4: A secure connection on the wrong site
A page uses HTTPS and the connection appears protected.
However, the website address is not the organization you intended to visit.
The protected connection does not correct the wrong destination.
Leave the page and navigate to the known real service.
What if you are still uncertain?
You do not have to decide immediately.
If a website feels suspicious:
- do not enter personal information
- do not enter passwords
- do not make a payment
- do not download unfamiliar files
- verify the organization another way
When the transaction is important, taking more time is safer than guessing.
Report suspicious websites when appropriate
Government cybersecurity and consumer protection services in some countries provide ways to report suspected scam websites.
You may also be able to report a fraudulent page to the organization being impersonated or through your browser's safety tools.
Use reporting routes appropriate to your country and situation.
If you already entered a password
If you believe you entered a password on a fraudulent website:
- open the real service independently
- change the compromised password
- make sure it is not reused on another account
- review account sessions and security settings
- enable or review multi factor authentication
If that password was reused elsewhere, replace it on those accounts too.
If you entered financial information
Contact the relevant bank, card issuer or financial provider using its official contact channel.
Explain what information may have been exposed and follow its fraud response instructions.
Do not use contact information supplied by the suspicious website.
If you downloaded something suspicious
Stop interacting with the suspicious site.
Follow trusted device security guidance appropriate to your operating system.
Update security software where applicable and use official security or malware scanning tools.
If the device belongs to an employer or school, follow its incident reporting process.
Common website checking mistakes
- trusting a site only because it uses HTTPS
- assuming the first search result is official
- trusting a familiar logo
- ignoring the exact website address
- bypassing browser warnings without investigation
- entering a password after following an unexpected message link
- trusting a seller only because the site looks professional
- allowing a countdown timer to force an immediate decision
- installing software because a web page says it is urgently required
- assuming a QR code is automatically safe
Website safety checklist
Before entering sensitive information, ask:
- Did I expect to visit this website?
- Is the complete address the one I intended to use?
- Did I reach it through a trusted route?
- Is my browser showing a warning?
- Does the website explain why it needs the information?
- Can I verify the organization independently?
- Does the offer make reasonable sense?
- Is the payment method appropriate?
- Am I being pressured to act immediately?
- Would it be safer to open the real service independently?
The main idea
A safe looking website is not necessarily a safe website.
Check the complete address, pay attention to browser warnings and remember that HTTPS protects the connection but does not prove that the organization behind the page is honest.
Be especially cautious when you arrive through an unexpected message, advertisement, QR code or shortened link.
When a site asks for a password, payment, personal information or a download, verify the organization independently before continuing.
When in doubt, leave the suspicious page and reach the real organization through a route you already trust.
Continue learning
Review How to Recognize Phishing Messages for suspicious emails, texts and links.
Review How to Protect Personal Information Online for protecting information requested by websites and applications.
The next lesson will practise checking a suspicious link before opening it.