Before you enter a password, card number, or personal details on a website, it's worth thirty seconds to check it's genuine. Fake and malicious sites are common and increasingly convincing, but they almost always leave signs — in the address, the connection, and the details — that give them away if you know where to look.
This guide covers how to check whether a website is safe and legitimate before you trust it with anything.
What you need
- ✓The website's full address (URL).
- ✓A moment to look before you act — scams rely on haste.
- ✓A few free tools to confirm your judgement.
Step-by-step
- 1
Check the exact address carefully
Read the full domain, not just what it looks like. Scammers use lookalikes: 'paypa1.com', 'amaz0n-security.net', or a real brand name buried in a longer address. Make sure the domain is exactly the official one, spelled correctly — this catches most phishing sites instantly.
- 2
Look for HTTPS — but don't over-trust it
A padlock and 'https://' mean the connection is encrypted, which is necessary but not sufficient. Scam sites can have HTTPS too. Its absence on a page asking for passwords or payment is a clear red flag; its presence alone doesn't prove the site is honest.
- 3
Judge the site's quality and details
Legitimate sites usually have working links, professional design, clear contact information, a privacy policy and terms, and no glaring spelling errors. Missing contact details, lots of typos, pushy urgency, and prices too good to be true are classic scam signals.
- 4
Verify with free tools
Check the domain's age and owner with a WHOIS lookup — a brand-new domain impersonating an established company is suspicious. Confirm the SSL certificate is valid, and you can check a site's reputation through browser safety warnings and reputable site-checker services.
- 5
Be wary of how you arrived
Extra caution if you reached the site from an email link, an ad, or a message. Instead of clicking through, open a new tab and type the official address yourself. Many scams work by sending you a convincing link to a fake version of a real site.
- 6
Never enter sensitive data if unsure
If anything feels off — the address is slightly wrong, the connection isn't secure, the details don't add up — don't enter passwords, card numbers or personal information. When in doubt, leave and access the service through its official app or website directly.
Examples
- A 'bank' email linked to 'secure-bank-verify.com' — checking the domain revealed it wasn't the bank's real address at all, exposing the phishing attempt.
- A WHOIS lookup showed a site claiming to be an established retailer was registered two weeks ago — a strong sign of a scam.
Tips
- →Read the full domain for lookalike spelling — it catches most fakes.
- →HTTPS is necessary but not proof; its absence on a login page is a red flag.
- →Check for real contact details, a privacy policy and professional quality.
- →Use WHOIS to check a suspicious domain's age and owner.
- →Reached it from a link? Type the official address yourself instead.
Common mistakes
- Trusting the padlock alone. HTTPS only means encryption; scam sites can have it too — check other signals.
- Not reading the full domain. Look for lookalike spellings and brand names buried in longer addresses.
- Clicking links from emails/ads. Open a new tab and type the official address yourself.
- Entering data when unsure. If anything feels off, don't submit sensitive info — leave and go direct.
Conclusion
Checking a website is safe takes seconds: read the exact domain, confirm a secure connection without over-trusting the padlock, judge the quality and contact details, verify a suspicious domain with WHOIS, and never enter sensitive data if something feels off. A little scrutiny before you trust a site prevents most online scams.