Gearboxly
Security

How to Check If a Website Is Safe

By Gearboxly5 min read

Before you enter a password, card number, or personal details on a website, it's worth thirty seconds to check it's genuine. Fake and malicious sites are common and increasingly convincing, but they almost always leave signs — in the address, the connection, and the details — that give them away if you know where to look.

This guide covers how to check whether a website is safe and legitimate before you trust it with anything.

What you need

  • The website's full address (URL).
  • A moment to look before you act — scams rely on haste.
  • A few free tools to confirm your judgement.

Step-by-step

  1. 1

    Check the exact address carefully

    Read the full domain, not just what it looks like. Scammers use lookalikes: 'paypa1.com', 'amaz0n-security.net', or a real brand name buried in a longer address. Make sure the domain is exactly the official one, spelled correctly — this catches most phishing sites instantly.

  2. 2

    Look for HTTPS — but don't over-trust it

    A padlock and 'https://' mean the connection is encrypted, which is necessary but not sufficient. Scam sites can have HTTPS too. Its absence on a page asking for passwords or payment is a clear red flag; its presence alone doesn't prove the site is honest.

  3. 3

    Judge the site's quality and details

    Legitimate sites usually have working links, professional design, clear contact information, a privacy policy and terms, and no glaring spelling errors. Missing contact details, lots of typos, pushy urgency, and prices too good to be true are classic scam signals.

  4. 4

    Verify with free tools

    Check the domain's age and owner with a WHOIS lookup — a brand-new domain impersonating an established company is suspicious. Confirm the SSL certificate is valid, and you can check a site's reputation through browser safety warnings and reputable site-checker services.

  5. 5

    Be wary of how you arrived

    Extra caution if you reached the site from an email link, an ad, or a message. Instead of clicking through, open a new tab and type the official address yourself. Many scams work by sending you a convincing link to a fake version of a real site.

  6. 6

    Never enter sensitive data if unsure

    If anything feels off — the address is slightly wrong, the connection isn't secure, the details don't add up — don't enter passwords, card numbers or personal information. When in doubt, leave and access the service through its official app or website directly.

Examples

  • A 'bank' email linked to 'secure-bank-verify.com' — checking the domain revealed it wasn't the bank's real address at all, exposing the phishing attempt.
  • A WHOIS lookup showed a site claiming to be an established retailer was registered two weeks ago — a strong sign of a scam.

Tips

  • Read the full domain for lookalike spelling — it catches most fakes.
  • HTTPS is necessary but not proof; its absence on a login page is a red flag.
  • Check for real contact details, a privacy policy and professional quality.
  • Use WHOIS to check a suspicious domain's age and owner.
  • Reached it from a link? Type the official address yourself instead.

Common mistakes

  • Trusting the padlock alone. HTTPS only means encryption; scam sites can have it too — check other signals.
  • Not reading the full domain. Look for lookalike spellings and brand names buried in longer addresses.
  • Clicking links from emails/ads. Open a new tab and type the official address yourself.
  • Entering data when unsure. If anything feels off, don't submit sensitive info — leave and go direct.

Conclusion

Checking a website is safe takes seconds: read the exact domain, confirm a secure connection without over-trusting the padlock, judge the quality and contact details, verify a suspicious domain with WHOIS, and never enter sensitive data if something feels off. A little scrutiny before you trust a site prevents most online scams.

Tools for this task

Frequently asked questions

Read the full domain carefully for lookalike spelling, check for HTTPS (necessary but not sufficient), judge the site's quality and contact details, verify the domain's age with a WHOIS lookup, and be cautious if you arrived via a link.

Not by itself. The padlock and HTTPS mean the connection is encrypted, which scam sites can also have. Its absence on a page asking for passwords or payment is a red flag, but its presence alone doesn't prove legitimacy.

Watch for lookalike or misspelled domains, missing contact details or policies, poor design and typos, prices too good to be true, pushy urgency, and very new domains impersonating established brands. Any combination is a warning.

Don't enter any passwords, card numbers or personal details. Leave the site and access the service through its official website or app that you navigate to yourself, and report the fake if you can.

Related guides