Privacy & Security 8 min readBy Mehadi ShawonPublished Updated

How to Tell If a Website Is Legit Before You Enter Your Card Details

How to tell if a website is legit before you pay: five checks that expose a fake shop in two minutes — domain, certificate, age, contact details, payment.

Glowing cyan magnifier inspecting a browser address bar and padlock on a dark background, representing how to tell if a website is legit
Quick answer

How to Tell If a Website Is Legit Before You Enter Your Card Details

To tell if a website is legit, check the exact domain name character by character, confirm the site is old enough to have a history, look for real contact details and a specific returns policy, and pay only with a reversible method. The FTC reported consumers lost more than $12.5 billion to fraud in 2024, a 25% rise on 2023.

Before you enter card details, you need two minutes and five checks. Almost every fake shop fails at least one of them, and most fail three.

The stakes justify the pause. According to the Federal Trade Commission's press release of 10 March 2025, US consumers reported losing more than $12.5 billion to fraud in 2024 — a 25% increase on the previous year — with investment scams the largest single category at $5.7 billion.

Check 1: read the domain, not the design

A convincing template costs nothing, so appearance proves nothing. The domain is the part that cannot be faked, only imitated.

Find the registrable domain: read the address bar from the start, and stop at the first single slash. The last two labels before that slash are the real owner. In 'shop.example-payments.com/secure/login', the owner is 'example-payments.com', regardless of how the path is worded.

  • Look for substituted characters: rn for m, l for I, a zero for an O.
  • Watch for added words: brand-support.com, brand-outlet-uk.com, brand.secure-billing.net.
  • Check the suffix. A well-known retailer selling on an unusual top-level domain deserves suspicion.
  • Beware subdomain tricks, where the brand name appears as a subdomain of a domain you have never heard of.

If a shortened or redirected link brought you here, expand it before deciding — our URL parser breaks an address into its parts so you can see the actual host.

Checkout page outline with glowing checkmarks beside domain, certificate and payment method checks before entering card details

Check 2: the padlock is not a trust badge

The padlock means the connection is encrypted, which is now the default for essentially all sites including fraudulent ones. Certificates are free and issued in minutes to anyone who controls a domain.

Google Safe Browsing, which states on its own site that it helps protect over five billion devices every day, is a more meaningful signal: if your browser interrupts with a warning about a deceptive or dangerous site, that verdict is worth more than any on-page seal.

You can still learn something from the certificate itself — who issued it and when — using our SSL checker. A certificate issued days ago on a site claiming a decade of trading is a contradiction.

Check 3: how old is the domain?

Fake shops are disposable. They are registered, run for a few weeks of advertising, and abandoned before the chargebacks arrive.

Registration date is therefore one of the strongest single indicators available to a consumer. Run the address through our domain age checker or the WHOIS lookup and compare what you find with the site's own story. 'Family business since 2009' plus a domain created last month settles the question.

Age alone does not prove legitimacy — expired domains get bought and repurposed — but extreme youth combined with heavy discounting is close to conclusive.

Check 4: contact details, policies and reviews

  1. Look for a full postal address, a company registration number where the jurisdiction requires one, and a phone number that connects to something.
  2. Read the returns policy for specifics: a real address to send goods back to, a stated window, who pays return postage. Vague reassurance is a red flag.
  3. Search the brand name with the word 'scam' or 'review' and read results on sites you already know, not testimonials hosted on the shop itself.
  4. Check whether product photos appear elsewhere via reverse image search — stolen catalogue images are routine.
  5. Distrust urgency: countdown timers, 'two left in stock', and pressure to complete checkout immediately.
  6. Treat prices far below every legitimate seller as the strongest warning of all. Nobody sells current-season goods at 80% off out of goodwill.

Check 5: pay with something reversible

If the site turns out to be fraudulent, your payment method decides whether you get your money back.

  • Credit or debit card: chargeback rights through the card network.
  • Established payment platforms: buyer protection with a dispute process.
  • Bank transfer to a named individual: effectively unrecoverable.
  • Cryptocurrency: irreversible by design.
  • Gift cards: the signature demand of a scam, with no recovery path.

A checkout that only accepts irreversible methods is not a checkout — it is the point of the exercise. The same logic applies when a scam arrives by other routes, including the tampered codes we cover in QR code scams in 2026.

If you already paid

  1. Contact your card issuer or payment platform and open a dispute; mention that the merchant appears fraudulent.
  2. Change the password you used on the site if you reused it anywhere, and generate a unique replacement with our password generator.
  3. Watch the account for small test transactions, which often precede larger ones.
  4. Report the site to your national fraud body so it can be added to blocklists.

Why it is easier than it feels

Fraudulent shops optimise for one thing: getting you through checkout before you think. Every check above works by slowing that down.

Read the domain, look up its age, find the returns address, pay with a card. If any of those four resists you, close the tab — and if the link arrived in a message rather than from your own search, read what actually happens when you click a phishing link before you go any further.

Fakes that pass the obvious checks

Some fraudulent sites clear the first three checks, so it is worth knowing what those look like. A cloned storefront on an expired domain with real history, a marketplace listing that moves the conversation off-platform, and a paid search advert sitting above the genuine result all defeat a quick glance.

  • Adverts at the top of search results: read the destination rather than the headline, and prefer the organic result for a brand you know.
  • Sellers who ask you to complete payment outside a marketplace, which strips the buyer protection you were relying on.
  • Sites reachable only through a link in a message, never through a search for the brand.
  • Checkout pages hosted on a different domain from the shop, without any explanation.
  • Copied policy text with mismatched company names or currencies, a sign the site was assembled from a template.

A two-minute routine to check if a website is legit

  1. Read the registrable domain out loud, character by character.
  2. Check the registration date and compare it with the site's own claims.
  3. Find the returns address and a working contact route.
  4. Search the brand name plus 'review' away from the site itself.
  5. Choose a payment method you can reverse, and stop if none is offered.

Done in that order, the checks fail fast: most fraudulent shops collapse at step one or two, and you rarely need to reach step five.

Frequently Asked Questions

Does the padlock mean a website is safe?+

No. The padlock only confirms the connection is encrypted, and certificates are free and issued within minutes to anyone who controls a domain. Fraudulent sites routinely display a padlock, so it tells you nothing about who runs the site.

How do I check if a site is legit before paying?+

Read the exact domain name character by character, check when the domain was registered, look for a real postal address and specific returns policy, search for independent reviews off-site, and pay with a card or payment platform that offers a dispute process.

How can domain age tell me a shop is fake?+

Fraudulent shops are usually disposable and only weeks old, because they are abandoned before disputes arrive. A domain registered recently on a site claiming years of trading is a direct contradiction you can verify in seconds.

What payment method is safest on an unfamiliar site?+

A credit or debit card, or an established payment platform with buyer protection, because both give you a route to reverse the transaction. Bank transfers to individuals, cryptocurrency and gift cards offer no recovery and are favoured by scammers for that reason.

How much money do people lose to online fraud?+

The FTC reported in March 2025 that US consumers lost more than $12.5 billion to fraud during 2024, a 25% increase on 2023, with investment scams accounting for $5.7 billion of that total.

Ad Space

Try the related free tools

Hands-on utilities from DigiMetrics Hub that go with this guide.

All tools