A fake website only needs you to move fast — enter a card number, hit checkout, and it’s gone before you’ve had a chance to think. The good news is that fake storefronts almost always leave the same handful of tells, and checking for them takes less time than filling out the checkout form itself. Here’s what to look for before you buy, and what to do if you’ve already paid one.
Why this is worth ten minutes of your attention
Fake storefronts have gotten easier to build and harder to eyeball at a glance. A convincing template, a cheap domain, and a payment processor are enough to spin up something that looks like a real store — sometimes for a weekend, sometimes long enough to collect a wave of orders that never ship. You don’t need to become suspicious of every store you’ve never heard of. You need a fast checklist you run before you type in a card number, the same way you’d glance at an expiration date before eating something. That’s what this guide is.
Step-by-step: checking a store before you buy
1. Read the URL character by character
This is the single fastest tell, and the one most people skip because they’re moving fast. Before you do anything else, look — really look — at the address bar:
- Lookalike domains. A single swapped letter (
amaz0n.com), an inserted word (amazon-deals.com), or an extra hyphen that a real brand wouldn’t use. - Misspellings of a known brand. Scammers deliberately buy near-miss spellings of popular retailers, betting you’ll skim past the typo.
- Unusual or unfamiliar top-level domains. A brand you associate with
.comsuddenly showing up on an unfamiliar ending is worth a second look — not automatically fake, but a reason to slow down.
If a link arrived by text, email, or a social ad, this step matters even more — those are the channels scammers use most, precisely because the fake link is easy to miss on a small screen.
2. Don’t stop at the padlock — HTTPS isn’t a trust signal
Here’s the myth worth correcting directly: a padlock icon and “https://” do not mean a site is legitimate. They mean the connection between your browser and the site is encrypted, so a stranger on the same network can’t easily read what you’re sending. That’s it. It says nothing about who’s actually running the store, whether they’ll ship anything, or what they do with your card details once they have them.
Free, automated certificates take minutes to set up and cost nothing, so scam sites use HTTPS just as routinely as real ones do now. Treat the padlock as a bare-minimum expectation — the absence of it is a red flag, but its presence proves nothing on its own. This single correction stops more people from getting scammed than almost anything else on this list, because “it had the little lock, so I figured it was fine” is one of the most common things people say after the fact.
3. Search for the brand’s real-world reputation — away from the site itself
A store’s own “About Us” page and its own five-star testimonials are the last place to verify anything, for the same reason you wouldn’t take a stranger’s word for their own trustworthiness. Open a new tab and check somewhere the store doesn’t control:
- Search the brand name plus “reviews,” “scam,” or “complaints.” A pattern of recent complaints about orders never arriving, or a total absence of any independent mentions at all for a store claiming to be established, both matter.
- Look for a real, checkable physical address and contact information — not just a contact form that goes nowhere. A working phone number or a specific address you can independently verify is a meaningfully different signal than a P.O. box or none at all.
- Check whether the domain’s age matches its claims, if you have access to a lookup tool — a site presenting itself as a long-standing brand but registered only weeks ago is a clear mismatch.
- Look for consistency. Genuine stores have branding, pricing, and product photography that feel like they came from one place. Fake storefronts are frequently stitched together from scraped photos and mismatched fonts — inconsistency across pages is a tell worth trusting.
4. Be suspicious of impossible deals and manufactured urgency
A discount that sits far outside what the real market supports for that product is worth pausing on, especially when it’s paired with pressure tactics: a countdown timer ticking down to a deadline, a banner insisting only two are left in stock, or a popup claiming someone else just bought the item. These are designed to short-circuit exactly the checking you’re doing right now — to get you to the “buy” button before you think.
Real sales exist. The distinction isn’t “any discount is suspicious” — it’s whether the size of the discount, combined with urgency tactics and a store you’ve never heard of, is doing more work to rush you than to actually sell you something.
5. Check for a real returns and refund policy
A legitimate store has a clear, specific returns and refund policy that tells you exactly how to send something back and get your money back — because they expect to still be operating when you need it. A missing policy, one that’s vague to the point of being unenforceable, or one that only appears after you’ve already paid, is a sign there’s no real operation behind the storefront prepared to honor it.
6. Pay with a method that can fight back for you
This is the step that protects you even if everything above looked fine and you were still wrong. Use a credit card, or a payment method with built-in fraud protection and dispute rights, for any store you’re not already confident in. These give you a real path to get your money back if the order never shows up or the store turns out to be fake.
The clearest red flag of all: if an unfamiliar store’s checkout only offers direct bank transfer, cryptocurrency, or gift cards — and no card option — treat that as close to a confirmed warning sign on its own. Legitimate retailers want your business badly enough to accept the payment methods that come with buyer protection. Scammers avoid them for the same reason: those methods are hard to claw money back through, and gift cards and crypto payments are close to untraceable once sent.
Surfshark
A VPN like this encrypts your connection on public or untrusted Wi-Fi and adds a layer of general browsing privacy — genuinely useful hygiene, but it's a complement to these checks, not a substitute. It can't tell you whether the store at the other end is real.
What to do if you already paid a fake site
If you’ve already gone through checkout and something feels off — or you’ve since realized the store was fake — act quickly and in this order:
- Contact your card issuer or payment provider immediately. Explain that the merchant appears fraudulent and ask to dispute the charge. This is exactly the situation card protections and chargebacks exist for, and the sooner you report it, the better your odds of getting the money back.
- Change the password you used on that site — everywhere you reused it. If the fake store captured your login details, assume they’re compromised and update that password on every account sharing it, starting with anything financial or email-related.
- Watch for follow-up phishing. Fake stores often reuse or resell the contact information you handed over at checkout, so expect a possible wave of “your order has a problem” emails or texts afterward. Don’t click through them — go directly to your card issuer’s app or site instead.
- Report it, if you’re able to, to your card issuer, the platform that hosted the ad or link that led you there, and a consumer-protection or fraud-reporting body in your country. It won’t undo your loss, but it helps flag the site for the next person.
Common mistakes to avoid
- Trusting the padlock alone. HTTPS confirms encryption, not legitimacy. Scam sites have it too.
- Only reading the store’s own reviews. Testimonials on the site itself prove nothing — search for independent mentions elsewhere.
- Getting swept up by a countdown timer. Urgency tactics are designed to stop you from doing the checking that would catch the scam.
- Paying by bank transfer, crypto, or gift card for an unfamiliar store. If that’s the only option, that alone is reason enough to stop.
- Reusing a password on a site you weren’t sure about. If it turns out to be fake, that password is now exposed everywhere else you used it.
The bottom line
Spotting a fake website comes down to a handful of habits: read the URL like you mean it, remember that the padlock isn’t a verdict, check the brand’s reputation somewhere it doesn’t control, be skeptical of deals that feel engineered to rush you, confirm there’s a real returns policy, and pay with a method that can dispute a charge. None of that takes long, and it’s the difference between a good deal and a story that starts with “I should have looked closer.”
This guide pairs well with how to spot fake reviews, the honest read on whether Temu is safe to shop, and how AI has changed phishing scams. For the full toolkit — password managers, breach monitoring, and browsing privacy — see the Privacy & Security Kit hub and the Digital Lockdown Kit.