How to Tell if a Website is Safe

Scam sites look just like real ones. Run these quick checks — on the domain, the padlock and the behaviour — before you trust any site with your money or data.

Key takeaways

  • The padlock means encrypted, not honest — scam sites have padlocks too.
  • The domain name is the real test: read it carefully for look-alikes and typos.
  • Pressure, prices too good to be true and odd payment methods are red flags.
  • Never enter card details on a site you reached from an unexpected link.

Fake and malicious websites are designed to look exactly like the real thing, so "it looks professional" is not proof of safety. The good news is that a handful of quick checks — the kind recommended by the UK's National Cyber Security Centre and consumer-protection agencies like the US FTC — will catch the large majority of dangerous sites. This guide gives you a fast routine you can run on any unfamiliar site before you trust it with your money or data.

The 30-second safety check

Before entering anything, glance at four things: the full domain name in the address bar (is it really the company you expect?), whether it uses HTTPS, how you arrived there (a link in an unexpected email or text is a warning), and whether the site is pressuring you to act fast. If all four look fine, you are probably safe; if any feels off, slow down and dig deeper before you proceed.

HTTPS and the padlock — what it really tells you

A padlock and https:// mean your connection to the site is encrypted, so others cannot easily snoop on what you send. That is good — but it does not mean the site is trustworthy. Encryption certificates are free and instant, so scammers routinely add a padlock to look legitimate. Treat the absence of HTTPS on a page asking for a password or payment as a clear stop sign, but never treat the padlock alone as a seal of approval.

The padlock is the most misunderstood security signal on the web. The vast majority of phishing sites now use HTTPS. It protects the connection, not your wallet — judge the site by its domain and behaviour, not its padlock.

Read the URL carefully

The domain is where scams hide. Check the part right before the first single slash — that is the real domain. Watch for look-alikes and typos (paypa1.com, amaz0n-support.com), extra words bolted on (apple.com.secure-login.net is not Apple — the real domain is secure-login.net), and unusual endings. When in doubt, do not click the link at all: open a new tab and type the company's address yourself, or search for it.

Looks likeReal domain isVerdict
apple.com.account-verify.netaccount-verify.netNot Apple
secure-paypal.comsecure-paypal.comNot PayPal
amazon.co.ukamazon.co.ukGenuine

Warning signs of a scam site

Beyond the URL, watch for: prices far below everyone else (the classic too-good-to-be-true lure), heavy countdown timers and pressure to buy now, poor spelling and grammar, no real contact details or address, requests to pay by bank transfer, gift cards or cryptocurrency (which offer no buyer protection), and a flood of pop-ups or fake virus warnings. Any single one of these should make you pause; several together mean leave.

Before you buy or enter card details

For shopping, do a few extra checks. Search the store's name plus "scam" or "reviews" and read what comes up. Look for a genuine returns and contact policy. Prefer paying with a credit card or a protected payment service rather than a direct bank transfer, because they offer recourse if something goes wrong. And be sceptical of glowing reviews on the site itself — check independent sources too, as covered in our guide on spotting fake reviews.

Free tools that help

A few free services give a second opinion. Google Safe Browsing powers the red warning pages in Chrome and other browsers; if you see one, heed it. You can paste a suspicious link into a reputable URL or file scanner before clicking. And your browser's own phishing and malware protection (on by default in Chrome, Edge, Safari and Firefox) should stay enabled. These complement the manual checks above rather than replacing your judgement.

If you are still unsure

When something feels wrong, the safest move is simply not to proceed. Close the tab, and if the site came from an email or text, treat it as likely phishing and report it to your email provider. If you have already entered a password, change it immediately (and anywhere you reused it), and if you have entered card details, contact your bank. Trusting your instinct and walking away costs nothing; recovering from a scam costs a great deal more.

Frequently asked questions

Does the padlock icon mean a website is safe?

No. The padlock and HTTPS mean your connection to the site is encrypted, not that the site is honest. Security certificates are free, so scam and phishing sites use them too. Judge a site by its domain name and behaviour, not by the padlock alone.

How can I check if a website is legitimate?

Read the full domain name carefully for look-alikes and typos, confirm it uses HTTPS, be wary of how you arrived (unexpected links are risky), and search the site's name with the word 'scam' or 'reviews'. Several warning signs together mean you should leave.

What are the warning signs of a scam website?

Prices that seem too good to be true, high-pressure countdown timers, poor spelling and grammar, no genuine contact details, requests to pay by bank transfer, gift cards or cryptocurrency, and aggressive pop-ups or fake virus alerts. Any of these should make you pause.

How do I spot a fake URL?

Look at the domain immediately before the first single slash — that is the real site. Scammers add the real brand as a subdomain or extra word (apple.com.secure-login.net is not Apple). Watch for character swaps like a zero for an 'o' or a one for an 'l'.

What should I do if I entered details on a fake site?

Act quickly. If you entered a password, change it immediately and anywhere you reused it, and enable two-factor authentication. If you entered card or bank details, contact your bank or card provider to flag the risk and watch for unauthorised transactions.

Sources & further reading

This guide is independently produced. We reference primary documentation from device makers and security authorities (NIST, CISA, FTC). Tudug is reader-supported and may earn from ads.

Guide

Spot a Phishing Email

Catch the scams that lead to fake sites.

Open →
Guide

Spot Fake Reviews

Tell genuine reviews from planted ones.

Open →
Guide

Protect Your Privacy Online

Reduce what you expose on the web.

Open →