How to spot a safe website in seconds

A safe website shows three things before you enter passwords, credit card numbers, or personal details: a padlock icon in the address bar, a URL that starts with https:// (not http://), and a domain name that matches the organization you think you're visiting. If any of these is missing, stop and do not enter sensitive information. The padlock means your connection is encrypted — data traveling between your browser and the site cannot be read by someone on the same network. The https protocol is the standard for any site handling money or login credentials. The matching domain name prevents you from accidentally landing on a fake site designed to look like the real one.

Beyond those three checks, you can verify a website's legitimacy by looking up the organization's phone number independently and calling to confirm the site is theirs, checking whether the site has a physical address and privacy policy posted, and seeing whether the domain registration is recent or has existed for years. Newly registered domains are not automatically dangerous, but combined with other red flags — poor spelling, generic stock photos, pressure to act fast — they suggest the site may not be what it claims.

Key Takeaways

  • Always check for the padlock icon and https:// in the address bar before entering passwords or payment information.
  • Verify the domain name matches the organization you intend to visit, because fake sites often use similar-sounding URLs.
  • Look for a physical address and privacy policy on the site; legitimate organizations post both.
  • Call the organization directly using a phone number you find independently to confirm the website is theirs.
  • Be cautious of sites with poor spelling, urgent language, or requests to download files before you can proceed.

What the padlock and https mean

The padlock icon and https protocol work together to encrypt your connection. When you see both, the data you send — your login, your credit card number, your address — is scrambled in a way that only the website's server can unscramble. Someone monitoring your network traffic, such as on public Wi-Fi at a coffee shop, cannot read what you type.

The padlock appears in different places depending on your browser. In Chrome, Firefox, and Edge, it sits to the left of the address bar. In Safari, you tap the address bar to see it. Clicking the padlock shows you details about the certificate — the digital proof that the site is who it claims to be. You do not need to understand the certificate details; the presence of the padlock is the signal that matters.

A site without https is not automatically malicious, but it is not safe for sensitive information. Many news sites and blogs use http because they do not collect passwords or payments. The rule is simple: if a site asks for a password, credit card, or personal details, it must have https and a padlock. If it does not, leave the site.

How to spot a fake domain name

Scammers register domain names that look similar to legitimate ones, counting on you to misread them in a hurry. Instead of paypa1.com (with the number 1), they register paypa1.com. Instead of amaz0n.com, they use amaz0n.com. The difference is tiny but the site is fake. Before you enter information, read the domain name character by character.

The safest method is to navigate to the site by searching for the organization's name in a search engine, rather than clicking a link in an email or text message. When you search, you are more likely to land on the real site. If you receive an email claiming to be from your bank or a service you use, do not click the link in the email. Instead, open a new browser tab, search for the organization, and navigate to their site independently. Then log in and check your account.

Legitimate organizations also own multiple domain variations to protect their brand. Amazon owns amazon.com, amazon.co.uk, amazon.ca, and others. If you are unsure which domain is correct, search for the organization's official site or call their customer service number — one you find by searching, not from the email.

What to look for in the site's details

Scroll to the bottom of a website and look for a privacy policy, terms of service, and a physical mailing address. Legitimate businesses post these because they are required by law in most countries. If the footer is empty or contains only a copyright notice, that is a warning sign. Click on the privacy policy and read the first paragraph; it should explain what information the site collects and how it uses it.

A physical address is harder to fake than a website. If a site claims to be a U.S. company but lists only a P.O. box or no address at all, search for the company name plus "address" or "headquarters" to verify. Scam sites often claim to be based in one country while actually operating from another. A real address you can verify independently is a strong signal of legitimacy.

Check whether the site has contact information beyond a contact form. A phone number, email address, or live chat option suggests the organization is willing to be reached. Scam sites often hide behind contact forms that go nowhere. If you have doubts, call the organization using a phone number you find by searching — not a number listed on the suspicious site.

How to check when a domain was registered

You can look up when a domain was registered using a WHOIS search tool. Visit whois.com or whois.net, enter the domain name, and you will see the registration date and expiration date. A domain registered last week is not automatically fake, but it is worth investigating further, especially if the site claims to be an established company.

Scammers often register domains shortly before launching a phishing campaign, then abandon them after a few weeks. If a site claims to be a bank, insurance company, or major retailer, the domain should have been registered years ago. If it was registered recently and the site looks professional, search for news articles or reviews about the company to see whether it is real.

Legitimate organizations sometimes register new domains for specific purposes — a new product line, a regional office, or a marketing campaign. But they also maintain a privacy policy, contact information, and a connection to their main website. A newly registered domain with none of these is a red flag.

Red flags that suggest a site is not legitimate

Poor spelling and grammar throughout a site is a common sign of a scam. Legitimate organizations hire people to write and review their content. If you see repeated misspellings, awkward phrasing, or sentences that do not make sense, the site may not be what it claims. This is especially true for sites claiming to represent banks, government agencies, or major companies — these organizations have professional standards for their websites.

Urgent language and pressure to act fast are also warning signs. Phrases like "verify your account now," "confirm your information immediately," or "your access will expire in 24 hours" are common in phishing emails and fake sites. Legitimate organizations do not pressure you to enter sensitive information on a deadline. If a site is pushing you to act fast, do not comply. Instead, contact the organization directly using a phone number you find independently.

Requests to download files, install software, or enable plugins before you can use the site are another red flag. Legitimate banks and services do not ask you to download anything to log in. If a site says you need to install something to proceed, close the browser and contact the organization by phone.

How to verify a site belongs to the organization it claims

The most reliable way to confirm a website is legitimate is to call the organization directly. Use a phone number you find by searching the organization's name, not a number listed on the website you are investigating. Tell the person who answers that you received an email or found a website and ask them to confirm the URL is correct. They can tell you immediately whether the site is theirs.

You can also check whether the organization's official social media accounts link to the site. Visit the organization's Facebook, Twitter, or LinkedIn page and look for a link to their website. If the suspicious site is not linked from their official accounts, that is a warning sign. Be careful, though — scammers sometimes create fake social media accounts that look similar to the real ones. Verify the account is official by checking the number of followers, the date it was created, and whether it has a verification badge.

Some organizations publish a list of authorized resellers or partners on their website. If you are buying from a third-party seller, check whether they appear on that list. For example, if you are buying software, check the software maker's website to see whether the seller is authorized. This prevents you from accidentally buying from a counterfeit seller.

What to do if you think a site is fake

If you suspect a website is a scam, do not enter any information. Close the browser tab and do not return to the site. If you received an email directing you to the site, report it as phishing to your email provider. In Gmail, click the three dots next to the email and select "Report phishing." In Outlook, click the "Junk" button and select "Phishing." This helps your email provider block similar emails in the future.

If you already entered information on a fake site, contact the organization the site was impersonating. Tell them what information you provided and when. For credit card information, contact your bank or credit card company immediately and ask them to monitor your account for fraudulent charges. For passwords, change the password on the real site and on any other sites where you use the same password. If the fake site was impersonating a government agency, report it to the Federal Trade Commission at reportfraud.ftc.gov.

Frequently Asked Questions

Is a website with https always safe?

https means your connection is encrypted, but it does not mean the site is legitimate. A fake site can have https and a padlock. Always check the domain name and look for contact information and a privacy policy. https protects your data from being read in transit, but it does not protect you from entering information into a fake site.

What does the certificate information in the padlock mean?

The certificate shows the organization name the domain is registered to and the certificate authority that issued it. If the organization name does not match who you think you are visiting, that is a red flag. You do not need to understand all the technical details — the padlock's presence is what matters most.

Can I trust a site just because it has good reviews online?

Scammers sometimes post fake reviews or create fake review sites. Check reviews on established platforms like Google, Trustpilot, or the Better Business Bureau rather than reviews posted on the site itself. Search for the site name plus "scam" to see whether others have reported problems. If you find multiple complaints from different people, be cautious.

What should I do if a site asks me to disable my browser's security warnings?

Do not disable security warnings under any circumstances. If your browser is warning you about a site, there is a reason. Close the site and do not return. Legitimate organizations never ask you to bypass your browser's safety features.

How can I tell if a site is using my location or camera without permission?

Your browser will ask for permission before a site can access your location, camera, or microphone. A notification will appear at the top of the page asking "Allow" or "Block." Always click "Block" unless you are certain the site needs access and you trust it. Legitimate sites explain why they need access before asking. If a site tries to access these features without asking, close it immediately.