Short answer: Most scam websites give themselves away within two minutes. If you know what to look at — the URL, the age of the domain, the checkout, the contact info, the reviews, and the way the site talks to you — you can spot a fake before you type a card number. Below are the 12 warning signs that catch the majority of fraudulent shops, phishing pages, and fake service sites in 2026.
The 12 warning signs (in order of how often they catch a scam)
1. The domain is brand new
The single strongest signal is age. Fake shops rarely survive more than a few months before payment processors shut them down, so almost all of them are on domains younger than 90 days. Free WHOIS lookups on who.is or whois.com show the registration date in one click. According to the U.S. Federal Trade Commission’s Consumer Sentinel Data Book, online shopping fraud reports rose past 400,000 filings in 2023, and the majority of the shops named in those reports had been online for under six months. New domain plus real-looking storefront plus deep discounts is a near-perfect scam signature.
2. The URL is almost — but not quite — a familiar brand
Look-alike domains are the workhorse of phishing. amaz0n-support.com, paypa1-security.net, apple-id-verify.co. Read every character of the URL out loud before you click. Watch for extra hyphens, swapped letters, and country endings you would not expect from the real brand. The APWG’s Phishing Activity Trends Report for the fourth quarter of 2023 counted 1,077,501 phishing attacks in a single quarter — the vast majority routed through look-alike domains.
3. Prices are unrealistically low across the entire catalog
One item on sale is normal. A whole store selling brand-name electronics, designer bags, and premium clothing at 70 to 90 percent off is not a warehouse clear-out, it is bait. Real retailers compete on razor-thin margins and cannot sustain those prices. If everything looks too cheap, the plan is to take your money and never ship the product.
4. Only unusual payment methods are accepted
Legitimate shops accept credit cards, PayPal, and mainstream buy-now-pay-later providers because those systems come with buyer protection. Scam sites push you toward wire transfers, cryptocurrency, gift cards, or direct bank transfers — payment types with no dispute rights. A “please pay by Zelle for a 10 percent discount” request at checkout is the scam telling you what it is.
5. The contact page has no real address, phone, or company name
Open the contact page and read it. A real business has a registered address, a working phone number, and a company identifier (VAT number in the EU, company registration number in the UK, EIN in the U.S.). “Contact form only” with a generic Gmail address is a red flag. If an address is given, paste it into Google Maps — scam sites frequently list residential addresses or vacant lots.
6. The design is copied but the details are broken
A slick storefront theme is cheap and easy to install. What is hard to fake is the polish: consistent product photography, working internal links, honest stock counts, and complete category pages. On fake sites you often find empty categories, product photos stolen from other retailers with different lighting and backgrounds, checkout pages in a different language than the rest of the site, and a footer that links to nothing. Click three or four random links in the footer. On a scam, at least one will 404 or loop back to the homepage.
7. There is no SSL certificate — or the certificate does not match the site name
The padlock icon and the https:// prefix are the bare minimum. If a checkout page is served over plain http://, walk away. But note the reverse warning: about 84 percent of phishing sites now use HTTPS according to APWG data, so a padlock alone is not proof of safety. Click the padlock and read the certificate details. The certificate should be issued to the domain you are on, and its “issued to” name should match the visible URL exactly.
8. Reviews only exist on the site itself
Search the shop name on Trustpilot, Reddit, and a directory like webwiki.com. A shop that has been active for a year should have some external mentions — good, bad, or mixed. Zero footprint anywhere except its own on-site testimonials is a strong warning. Also check whether the on-site reviews are suspiciously uniform: five stars, similar sentence length, no photos, no downsides, no dates.
9. The reviews that do exist read like AI-generated praise
Look for tell-tale patterns: repeated phrases across multiple reviews, no misspellings, no specific product details, only glowing sentiment, all posted within a short time window. A legitimate shop with real customers has a mix of ratings, complaints about shipping speed, mentions of specific colors or sizes, and reviews spread across months.
10. Urgency and scarcity are everywhere
Countdown timers on every product, “only 2 left” banners that never change, pop-ups every fifteen seconds saying someone in a nearby city just bought the item. These pressure tactics exist to stop you from thinking. Reputable retailers use scarcity signals sparingly and honestly. Wall-to-wall urgency is a psychological red flag, not a marketing choice.
11. Grammar and translation errors in headers and legal pages
Product descriptions can be sloppy on any site — small merchants often write them fast. But the header navigation, the checkout labels, and the terms and conditions page are usually copy-pasted from templates. Awkward English in these places suggests a template translated by machine for a market it was not designed for. A real German retailer will not have “Basket Cart Payment Proceed” in the checkout.
12. The email confirmation never arrives — or arrives from a random address
After the checkout, watch what happens. A real shop sends a confirmation within minutes, from an address on its own domain (or****@******me.com), with an order number, a shipping estimate, and a receipt. A scam sends nothing at all, or a bland confirmation from a Gmail or Outlook address, or an email from a completely different domain than the site. If this happens, contact your card issuer immediately and dispute the charge before shipping supposedly begins.
How to run these checks in under two minutes
You do not need to run all twelve on every visit. A fast three-step check catches most fakes:
- URL and age. Read the URL character by character. Look up the domain age on a WHOIS site. Under 90 days plus deep discounts is enough to walk away.
- Payment options. If checkout will not accept a credit card or a mainstream processor with chargeback rights, do not proceed.
- External footprint. Search the brand name plus the word “review” or “scam” on Google. Cross-check on Trustpilot and a directory like webwiki.com. Zero external traces is a warning; several complaints on independent sites is a decision.
The full 12-point list is worth running when the stakes are higher — a large purchase, a health product, a service that will hold personal data, or anything asking for banking credentials.
Where scam sites usually appear
Understanding the delivery channel makes the warning signs easier to trust. According to the FTC’s 2023 fraud data, the most common entry points for online shopping scams are ads on social media platforms (particularly Instagram and Facebook Marketplace), sponsored search results, and unsolicited text messages that link to a fake tracking or payment page. The site itself may look convincing, but the way you arrived at it is often the first clue. A shop you found because it advertised to you within the last hour deserves more scrutiny than a shop you have used before.
What to do if you already entered your details
Speed matters. Contact your card issuer or bank on the phone number on the back of your card and request an immediate block plus a chargeback. Change the password of any account that reuses the password you typed on the scam site. Enable two-factor authentication on your email account, because scammers frequently follow up with phishing attempts that rely on knowing you just made a purchase. Report the site to your country’s consumer protection body — the FTC in the U.S. (reportfraud.ftc.gov), Action Fraud in the UK, or the European Consumer Centres Network across the EU. Reporting does not always recover money, but it feeds the takedown pipelines that shorten a scam site’s lifespan for the next visitor.
Related reading on webwiki.com
Two companion guides go deeper on the fundamentals: How to Tell If a Website Is Trustworthy: The Complete Checklist covers the broader trust framework, and The Most Common Online Scams in 2026 and How to Avoid Them maps the delivery channels these fake sites use. For a walked-through example of applying these checks to a real, high-volume site, see Is Temu Legit? Full Review and Safety Check (2026). If you want a specific store checked, the review index on webwiki.com lists user reports on hundreds of thousands of sites.
FAQ
Is the padlock icon enough to trust a website?
No. The padlock only means the connection to the site is encrypted. It says nothing about who owns the site or whether they intend to fulfill your order. Around 84 percent of phishing sites in 2024 used valid SSL certificates.
How new is too new for a shop domain?
Under 90 days is a strong warning signal for a first-time buyer, especially combined with heavy discounts. Under one year still warrants a full check. Established retailers you already know are of course exempt.
Can a scam site have real Trustpilot reviews?
Yes, though the pattern is usually visible: a burst of five-star reviews in the first weeks, all with generic praise, and then a wave of one-star complaints as customers realize goods will not arrive. Sort reviews by “newest” and read the recent ones before you decide.
What if the site asks for my ID or a photo of my card?
Never send either. Legitimate merchants do not need a photo of your credit card. If a purchase is flagged for verification, real payment processors run their own checks through the card issuer — the merchant never sees your card image.
Are big marketplaces safe by default?
The marketplace platform (eBay, Amazon, Facebook Marketplace, Etsy) may be legitimate while individual sellers on it are not. The same 12 warning signs apply to the seller’s profile: age of the account, external reviews, contact information, and payment method requested.
Sources and further reading
Federal Trade Commission — Consumer Sentinel Network Data Book 2023, published February 2024.
Anti-Phishing Working Group (APWG) — Phishing Activity Trends Report, Q4 2023, published February 2024.
UK National Cyber Security Centre — Shopping and paying safely online guidance, updated 2024.
Europol Internet Organised Crime Threat Assessment (IOCTA) 2024.
Read next: Is Temu Legit? Full Review, Ratings and Safety Check (2026). A closer look at is temu legit.
