Every day people land on an unfamiliar shop, service, or download page and ask the same question: can I trust this? It is a good instinct. Losses to online shopping fraud and fake stores run into the billions each year, and the Federal Trade Commission logged more than 2.6 million fraud reports from consumers in a single recent year. The good news is that legitimate and fraudulent sites tend to differ in predictable ways, and you can learn to read those differences in a couple of minutes.
The trust checklist at a glance
Use this as a fast scan. If a site clears most of these, it is probably fine. If it fails several, treat it with caution.
| Signal | Trust sign | Warning sign |
|---|---|---|
| Connection | Valid HTTPS, no certificate warnings | Browser security warning, http only on a checkout |
| Identity | Named company, address, working contact | No contact details, only a web form |
| Domain age | Registered months or years ago | Registered days ago for an “established” brand |
| Reviews | Consistent feedback across independent platforms | Only glowing reviews, all posted the same week |
| Pricing | Prices in line with the market | 90 percent off everything, always ending soon |
| Payment | Cards, PayPal, buyer-protected methods | Only bank transfer, crypto, or gift cards |
| Language | Clean, professional copy | Repeated spelling and grammar errors |
1. Start with the connection, but do not stop there
Check that the address begins with https and that your browser shows no certificate warning. HTTPS means the traffic between you and the site is encrypted, which matters on any page where you type a password or card number. The common myth is that the padlock means a site is safe. It does not. A padlock only confirms the connection is encrypted, not that the business behind it is honest. Free certificates are easy to obtain, and a large share of phishing pages now use HTTPS too. Treat the padlock as the minimum bar, then keep checking.
2. Look for a real identity
Trustworthy businesses are easy to identify. Look for a company name, a physical address, a phone number or a monitored support channel, and in many regions a legal imprint or company registration number. Open the contact and about pages and ask whether a real organisation stands behind the site. A store that sells physical goods but hides who it is, where it is based, and how to reach it is a meaningful red flag. Cross-check the business name in a search engine and in a website directory such as Webwiki, where entries collect descriptions, categories, and user feedback that help you place an unfamiliar brand.
3. Check how old the domain is
A brand that claims to have served customers for years should not be running on a domain registered last week. You can look up a domain’s registration date through any WHOIS lookup. A very new domain is not automatically bad, since every legitimate site starts somewhere, but a new domain combined with deep discounts and a hard sell is a classic fake-shop pattern. Age is context, not a verdict.
4. Read reviews the smart way
Reviews are useful only when you read them critically. One page of five-star ratings on the seller’s own site proves little. Look for feedback across independent platforms, and pay attention to the shape of it: a healthy business has a spread of ratings and a few complaints it has answered, while a fabricated profile often shows a burst of near-identical praise posted within a short window. Vague reviews that never mention a specific product, repeated phrasing, and reviewer accounts with no other history are all signs of manipulation.
5. Sanity-check the prices and the pressure
If a site offers the season’s most wanted product at a fraction of everyone else’s price, ask why. Fake shops rely on two levers: prices too good to refuse and urgency that stops you thinking. Countdown timers, “only two left”, and “offer ends in ten minutes” are designed to rush you past your own judgement. Legitimate retailers run sales too, but they rarely need to manufacture panic to close a sale.
6. Notice the payment options
How a site wants to be paid is one of the strongest tells. Cards and buyer-protected wallets give you a route to a refund if something goes wrong. A seller that insists on bank transfer, cryptocurrency, or gift cards is asking for methods that are almost impossible to reverse. If the only way to pay removes your protection, walk away.
7. Read the fine print and the copy
Skim the returns policy, shipping terms, and privacy policy. Legitimate businesses publish these because they have to and because customers expect them. Missing or copy-pasted policies, no returns address, and a privacy policy that says nothing specific are all warning signs. Persistent spelling and grammar mistakes on a supposedly professional store are another, since real brands proofread the pages that ask for your money.
A note on judgement over checklists
Checklists are a starting point, not a substitute for judgement. Sophisticated scams can pass several of these tests, and a perfectly honest small business might fail one or two through inexperience rather than intent. The point is the pattern. When multiple signals line up against a site, trust that picture. When you are unsure, the safest move is simple: do not enter payment details, and buy from a source you already know. If a purchase feels wrong after you have paid, contact your card provider quickly, since fast reporting is what usually gets money back.
Related reading: learn the specific tricks fraudsters use in our guide to the most common online scams in 2026.
Frequently asked questions
Does the padlock icon mean a website is safe?
No. The padlock only means the connection is encrypted with HTTPS. Many fraudulent sites use HTTPS as well. Treat it as a basic requirement, then check identity, reviews, and payment options.
How can I check if a website is legit in under two minutes?
Confirm HTTPS, open the contact and about pages to see who runs it, do a quick WHOIS check on the domain age, search the brand name for independent reviews, and glance at the payment options. If those line up, it is probably fine.
Is a brand-new website automatically a scam?
No. Every legitimate site is new at some point. A new domain becomes a concern mainly when it is paired with other red flags such as extreme discounts, urgency tactics, or irreversible payment methods.
What should I do if I already paid on a site I now suspect?
Contact your bank or card provider as soon as possible to ask about a chargeback, change any reused passwords, and watch your statements. The sooner you report it, the better your chances of recovering the money.
Sources and further reading
Federal Trade Commission, Consumer Sentinel Network fraud reports. Anti-Phishing Working Group data on HTTPS use in phishing. General guidance from national consumer-protection and cybersecurity agencies on spotting fake online shops.
Read next: The Most Common Online Scams in 2026 and How to Avoid Them. A closer look at most common online scams.
