Help · Spot fake sites

How to spot a fake website.

A few quick checks separate most fraudulent sites from the real thing — before you enter a password or card number.

1. Check the full domain

Read left-to-right starting from the last dot. A site at 'support.brand-secure.com' is on 'brand-secure.com', not on 'brand.com'. The bit immediately before the TLD (.com / .co.uk) is the real owner.

2. Look for unusual characters

Cyrillic and Greek letters can imitate Latin ones. If a domain looks right but the browser address bar shows it as 'xn--' something, it's a homoglyph. Hover over the address bar to see the raw form.

3. Mistrust pressure tactics

'Your account will be closed in 24 hours' is a fraud signal, not a service notice. Real businesses don't operate that way for security-sensitive actions, and never gate account access behind countdown timers.

4. Watch the payment method

Requests to pay in gift cards, crypto, or via personal bank transfer for what should be a standard merchant purchase are almost always fraudulent. Legitimate retailers accept card payments through PCI-compliant processors.

5. Verify out-of-band

If you're unsure, navigate to the brand's site by typing the URL or using a bookmark — never via a link from the suspicious message. For banks, call the number on the back of your card; never call a number provided in the message.

6. Check WHOIS and SSL

A brand-new domain (registered within days) with a free SSL certificate, claiming to represent a 50-year-old company, is suspect. Tools like who.is and crt.sh show registration and certificate history.

7. Search the URL

Search the domain plus 'scam' or 'review' — fraud victims often post about active scams quickly on Reddit, Trustpilot, and forum sites. Absence of any results for a 'global brand' is itself a red flag.

8. Inspect the visuals

Low-resolution logos, mismatched fonts, broken stock photos, and grammatical errors in product copy are all reliable indicators. Modern scams are slicker than they used to be, but the long-tail still cuts corners.

9. Test a 'fake' password

On a suspected phishing page, enter a deliberately wrong password. A real login form will reject it. A phishing page often accepts anything and proceeds to the next step.

10. When in doubt, report it

Submit the URL to FraudRadar and to the impersonated brand. A single early report often prevents many later victims, and feeds the pattern detection that surfaces the next wave of clones.

Frequently asked questions

Does a padlock icon mean a site is safe?
No. The padlock only confirms the connection is encrypted, not that the site is legitimate. Free SSL certificates make padlocks trivial for any scammer to obtain.
Are .com sites safer than other TLDs?
Not inherently. Many scams now use .shop, .store, .top, .xyz, .vip, and country-code TLDs because they're cheap and have lighter abuse enforcement — but .com is also widely abused.
What about review sites?
Reviews can be useful but are often manipulated. Look at the reviewer profile age, posting pattern, and whether reviews mention specific products or just generic praise. Trustpilot, Sitejabber, and Reddit are usually more reliable than reviews hosted on the site itself.