How to identify a fake website: 8 red flags anyone can spot

    Not every scam site looks amateur. Modern kits clone real stores pixel-perfectly, host on fast CDNs and even display fake trust badges. These eight checks are designed to catch what polished design cannot hide: infrastructure, behaviour and provenance.

    6 min readUpdated July 6, 2026

    1. Inspect the URL carefully

    Look-alike domains are the oldest trick and still the most effective. Check for:

    • Misspellings and homoglyphs. arnazon.com (rn instead of m), paypa1.com (1 instead of l), or Unicode homoglyphs that look identical in the browser bar.
    • Extra subdomains or paths. secure-paypal.com.signin.ru: the registered domain is the rightmost pair (signin.ru), not the brand name.
    • Suspicious TLDs. Brands rarely use .tk, .ml, .top or .store for their primary operations.

    When in doubt, type the brand's known domain manually instead of clicking a link.

    2. Verify HTTPS and certificate details

    HTTPS is no longer a trust signal: every phishing kit has it. What matters is who issued the certificate and when:

    • Click the padlock icon in your browser bar and view the certificate. A legitimate enterprise usually uses a well-known CA (DigiCert, Sectigo, GlobalSign) with an organisation-validated (OV) or extended-validation (EV) cert.
    • A brand-new Let's Encrypt certificate issued yesterday to a supposed bank is a red flag.
    • Check the certificate's subject alternative names (SANs). If the cert covers fifty unrelated domains, it may be from a shared hosting provider used by scammers.

    3. Review contact and company information

    Legitimate businesses want to be found. Scam sites want the opposite:

    • No physical address or a fake one (search it on Google Maps: many scam sites list residential addresses or demolished buildings).
    • Generic email only. A support address at @gmail.com or @proton.me for a supposed corporation is a hard stop.
    • Missing company registration number. In the EU, a valid VAT or trade-register number is legally required and easily verifiable.
    • No phone number or a number that goes to voicemail in a different country.

    4. Search for reviews and reputation

    Before buying from an unfamiliar store, search the domain plus one of these keywords:

    • site:reddit.com [domain] scam
    • site:trustpilot.com [domain]
    • [domain] review fraud

    Be wary of sites with only five-star reviews posted within the last week, or reviews that repeat the same phrases. Many scam stores populate their own review sections with LLM-generated text.

    5. Inspect images, copy and design

    Cloned stores reuse assets from the original brand, but clones are never perfect:

    • Right-click an image and search with Google Lens. If it appears on a dozen unrelated sites, it is stock photography, not original product shots.
    • Copy a product description into a search engine. Identical text across multiple domains is a hallmark of template scam shops.
    • Check the footer copyright year. A site claiming to be established in 2015 with a footer saying "© 2022" has not been maintained: or is a recently deployed kit.

    6. Scrutinise payment methods

    Payment preference is one of the strongest signals:

    • Bank transfer only. Scammers prefer irreversible transfers (SEPA, wire, crypto) because chargebacks are impossible.
    • PayPal "Friends & Family". A request to use the non-goods option removes buyer protection: always refuse.
    • Only crypto. A store that accepts only Bitcoin or Ethereum and offers a "discount" for crypto is almost always fraudulent.
    • Fake checkout flows. Some kits simulate a checkout page but never actually process a card. If you enter fake card details and the order "succeeds", the site is a data-harvesting frontend.

    7. Verify social proof and trust badges

    Trust badges are copy-paste decorations on most scam sites:

    • Hover over a "Norton Secured" or "McAfee SECURE" badge. If it is not clickable, or clicks to a generic homepage instead of a verification page, it is fake.
    • Check the social media icons. On many scam sites they are static images that do not link anywhere, or they link to the real brand's account (which has no posts about the promotion).
    • Live-chat widgets that repeat the same scripted greeting are often bots, not support staff.

    8. Use Blackwall's Website Scam Check

    If a site passes the first seven checks but still feels off, paste the URL into Blackwall's scam check or submit a report. The AI Triage engine scores the domain for phishing, malware and fraud indicators in under a minute, using signals you cannot see from the surface:

    • Domain age, registrar reputation and nameserver history
    • Hosting provider abuse history and ASN reputation
    • Blocklist status across Google Safe Browsing, PhishTank and SURBL
    • SSL certificate anomalies and redirect chains

    A low score does not guarantee safety, but a high score is a strong signal to stop and report.

    Have a URL to report right now?

    Blackwall triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.

    Run a website scam check

    Frequently asked questions

    What is the fastest way to check if a website is fake?

    Run the URL through Blackwall's Website Scam Check: it combines WHOIS age, TLS analysis, blocklist status and DOM heuristics into a single score in seconds.

    Is HTTPS a guarantee that a site is safe?

    No. HTTPS only means the connection is encrypted, not that the site is trustworthy. Most phishing sites now use free Let's Encrypt certificates.

    What are the most-abused TLDs for fake websites?

    .tk, .ml, .gq, .cf, .ga, .top, .rest, .zip, .xyz see disproportionate fake-site registration. Not automatically fake, but weigh accordingly.

    How do I check a website's age?

    Use whois.com, rdap.org or Blackwall's Website Scam Check. Domains younger than 90 days selling luxury goods at deep discounts are the highest-risk category.

    What should I do if I already entered payment info on a fake site?

    Contact your bank or card issuer to block the card, file a chargeback within 60 days, and change any password you may have reused.

    Cookie Notice

    We use cookies to ensure the functionality of our website. Necessary cookies are required for operation. Optional cookies help us improve our services. For more information, see our Privacy Policy.