How to identify a fake website: 8 red flags anyone can spot
Not every scam site looks amateur. Modern kits clone real stores pixel-perfectly, host on fast CDNs and even display fake trust badges. These eight checks are designed to catch what polished design cannot hide: infrastructure, behaviour and provenance.
1. Inspect the URL carefully
Look-alike domains are the oldest trick and still the most effective. Check for:
- Misspellings and homoglyphs.
arnazon.com(rn instead of m),paypa1.com(1 instead of l), or Unicode homoglyphs that look identical in the browser bar. - Extra subdomains or paths.
secure-paypal.com.signin.ru: the registered domain is the rightmost pair (signin.ru), not the brand name. - Suspicious TLDs. Brands rarely use
.tk,.ml,.topor.storefor their primary operations.
When in doubt, type the brand's known domain manually instead of clicking a link.
2. Verify HTTPS and certificate details
HTTPS is no longer a trust signal: every phishing kit has it. What matters is who issued the certificate and when:
- Click the padlock icon in your browser bar and view the certificate. A legitimate enterprise usually uses a well-known CA (DigiCert, Sectigo, GlobalSign) with an organisation-validated (OV) or extended-validation (EV) cert.
- A brand-new Let's Encrypt certificate issued yesterday to a supposed bank is a red flag.
- Check the certificate's subject alternative names (SANs). If the cert covers fifty unrelated domains, it may be from a shared hosting provider used by scammers.
3. Review contact and company information
Legitimate businesses want to be found. Scam sites want the opposite:
- No physical address or a fake one (search it on Google Maps: many scam sites list residential addresses or demolished buildings).
- Generic email only. A support address at
@gmail.comor@proton.mefor a supposed corporation is a hard stop. - Missing company registration number. In the EU, a valid VAT or trade-register number is legally required and easily verifiable.
- No phone number or a number that goes to voicemail in a different country.
4. Search for reviews and reputation
Before buying from an unfamiliar store, search the domain plus one of these keywords:
site:reddit.com [domain] scamsite:trustpilot.com [domain][domain] review fraud
Be wary of sites with only five-star reviews posted within the last week, or reviews that repeat the same phrases. Many scam stores populate their own review sections with LLM-generated text.
5. Inspect images, copy and design
Cloned stores reuse assets from the original brand, but clones are never perfect:
- Right-click an image and search with Google Lens. If it appears on a dozen unrelated sites, it is stock photography, not original product shots.
- Copy a product description into a search engine. Identical text across multiple domains is a hallmark of template scam shops.
- Check the footer copyright year. A site claiming to be established in 2015 with a footer saying "© 2022" has not been maintained: or is a recently deployed kit.
6. Scrutinise payment methods
Payment preference is one of the strongest signals:
- Bank transfer only. Scammers prefer irreversible transfers (SEPA, wire, crypto) because chargebacks are impossible.
- PayPal "Friends & Family". A request to use the non-goods option removes buyer protection: always refuse.
- Only crypto. A store that accepts only Bitcoin or Ethereum and offers a "discount" for crypto is almost always fraudulent.
- Fake checkout flows. Some kits simulate a checkout page but never actually process a card. If you enter fake card details and the order "succeeds", the site is a data-harvesting frontend.
8. Use Blackwall's Website Scam Check
If a site passes the first seven checks but still feels off, paste the URL into Blackwall's scam check or submit a report. The AI Triage engine scores the domain for phishing, malware and fraud indicators in under a minute, using signals you cannot see from the surface:
- Domain age, registrar reputation and nameserver history
- Hosting provider abuse history and ASN reputation
- Blocklist status across Google Safe Browsing, PhishTank and SURBL
- SSL certificate anomalies and redirect chains
A low score does not guarantee safety, but a high score is a strong signal to stop and report.
Have a URL to report right now?
Blackwall triages the case, files with the right blocklists and opens a takedown with the hosting provider: usually within minutes.
Run a website scam checkRelated guides
Frequently asked questions
What is the fastest way to check if a website is fake?
Run the URL through Blackwall's Website Scam Check: it combines WHOIS age, TLS analysis, blocklist status and DOM heuristics into a single score in seconds.
Is HTTPS a guarantee that a site is safe?
No. HTTPS only means the connection is encrypted, not that the site is trustworthy. Most phishing sites now use free Let's Encrypt certificates.
What are the most-abused TLDs for fake websites?
.tk, .ml, .gq, .cf, .ga, .top, .rest, .zip, .xyz see disproportionate fake-site registration. Not automatically fake, but weigh accordingly.
How do I check a website's age?
Use whois.com, rdap.org or Blackwall's Website Scam Check. Domains younger than 90 days selling luxury goods at deep discounts are the highest-risk category.
What should I do if I already entered payment info on a fake site?
Contact your bank or card issuer to block the card, file a chargeback within 60 days, and change any password you may have reused.

7. Verify social proof and trust badges
Trust badges are copy-paste decorations on most scam sites: