How to check if a website is legit before you buy or sign in

Nine checks, most of them under a minute, for deciding whether to trust a shop, a sign-in page or a site that suddenly wants your details.

To check if a website is legit, you don't need special software. Most scam sites fail one of a handful of simple tests, and you can run the first few before the page has finished loading. Here are nine checks, ordered from quickest to most thorough. Use more of them the more a site is asking from you: browsing a recipe needs none, typing a password needs a few, and paying a new shop needs most.

1. Read the whole address

Look at the domain, the part just before the first single slash. Scam sites borrow a real brand's name and change something small:

  • A swapped character: paypa1.com, arnazon.com
  • An extra word: apple-support-id.com, chase-secure-login.net
  • A different ending: nike-outlet.shop instead of nike.com
  • The brand as a subdomain of something else: paypal.account-check.xyz, where the real domain is account-check.xyz

On a phone, tap the address bar; mobile browsers often hide most of it.

2. Think about how you got there

A site you typed yourself or reached from a bookmark is very different from one you reached through a text message, a social media ad or an urgent email. Delivery problems, locked accounts, prize wins and unpaid tolls are the classic lures. If the message pushed you to act fast, close the tab and go to the company the long way.

3. Don't trust the padlock alone

The padlock and https:// mean the connection between you and the site is encrypted. They say nothing about who runs the site. Certificates are free and automatic, and nearly every phishing site has one. A missing padlock on a page asking for details is a reason to leave; a present padlock is not a reason to stay.

4. Check how old the domain is

Search for "whois" plus the domain, or use your domain registrar's lookup tool, and look at the creation date. A shop claiming twenty years in business on a domain registered last week is not telling the truth. Scam shops are often only weeks old, because they are reported and replaced quickly.

A young domain isn't proof of anything on its own. New businesses exist. It is one weight on the scale.

5. Ask Google Safe Browsing

Google's Safe Browsing site status page tells you whether Google currently lists a site as unsafe. Most browsers already check this list and will show a red warning page. A clean result means the site is not known to be bad yet, not that it is good.

6. Look at how it wants to be paid

Legitimate shops take credit cards and well-known payment services, which give you a way to dispute a charge. Be wary when a site:

  • Only accepts bank transfer, crypto, gift cards or payment apps meant for friends
  • Offers a big discount for paying one of those ways
  • Sends you to a different site to pay, with a different name in the address

No real company asks to be paid in gift cards.

7. Check the contact details and policies

A real business can be reached. Look for a physical address you can find on a map, a phone number, a company name in the footer, and refund and shipping policies that name that company. Copy a sentence from the returns policy and search it in quotes: scam shops often paste the same policy word for word across dozens of sites.

Watch for placeholders nobody filled in, such as 123 Main Street, Your Company or Lorem ipsum. They suggest a template published in a hurry.

8. Read reviews somewhere else

Reviews on the site itself prove nothing. Search for the site's name plus "reviews" or "scam" and read what people say on independent review sites and forums. No footprint at all for a shop with "10,000+ happy customers" is a warning in itself.

9. Look at how the site was built

This is the check most guides skip. AI app builders such as Lovable, Bolt and v0 let anyone publish a polished site in minutes, and scammers use them for the same reason everyone else does. Most sites made with them are honest. But some combinations should stop you:

  • A brand's sign-in page on a builder domain. microsoft-login.lovable.app is not Microsoft.
  • A big brand's page carrying a builder badge or script, such as Made with Bolt or Lovable's gptengineer.js.
  • A "verify you are human" step that asks you to press Win+R and paste. That is malware, not a CAPTCHA.

Our guide to phishing sites built with AI builders goes deeper, and how to tell if a website was made with AI shows how to read the build evidence.

Putting it together

What the site asks forChecks worth running
Nothing, you're just readingNone, unless it pushes downloads or pop-ups
A newsletter email1 and 2
A password or one-time code1, 2 and 9; better still, go to the site yourself
Card details or a paymentAll nine

Kitsuvo runs the build check on every page as it loads and shows a score with the evidence. Separately, it stops you with a warning when a look-alike page asks for a password or card. Everything runs on your own computer.

Questions people ask

How can I check if a website is safe for free?

Read the full address carefully, look up the domain's age with a whois search, check Google Safe Browsing's site status page, and search for independent reviews. All of these are free and take a few minutes together.

Does a padlock mean a website is safe?

No. The padlock means the connection is encrypted, so nobody in between can read what you send. It does not tell you who runs the site, and almost every scam site has one.

What should I do if I paid a scam website?

Call your card issuer or bank straight away using the number on your card and ask about a chargeback. Change any password you entered, and report the site to Google Safe Browsing and your country's fraud reporting service.