A friend texted me a link last spring with three words: is this real? It was a running-shoe store, and it looked immaculate. Clean photography, a glowing wall of five-star reviews, a countdown clock promising the sale ended in nine minutes. The exact shoes I had been eyeing for months were sitting there at 70 percent off. I wanted it to be real. That is precisely the feeling these sites are engineered to produce.

I did not buy. Instead I spent that evening pulling the page apart, then did the same thing with the next dodgy link a colleague forwarded, and the one after that. To check my instincts against something colder than a gut feeling, I began pasting each address into a website analyzer and lining up what it flagged against what I could see with my own eyes. Somewhere in those late sessions I stopped trusting the design and started trusting a short list of checks that take about two minutes and rarely lie.

This guide is that list, written for people who are not technical. It also includes two real fraud operations, both uncovered by security researchers, that show why each check matters. The whole approach comes down to a single discipline: slow down for the length of a coffee refill before you type in a card number.

Scam websites: how to spot them and check if a website is legit

The 30-second gut check

Before any tools, six things you can eyeball the moment a page loads. One on its own is a yellow light. Two or more is a red one.

Warning signWhat you are seeing
The price is impossibleCurrent-season branded goods at more than half off, from a store you have never heard of, are bait rather than luck.
The clock is tickingA countdown timer exists to switch off your judgment. Real retailers do not need a five-minute deadline to sell you shoes.
Reviews are all perfectGenuine stores collect complaints. A spotless five-star wall with no mixed feedback is usually planted.
The web address is almost rightExtra words, a misspelled brand, or an odd ending like .shop, .top, or .vip bolted onto a famous name.
Contact is a form and nothing elseNo real address, no working phone, no company name behind it. That is a store built to disappear.
Checkout gets strangeA quiet push toward bank transfer, gift cards, crypto, or a personal payment app is the clearest tell of all.

The numbers behind the routine

790%Rise in fake online-shop scams in early 2025 versus the year before, per Avast.
82%Of phishing sites in 2025 used HTTPS, so the padlock proves nothing on its own.
60–90Days is the typical lifespan of a scam store before it is reported and taken down.
$2.95BReported to the US FTC in impersonation-scam losses in 2024 alone.

Scam stores are built to be fast and disposable, which is exactly why a two-minute check beats a first impression.

The padlock is not a safety signal

This is the single most common mistake, and scammers count on it. The little lock icon feels like a stamp of approval. It is not.

The mythThe reality
The padlock and https mean the site is safe to buy from. Most of us were taught to look for it, so a locked, encrypted page reads as trustworthy the instant it loads.The padlock only means the connection is encrypted, not that the seller is honest. The certificates that produce it are free and take minutes to obtain, so criminals get them too. A missing padlock is a reason to leave. A present one is not a reason to trust.

If you want the padlock to actually tell you something, click it and read the certificate. A store claiming to be a major brand, but carrying a free basic certificate issued days ago on a domain that was also registered days ago, is a scam running on autopilot. The encryption is real. The safety is an illusion.

The two-minute verification routine

When a site clears the gut check but you are about to spend money, run these six. Each takes a minute or two, and together they catch the vast majority of fakes.

CheckHow to run itWhat a scam looks likeTime
Domain agePaste the web address into a free WHOIS lookup such as who.is.Registered days or weeks ago, yet selling deep brand discounts. Under six months old is high risk.1 min
Product photosRight-click an image and run a reverse image search.The identical photos appear across dozens of unrelated stores and marketplaces. Fakes reuse stolen images.1 min
Independent reviewsSearch the store name plus the word scam, and read results that are not on the store itself.No history anywhere, or a sudden pile of identical complaints about undelivered orders.2 min
Contact and returnsLook for a real street address, a working phone number, and a returns policy.A lone contact form, an address that fails on a map, or a copy-pasted or missing returns page.2 min
Payment optionsReach the checkout and note exactly what payment methods are accepted.The card option quietly replaced by bank transfer, gift card, crypto, or a personal payment app.1 min
The certificateClick the padlock and view the certificate details.A free basic certificate on a supposed brand-name store, issued the same week the domain appeared.1 min

Two real operations that prove the point

These are not hypotheticals. Both were documented by cybersecurity teams, both ran for years, and both would have been caught early by the checks above.

BogusBazaar Online Scam Targets Fashion Consumers - FIT Information  Technology
BogusBazaar    Uncovered May 2024 by Security Research Labs (SRLabs)
The scaleMore than 75,000 fake shops built since 2021, with around 22,500 live when researchers went public. Over 850,000 people handed over their card details.
The trickThe China-based group bought expired domains that already ranked well on Google, then rebuilt them as WordPress stores selling brand-name shoes and clothing at prices no real retailer would offer.
The damageRoughly 50 million dollars in attempted charges, plus stolen cards resold on the dark web for later fraud. Most victims were in the US and Western Europe. Almost none were in China, the network's home base.
What gave it awayTemplate shops sharing the same layout, original prices struck through beside discounts over 50 percent, and checkout pages that imitated PayPal and Stripe.

Lesson: a high Google ranking is not a safety signal. Criminals rent reputation by buying aged domains. Domain age and price are the two checks that cut straight through it.

Satori Threat Intelligence Alert: Phish 'n' Ships Fakes Online Shops to  Steal Money and Credit Card Information - HUMAN Security
Phish 'n' Ships    Uncovered October 2024 by HUMAN Security
The scaleMore than 1,000 legitimate websites quietly infected, feeding traffic to 121 fake stores. Hundreds of thousands of shoppers were hit over five years, with tens of millions of dollars lost.
The trickAttackers injected code into real sites to plant fake listings for hard-to-find items, then used search-ranking manipulation so those listings sat near the top of results. Clicking one redirected you to their store.
The damageAt checkout, one of four hijacked payment processors captured the card details and confirmed an order that never shipped.
Why it was dangerousShoppers arrived through ordinary Google searches and real, trusted sites, so nothing felt wrong until the package simply never came.

Lesson: a link from a search you trust can still land on a fake store. The redirect and the final checkout address, not the search result, are what you verify before paying.

Scam sites do not wait to be found. They come to you through three channels, and none of them is a vetting process.

Where it reaches youWhat to remember
Social media ads23 percent of all social media scams in late 2024 were fake online shops. A polished ad in your feed means someone paid to place it, nothing more.
Search resultsAs Phish 'n' Ships showed, ranking can be manipulated to push a fake listing above the real brand. A top result is not an endorsement.
Messages and commentsA link dropped in a group chat, a direct message, or a comment thread has no gatekeeper at all. Treat every one as unverified.

What the fakes look like up close

Three patterns show up again and again once you know where to look.

PatternWhat to watch for
The checkoutWatch for a form that wants your full card number on a domain that is not the brand, a switch to an irreversible payment method, or an unfamiliar company name doing the charging.
Domain ageA store selling premium brands on an address registered nine days ago is the clearest warning sign there is. Legitimate shops have usually existed for years.
Lookalike addressScammers register lookalike domains that read correctly at a glance. Slow down and read the address one character at a time, from left to right.

How you pay decides whether you can recover

This is the difference between a bad afternoon and a permanent loss. The method you choose determines whether the money can come back.

Use thisWhy it helps you recover
A credit card, ideally a virtual or single-use numberChargeback rights let you dispute and reverse a charge when goods never arrive or are not as described.
Well-known checkout providersThey keep your card details away from the seller.
Avoid for unfamiliar stores
Bank transfer or wire payments
Gift cards of any kind
Zelle, Venmo, Cash App, and other personal payment apps
Cryptocurrency

Every method in the avoid list behaves like cash. Once it is sent, it is close to impossible to claw back. So here is a rule worth memorizing: if an unfamiliar store steers you off cards toward any of those, that is the end of the visit.

If you already paid

Move quickly. Recovery odds drop with every day that passes, and the first few hours matter most.

Do thisHow
1.  Call your card issuer todayAsk for a chargeback for an item not received or not as described. The sooner you file, the stronger your case.
2.  Lock down reused passwordsChange any password you also used elsewhere, and keep an eye on the linked email and bank accounts for unusual activity.
3.  Report the siteIn the US, file at reportfraud.ftc.gov. These reports feed the takedowns that shorten how long these stores survive.
4.  Keep the evidenceSave the order confirmation, the exact web address, screenshots, and any emails. Your bank and the regulator will ask for them.

Before you enter a card number

Work down the list. Enter payment details only when every box can be ticked.

DoneCheck before you enter payment details
☐The deal is believable for a genuine retailer
☐The domain is more than a few months old
☐Product photos are not reused across other sites
☐Independent reviews exist and are not all identical
☐There is a real address, phone, and returns policy
☐Checkout accepts a credit card, not only irreversible methods
☐The final checkout address matches the brand you started with

The final verdict

Months of doing this changed one habit more than any other: I no longer decide whether a site is safe by looking at it. The good fakes look better than plenty of real stores now, and the ones built with AI-generated photos and reviews look better still. So I stopped grading the design and started running the checks. Nine times out of ten the two-minute version settles it, because domain age and price alone tell the story.

When something is borderline, or when I am about to enter a card on a store I have never used, I paste the address into an analyzer before I trust it, and Sitescano is the one I keep open in a tab for that. It scores the domain age, the reputation signals, and the security flags in a single pass, which saves me running each check by hand. Still, the tool is a second opinion, not a substitute for the discipline. The discipline is the whole thing.

So slow down for the length of a coffee refill. Run the list. Make the site earn your card number instead of assuming it deserves one. That single pause is the cheapest insurance you will ever buy online.