A friend texted me a link last spring with three words: is this real? It was a running-shoe store, and it looked immaculate. Clean photography, a glowing wall of five-star reviews, a countdown clock promising the sale ended in nine minutes. The exact shoes I had been eyeing for months were sitting there at 70 percent off. I wanted it to be real. That is precisely the feeling these sites are engineered to produce.
I did not buy. Instead I spent that evening pulling the page apart, then did the same thing with the next dodgy link a colleague forwarded, and the one after that. To check my instincts against something colder than a gut feeling, I began pasting each address into a website analyzer and lining up what it flagged against what I could see with my own eyes. Somewhere in those late sessions I stopped trusting the design and started trusting a short list of checks that take about two minutes and rarely lie.
This guide is that list, written for people who are not technical. It also includes two real fraud operations, both uncovered by security researchers, that show why each check matters. The whole approach comes down to a single discipline: slow down for the length of a coffee refill before you type in a card number.

The 30-second gut check
Before any tools, six things you can eyeball the moment a page loads. One on its own is a yellow light. Two or more is a red one.
| Warning sign | What you are seeing |
|---|---|
| The price is impossible | Current-season branded goods at more than half off, from a store you have never heard of, are bait rather than luck. |
| The clock is ticking | A countdown timer exists to switch off your judgment. Real retailers do not need a five-minute deadline to sell you shoes. |
| Reviews are all perfect | Genuine stores collect complaints. A spotless five-star wall with no mixed feedback is usually planted. |
| The web address is almost right | Extra words, a misspelled brand, or an odd ending like .shop, .top, or .vip bolted onto a famous name. |
| Contact is a form and nothing else | No real address, no working phone, no company name behind it. That is a store built to disappear. |
| Checkout gets strange | A quiet push toward bank transfer, gift cards, crypto, or a personal payment app is the clearest tell of all. |
The numbers behind the routine
| 790% | Rise in fake online-shop scams in early 2025 versus the year before, per Avast. |
| 82% | Of phishing sites in 2025 used HTTPS, so the padlock proves nothing on its own. |
| 60–90 | Days is the typical lifespan of a scam store before it is reported and taken down. |
| $2.95B | Reported to the US FTC in impersonation-scam losses in 2024 alone. |
Scam stores are built to be fast and disposable, which is exactly why a two-minute check beats a first impression.
The padlock is not a safety signal
This is the single most common mistake, and scammers count on it. The little lock icon feels like a stamp of approval. It is not.
| The myth | The reality |
|---|---|
| The padlock and https mean the site is safe to buy from. Most of us were taught to look for it, so a locked, encrypted page reads as trustworthy the instant it loads. | The padlock only means the connection is encrypted, not that the seller is honest. The certificates that produce it are free and take minutes to obtain, so criminals get them too. A missing padlock is a reason to leave. A present one is not a reason to trust. |
If you want the padlock to actually tell you something, click it and read the certificate. A store claiming to be a major brand, but carrying a free basic certificate issued days ago on a domain that was also registered days ago, is a scam running on autopilot. The encryption is real. The safety is an illusion.
The two-minute verification routine
When a site clears the gut check but you are about to spend money, run these six. Each takes a minute or two, and together they catch the vast majority of fakes.
| Check | How to run it | What a scam looks like | Time |
|---|---|---|---|
| Domain age | Paste the web address into a free WHOIS lookup such as who.is. | Registered days or weeks ago, yet selling deep brand discounts. Under six months old is high risk. | 1 min |
| Product photos | Right-click an image and run a reverse image search. | The identical photos appear across dozens of unrelated stores and marketplaces. Fakes reuse stolen images. | 1 min |
| Independent reviews | Search the store name plus the word scam, and read results that are not on the store itself. | No history anywhere, or a sudden pile of identical complaints about undelivered orders. | 2 min |
| Contact and returns | Look for a real street address, a working phone number, and a returns policy. | A lone contact form, an address that fails on a map, or a copy-pasted or missing returns page. | 2 min |
| Payment options | Reach the checkout and note exactly what payment methods are accepted. | The card option quietly replaced by bank transfer, gift card, crypto, or a personal payment app. | 1 min |
| The certificate | Click the padlock and view the certificate details. | A free basic certificate on a supposed brand-name store, issued the same week the domain appeared. | 1 min |
Two real operations that prove the point
These are not hypotheticals. Both were documented by cybersecurity teams, both ran for years, and both would have been caught early by the checks above.
| BogusBazaar Uncovered May 2024 by Security Research Labs (SRLabs) | |
|---|---|
| The scale | More than 75,000 fake shops built since 2021, with around 22,500 live when researchers went public. Over 850,000 people handed over their card details. |
| The trick | The China-based group bought expired domains that already ranked well on Google, then rebuilt them as WordPress stores selling brand-name shoes and clothing at prices no real retailer would offer. |
| The damage | Roughly 50 million dollars in attempted charges, plus stolen cards resold on the dark web for later fraud. Most victims were in the US and Western Europe. Almost none were in China, the network's home base. |
| What gave it away | Template shops sharing the same layout, original prices struck through beside discounts over 50 percent, and checkout pages that imitated PayPal and Stripe. |
Lesson: a high Google ranking is not a safety signal. Criminals rent reputation by buying aged domains. Domain age and price are the two checks that cut straight through it.
| Phish 'n' Ships Uncovered October 2024 by HUMAN Security | |
|---|---|
| The scale | More than 1,000 legitimate websites quietly infected, feeding traffic to 121 fake stores. Hundreds of thousands of shoppers were hit over five years, with tens of millions of dollars lost. |
| The trick | Attackers injected code into real sites to plant fake listings for hard-to-find items, then used search-ranking manipulation so those listings sat near the top of results. Clicking one redirected you to their store. |
| The damage | At checkout, one of four hijacked payment processors captured the card details and confirmed an order that never shipped. |
| Why it was dangerous | Shoppers arrived through ordinary Google searches and real, trusted sites, so nothing felt wrong until the package simply never came. |
Lesson: a link from a search you trust can still land on a fake store. The redirect and the final checkout address, not the search result, are what you verify before paying.
Where the link reaches you matters
Scam sites do not wait to be found. They come to you through three channels, and none of them is a vetting process.
| Where it reaches you | What to remember |
|---|---|
| Social media ads | 23 percent of all social media scams in late 2024 were fake online shops. A polished ad in your feed means someone paid to place it, nothing more. |
| Search results | As Phish 'n' Ships showed, ranking can be manipulated to push a fake listing above the real brand. A top result is not an endorsement. |
| Messages and comments | A link dropped in a group chat, a direct message, or a comment thread has no gatekeeper at all. Treat every one as unverified. |
What the fakes look like up close
Three patterns show up again and again once you know where to look.
| Pattern | What to watch for |
|---|---|
| The checkout | Watch for a form that wants your full card number on a domain that is not the brand, a switch to an irreversible payment method, or an unfamiliar company name doing the charging. |
| Domain age | A store selling premium brands on an address registered nine days ago is the clearest warning sign there is. Legitimate shops have usually existed for years. |
| Lookalike address | Scammers register lookalike domains that read correctly at a glance. Slow down and read the address one character at a time, from left to right. |
How you pay decides whether you can recover
This is the difference between a bad afternoon and a permanent loss. The method you choose determines whether the money can come back.
| Use this | Why it helps you recover |
|---|---|
| A credit card, ideally a virtual or single-use number | Chargeback rights let you dispute and reverse a charge when goods never arrive or are not as described. |
| Well-known checkout providers | They keep your card details away from the seller. |
| Avoid for unfamiliar stores |
|---|
| Bank transfer or wire payments |
| Gift cards of any kind |
| Zelle, Venmo, Cash App, and other personal payment apps |
| Cryptocurrency |
Every method in the avoid list behaves like cash. Once it is sent, it is close to impossible to claw back. So here is a rule worth memorizing: if an unfamiliar store steers you off cards toward any of those, that is the end of the visit.
If you already paid
Move quickly. Recovery odds drop with every day that passes, and the first few hours matter most.
| Do this | How |
|---|---|
| 1. Call your card issuer today | Ask for a chargeback for an item not received or not as described. The sooner you file, the stronger your case. |
| 2. Lock down reused passwords | Change any password you also used elsewhere, and keep an eye on the linked email and bank accounts for unusual activity. |
| 3. Report the site | In the US, file at reportfraud.ftc.gov. These reports feed the takedowns that shorten how long these stores survive. |
| 4. Keep the evidence | Save the order confirmation, the exact web address, screenshots, and any emails. Your bank and the regulator will ask for them. |
Before you enter a card number
Work down the list. Enter payment details only when every box can be ticked.
| Done | Check before you enter payment details |
|---|---|
| ☐ | The deal is believable for a genuine retailer |
| ☐ | The domain is more than a few months old |
| ☐ | Product photos are not reused across other sites |
| ☐ | Independent reviews exist and are not all identical |
| ☐ | There is a real address, phone, and returns policy |
| ☐ | Checkout accepts a credit card, not only irreversible methods |
| ☐ | The final checkout address matches the brand you started with |
The final verdict
Months of doing this changed one habit more than any other: I no longer decide whether a site is safe by looking at it. The good fakes look better than plenty of real stores now, and the ones built with AI-generated photos and reviews look better still. So I stopped grading the design and started running the checks. Nine times out of ten the two-minute version settles it, because domain age and price alone tell the story.
When something is borderline, or when I am about to enter a card on a store I have never used, I paste the address into an analyzer before I trust it, and Sitescano is the one I keep open in a tab for that. It scores the domain age, the reputation signals, and the security flags in a single pass, which saves me running each check by hand. Still, the tool is a second opinion, not a substitute for the discipline. The discipline is the whole thing.
So slow down for the length of a coffee refill. Run the list. Make the site earn your card number instead of assuming it deserves one. That single pause is the cheapest insurance you will ever buy online.

