The padlock advice is wrong

"Look for the padlock" and "check for HTTPS" made sense when certificates were expensive and hard to get. They are now free and automatic. A scammer setting up a fake shop gets a valid certificate in about thirty seconds, without proving anything about who they are.

All the padlock tells you is that your connection to that server is encrypted. It says nothing about whether the person running the server will send you a parcel. The overwhelming majority of scam shops have a perfectly valid padlock — and people trust them because of it, which makes this the most counterproductive piece of security advice still in circulation.

The absence of HTTPS is still a bad sign. Its presence is not a good one.

The checks, in the order that finds fakes fastest Payment method and domain age are the fastest disqualifiers; the padlock is not a signal at all. 1 · How do they want to be paid? Bank transfer, crypto, or gift cards — stop here. Ten seconds, and it settles most cases. 2 · Read the real domain The last two parts before the first single slash. Everything before that is decoration. 3 · How old is the domain? A WHOIS lookup. Three weeks old but "established since 2009" cannot both be true. ✕ The padlock Not a check. Certificates are free and automatic — almost every scam shop has one.
Whatever the checks say, paying by credit card means being wrong is recoverable. That single habit beats all of the above.

Check 1: how do they want to be paid?

Start here. It's the single most reliable indicator, and it takes ten seconds — get to the checkout page and look at the options.

Treat these as disqualifying:

Real shops accept credit cards or established payment processors, because their customers expect it. Those methods come with chargeback rights, which is exactly what a scammer is trying to avoid.

The practical rule: pay by credit card, or through a processor with buyer protection. Then even if you're wrong about the site, you can get your money back. This single habit matters more than every other check on this page combined.

Check 2: read the domain properly

Look at the address bar and find the real domain — the last two parts before the first single slash.

In shop.example-store.com/products/x, the domain is example-store.com. In apple.com.secure-login.net/verify, the domain is secure-login.net — the "apple.com" part is just a subdomain the scammer chose to make it look right. This is the trick, and it works on almost everyone who doesn't know to look for it.

Things to check:

Check 3: how old is the site?

This is the check most people don't know about, and it catches an enormous share of scam shops — because they're disposable and rebuilt constantly under new names.

Look up the domain's registration date with a WHOIS lookup service (search "whois lookup" and paste in the domain). What you're looking for is the creation date.

Age alone doesn't prove legitimacy, but a three-week-old domain selling discounted electronics is close to conclusive.

Illustration of a WHOIS lookup on a suspicious shop domain A drawing of a WHOIS result showing a domain created three weeks ago and registered for a single year. Illustration, not a screenshot. Search "whois lookup" and paste in the domain. mega-outlet-deals.example Creation Date 2026-07-24 — three weeks ago Registry Expiry Date 2027-07-24 — registered for one year only Registrant REDACTED FOR PRIVACY — normal, not suspicious by itself The site claims "Trusted by shoppers since 2011" and displays 4,000 reviews. Both cannot be true.
This is the check almost nobody knows about, and it catches an enormous share of scam shops — they are disposable by design and get rebuilt under new names constantly.

Check 4: can you actually reach anyone?

Find the contact page and test what's on it, rather than just noting that it exists.

Also read the returns and shipping policies. Scam sites often copy these from elsewhere, so they contradict each other, mention the wrong country, or reference a company name that doesn't match the site.

Check 5: reverse-search the photos

Right-click a product image and use your browser's reverse image search, or upload it to an image search service.

If the same photo appears across dozens of unrelated shops, it's a stock image or was lifted from the real manufacturer. That's normal for a small reseller, but combined with a new domain and unusual payment methods, it completes the picture.

The same trick works on the "our team" photos some fake sites use — those are frequently stock portraits, and a reverse search shows them selling insurance on four other websites.

Check 6: look for reviews they don't control

Reviews displayed on the site itself are worth nothing. They're written by whoever built the site.

Search instead for the domain name plus "scam", "review", or "legit" and see what comes back from places the site doesn't control — independent review platforms, forums, social media, consumer protection sites. Two patterns to watch for:

Softer signals

None of these prove anything alone, but they add up:

Act quickly — recovery odds drop sharply with time.

  1. Contact your bank or card issuer today. Ask specifically to dispute the transaction or raise a chargeback. Card payments have the strongest protection; a bank transfer has the weakest, but banks can sometimes recall a recent one, so it's still worth calling immediately.
  2. If you paid through a payment service, open a dispute in their system as well as with your bank. There are deadlines, so don't wait to see if the parcel arrives.
  3. Gather evidence now — screenshots of the product page, the order confirmation, the payment record, and any messages. Scam sites disappear, and you'll want this for the dispute.
  4. Report it to your country's fraud or consumer protection body. This rarely gets your money back directly but it's how these sites get taken down.
  5. If you entered a password, change it there and anywhere you reused it, and check your email account for the traces a real compromise leaves. If you entered card details, ask for a replacement card.
  6. Be sceptical of anyone offering to recover your money for a fee. Recovery scams specifically target people who have just been scammed, often using details from the original fraud to sound credible. Your bank and the official reporting service are the legitimate routes, and neither charges up front.
The two-minute version

Ignore the padlock — it means nothing. Look at the payment options first: bank transfer, crypto, or gift cards means stop. Read the actual domain, not the pretty part before it. Check the registration date with a WHOIS lookup; a new domain claiming to be an established shop is close to conclusive. Test the phone number and map the address. And whatever you decide — pay by credit card, so being wrong is recoverable.