The padlock advice is wrong
"Look for the padlock" and "check for HTTPS" made sense when certificates were expensive and hard to get. They are now free and automatic. A scammer setting up a fake shop gets a valid certificate in about thirty seconds, without proving anything about who they are.
All the padlock tells you is that your connection to that server is encrypted. It says nothing about whether the person running the server will send you a parcel. The overwhelming majority of scam shops have a perfectly valid padlock — and people trust them because of it, which makes this the most counterproductive piece of security advice still in circulation.
The absence of HTTPS is still a bad sign. Its presence is not a good one.
Check 1: how do they want to be paid?
Start here. It's the single most reliable indicator, and it takes ten seconds — get to the checkout page and look at the options.
Treat these as disqualifying:
- Direct bank transfer as the only option, especially to a personal name rather than a company.
- Cryptocurrency. Irreversible by design. A legitimate consumer shop has no reason to require it.
- Gift cards of any kind. No real business is paid in gift cards. This one is close to definitional.
- Money transfer services intended for sending cash to people you know.
- "Friends and family" on a payment app — this exists specifically to remove buyer protection, and asking for it is asking you to waive your recourse.
Real shops accept credit cards or established payment processors, because their customers expect it. Those methods come with chargeback rights, which is exactly what a scammer is trying to avoid.
The practical rule: pay by credit card, or through a processor with buyer protection. Then even if you're wrong about the site, you can get your money back. This single habit matters more than every other check on this page combined.
Check 2: read the domain properly
Look at the address bar and find the real domain — the last two parts before the first single slash.
In shop.example-store.com/products/x, the domain is example-store.com. In apple.com.secure-login.net/verify, the domain is secure-login.net — the "apple.com" part is just a subdomain the scammer chose to make it look right. This is the trick, and it works on almost everyone who doesn't know to look for it.
Things to check:
- Character substitutions.
rninstead ofm, a capitalIinstead of a lowercasel, a zero instead of an O. Read the domain letter by letter if the stakes are high. - Brand plus a word.
nike-outlet-sale.comis not Nike. Established brands sell from their own domain. - Unusual endings. Not disqualifying on their own, but a well-known retailer suddenly on an unfamiliar top-level domain is worth pausing over.
- Never navigate from a link in an email or a message. Type the address yourself or use a bookmark. A link's visible text and its actual destination are unrelated.
Check 3: how old is the site?
This is the check most people don't know about, and it catches an enormous share of scam shops — because they're disposable and rebuilt constantly under new names.
Look up the domain's registration date with a WHOIS lookup service (search "whois lookup" and paste in the domain). What you're looking for is the creation date.
- Registered in the last few months, but presenting itself as an established retailer with thousands of reviews? Those two facts can't both be true.
- Registration details hidden behind a privacy service is normal and not by itself suspicious — most registrars do this by default now.
- A very short registration period — registered for one year only — fits the disposable pattern, though plenty of legitimate small sites do this too.
Age alone doesn't prove legitimacy, but a three-week-old domain selling discounted electronics is close to conclusive.
Check 4: can you actually reach anyone?
Find the contact page and test what's on it, rather than just noting that it exists.
- Is there a physical address? Paste it into a map service. Fake shops list addresses that turn out to be a car park, a residential flat, or a building that doesn't exist. Some list a real company's address they have nothing to do with.
- Is there a phone number, and does it ring? Call it. A dead number or permanent voicemail on a shop supposedly processing hundreds of orders is telling.
- Is the email address on their own domain? A retailer using a free webmail address for customer service is a small operation at best.
- Send a pre-sales question. Ask something specific that requires a real answer — stock of a particular size, delivery time to your area. No reply within a couple of days, or a reply that doesn't address the question, tells you what support will be like after they have your money.
Also read the returns and shipping policies. Scam sites often copy these from elsewhere, so they contradict each other, mention the wrong country, or reference a company name that doesn't match the site.
Check 5: reverse-search the photos
Right-click a product image and use your browser's reverse image search, or upload it to an image search service.
If the same photo appears across dozens of unrelated shops, it's a stock image or was lifted from the real manufacturer. That's normal for a small reseller, but combined with a new domain and unusual payment methods, it completes the picture.
The same trick works on the "our team" photos some fake sites use — those are frequently stock portraits, and a reverse search shows them selling insurance on four other websites.
Check 6: look for reviews they don't control
Reviews displayed on the site itself are worth nothing. They're written by whoever built the site.
Search instead for the domain name plus "scam", "review", or "legit" and see what comes back from places the site doesn't control — independent review platforms, forums, social media, consumer protection sites. Two patterns to watch for:
- Nothing at all. A shop claiming to be established should leave some trace. Complete silence outside its own website is itself a finding.
- A burst of perfect reviews, all recent, all short. Bought reviews cluster in time and read alike. Real ones accumulate gradually and include mild complaints about delivery.
Softer signals
None of these prove anything alone, but they add up:
- Prices far below everyone else. If a current-model item is 70% off everywhere on the site, the question isn't how they do it — it's whether anything ships at all.
- Countdown timers and "only 2 left" on every product. Manufactured urgency exists to stop you doing the checks on this page.
- A catalogue that makes no sense — power tools, skincare, and phone cases in one shop, at identical discounts.
- Awkward machine-translated text, particularly in the footer and policy pages that get less attention than the product pages.
- You arrived from a social media advert. Not disqualifying — but this is the primary distribution channel for these shops, and it's worth extra scepticism.
- Broken links in the footer, or policy pages that link back to the homepage instead of real content.
If you already paid
Act quickly — recovery odds drop sharply with time.
- Contact your bank or card issuer today. Ask specifically to dispute the transaction or raise a chargeback. Card payments have the strongest protection; a bank transfer has the weakest, but banks can sometimes recall a recent one, so it's still worth calling immediately.
- If you paid through a payment service, open a dispute in their system as well as with your bank. There are deadlines, so don't wait to see if the parcel arrives.
- Gather evidence now — screenshots of the product page, the order confirmation, the payment record, and any messages. Scam sites disappear, and you'll want this for the dispute.
- Report it to your country's fraud or consumer protection body. This rarely gets your money back directly but it's how these sites get taken down.
- If you entered a password, change it there and anywhere you reused it, and check your email account for the traces a real compromise leaves. If you entered card details, ask for a replacement card.
- Be sceptical of anyone offering to recover your money for a fee. Recovery scams specifically target people who have just been scammed, often using details from the original fraud to sound credible. Your bank and the official reporting service are the legitimate routes, and neither charges up front.
Ignore the padlock — it means nothing. Look at the payment options first: bank transfer, crypto, or gift cards means stop. Read the actual domain, not the pretty part before it. Check the registration date with a WHOIS lookup; a new domain claiming to be an established shop is close to conclusive. Test the phone number and map the address. And whatever you decide — pay by credit card, so being wrong is recoverable.