How to Check Whether a Website Is Safe Before You Click
The Problem
Most people check the wrong thing. The padlock in the address bar means the connection is encrypted — nothing more. Certificates are free and automatic, so the overwhelming majority of phishing sites have a padlock too.
What actually tells you whether a site is safe is the domain name, how you arrived at it, and whether the page is asking for something a legitimate site would not ask for. Those three checks take about thirty seconds and catch nearly everything.
Already entered details on a site you now doubt? Go straight to recover a hacked email account and change that password from a different device. Link arrived by email or text? See spot and avoid phishing emails and spot scam text messages.
Symptoms
Check a site carefully when:
- You arrived from an email, text, ad, or social media post rather than typing the address yourself.
- Prices are dramatically below everyone else's.
- The page urges you to hurry — a countdown, "only 2 left", "your account will be closed today".
- It asks for payment by bank transfer, gift card, or cryptocurrency.
- Something about the address looks slightly off.
Step 1: Read the Domain from Right to Left
This is the single most valuable habit in this guide.
The real domain is the part immediately before the first single slash, read backwards from there:
https://accounts.google.com/signin→ the domain is google.com. Safe.https://google.com.secure-login.info/signin→ the domain is secure-login.info. Not Google.https://paypal-verify.com→ not PayPal. Anything before a hyphen is not ownership.https://amaz0n.co.uk→ a zero instead of an "o". Look character by character.
Points to check every time:
- Everything to the left of the real domain is a subdomain, and anyone can create one saying anything.
- Watch for extra words joined by hyphens, doubled letters, and swapped characters (
rnform,1forl,0foro). - Check the ending. A UK bank uses
.co.ukor.com, not.top,.xyz,.shop, or.click. - On a phone, tap and hold a link to preview the full address before opening it.
Step 2: Understand What the Padlock Does and Does Not Mean
- Click the padlock (or the tune icon) in Chrome or Edge → Connection is secure → Certificate is valid.
- Check Issued to matches the organisation you expect. On many sites it will name only the domain, which is normal.
- A padlock means: nobody on the network can read what you send.
- A padlock does not mean: the site is honest, the shop will ship anything, or the company is real.
- A missing padlock, or a certificate warning, is still a hard stop — never enter anything on such a page.
Step 3: Scan the URL with a Reputation Service
Free and worth the fifteen seconds for anything unfamiliar.
- Copy the link without opening it — right-click → Copy link address.
- Paste it into VirusTotal (
virustotal.com) → URL tab. It checks the address against dozens of security vendors. - Or use Google Safe Browsing site status, or URLVoid.
- A handful of "suspicious" flags on a well-known site is usually noise; several vendors flagging malicious or phishing is conclusive.
- If a link is shortened (
bit.ly,t.co), expand it first atunshorten.itor by pasting it into VirusTotal, which resolves redirects.
Step 4: Check How Old the Domain Is
Scam shops are typically days or weeks old. Real businesses are not.
- Look the domain up on a WHOIS service such as
whois.domaintools.comorwho.is. - Read the Creation Date. A "20-year-established retailer" whose domain was registered last month is lying.
- Privacy-protected registration is normal and not itself a red flag — the age is the useful signal.
- Cross-check with the Wayback Machine (
web.archive.org): a genuine business usually has years of snapshots.
Step 5: Look for the Things Fake Shops Cannot Fake
- A real postal address and phone number on the contact page — then search that address. Fake shops reuse addresses that turn out to be car parks or unrelated buildings.
- A company registration number where the country requires one. Look it up in the official register.
- Working links. Fake sites leave Terms, Returns, and Privacy pages empty or copied word for word from another shop — paste a sentence into a search engine and see how many sites have it.
- Consistent English and correct branding. Mixed currencies, mismatched logos, and stock photos of "our team" are all warnings.
- Reviews off-site. Search "sitename reviews" and "sitename scam". Trust Trustpilot and Reddit threads more than the testimonials on the site itself.
- Full checklist for buying: avoid online shopping scams.
Step 6: Judge What the Page Is Asking For
Legitimate organisations do not do these things:
- Ask for a password, PIN, or full card details by email or text link.
- Ask for payment by bank transfer, gift card, or cryptocurrency for a normal retail purchase.
- Ask you to install a "security tool" or a remote-access program to fix a problem — see avoid tech support scam calls.
- Ask for a code sent to your phone in order to "verify" you. That code is your 2FA code and giving it away hands over the account: set up two-factor authentication.
When paying, use a credit card or PayPal. Both give you a route to reclaim money; a bank transfer does not.
Step 7: Reach the Site the Safe Way Instead
The reliable defence is to stop following links at all.
- Type the address yourself, or use a bookmark you saved when you first signed up.
- Open the company's official app rather than a link in a message.
- If an email says there is a problem with your account, log in the way you normally do and check for the notice there. It will be absent if the email was fake.
- Be careful with search ads — the top result is often a paid ad impersonating the brand. Scroll to the organic result, or check the domain before clicking. Related: avoid malware in fake downloads.
Step 8: Turn On the Protection Your Browser Already Has
- Chrome: go to
chrome://settings/securityand select Enhanced protection. - Edge:
edge://settings/privacy→ turn on Microsoft Defender SmartScreen. - Firefox:
about:preferences#privacy→ tick both options under Deceptive Content and Dangerous Software Protection. - In Windows: Windows Security → App & browser control → Reputation-based protection → turn on Check apps and files, SmartScreen for Microsoft Edge, and Phishing protection.
- Consider a filtering DNS resolver such as Quad9 or Cloudflare
1.1.1.2, which blocks known malicious domains for every device: how to change DNS servers in Windows 11. - Keep the browser updated — most drive-by attacks target versions months out of date: keep your devices updated safely.
What Not to Do
- Don't trust the padlock on its own. It is the most misunderstood symbol on the web.
- Don't judge a site by how professional it looks. Templates are cheap and real sites are copied wholesale.
- Don't tap "unsubscribe" in a suspicious email to test whether it is real — it confirms your address is live.
- Don't enter real details "just to see". If you want to test a form, you have already decided you do not trust it.
Still Not Working?
If you have already entered a password, change it immediately from a different device and turn on two-factor authentication. If you entered card details, call your bank's fraud line using the number on the back of the card — not any number from the site or email.
If you downloaded and ran a file from the site, scan the PC: remove viruses and malware in Windows 11, and check for browser changes: how to remove a browser hijacker.
Related: protect your privacy on social media and set up account recovery options.
Related guides
How to Spot and Avoid Phishing Emails and Scams
Learn how to recognize phishing emails, fake login pages, and text scams before they steal your passwords or money—simple checks anyone can do in seconds.
How to Remove a Browser Hijacker and Search Redirect
Browser opening a search engine you never chose, or redirecting every result? Remove the hijacker properly: extensions, shortcuts, policies, scheduled tasks, and profiles.
How to Stop Spam Notifications from Your Browser
Fake virus alerts and gambling ads popping up in the corner of your screen? They come from browser notification permissions. Here is how to revoke them and block them for good.
How to Recover a Hacked Email Account
Locked out or seeing strange activity in your inbox? Step-by-step actions to recover a hacked email account and lock attackers out for good.
How to Spot Scam Text Messages (Smishing)
Fake delivery, bank, and prize texts are everywhere. Learn how to recognize scam text messages—called smishing—and what to do when one arrives.