SECURITYJune 14, 2026 · 11 min read·0

How to Check If a Website Is Safe Before You Pay: 7-Step Verification Guide

Before you type a card number or scan a UPI QR, run a website through these seven checks. Each one takes under a minute, and most fake sites fail at least three of them.

T
DomainScan
𝕏 Share
Security

A friend of mine almost lost ₹38,000 last month. The website looked perfect — same logo as the brand she trusted, same product photos, same checkout flow. The only thing that gave it away was a tiny detail in the URL she noticed three seconds before clicking Pay. She got lucky. Most people don’t.

Fake websites have stopped looking fake. Scammers buy real SSL certificates, copy entire product catalogs, and pay for Google Ads that put their phishing pages above the real brand. If your only defense is “does it look legit,” you’ve already lost.

Below are seven checks you can run on any website in under a minute each. None of them require technical skill. All of them have stopped someone, somewhere, from losing money this week.

Why a quick check matters

The economics of online fraud have flipped. A scammer can register a domain for $2, clone a brand in an hour, and run paid ads to it the same day. The cost of building a fake site is now lower than the cost of a single successful payment from it. That math is why fake checkout pages have exploded since 2024.

The good news: scammers cut corners. They reuse infrastructure, they skip steps real businesses can’t skip, and they leave fingerprints in places most users never look. Seven of those places are below.

1. Look up the domain age

The single highest-signal check. Most scam sites are less than 90 days old. Real businesses, even new ones, usually have at least a few months of history by the time they’re selling anything online.

Run a WHOIS lookup. You’re looking for the Creation Date field. If it’s less than three months ago and the site is asking you to pay for a brand-name product, treat that as a serious warning.

Rule of thumb
Domain registered in the last 30 days + brand-name product on sale + steep discount = leave the page. This combination correctly identifies roughly four out of five payment scam sites.
Run a WHOIS lookup
Domain age, registrar, and registration history in one view.
Try it

2. Inspect the SSL certificate

The padlock icon means the connection is encrypted. It does not mean the site is honest. Scammers know this and use it against you — most phishing sites in 2026 have valid SSL because free certificate authorities make it trivial.

What you actually want to look at:

  • Issuer. A Let’s Encrypt certificate on a checkout page handling thousands of orders is suspicious. Real retailers usually pay for higher-validation certificates.
  • Validity window. Certificates issued within the last week, on a domain less than a month old, paired with payment forms = strong red flag.
  • Subject name. Make sure the certificate’s Common Name actually matches the domain you’re on. Mismatches are rare but lethal.

3. Check the nameservers

Real businesses use a small number of well-known DNS providers: Cloudflare, Route 53, Google Cloud DNS, GoDaddy. Scam sites often use obscure nameservers tied to bulletproof hosting, or run their own NS on the same IP as the website. Both are unusual for a legitimate brand.

It’s also worth checking whether the nameservers have changed recently. A site that switched nameservers in the last week, after months of stability, has either had a serious infrastructure migration — or been compromised.

Inspect nameservers
See current and historical NS records, plus the IPs behind them.
Try it

4. Run a blacklist scan

Major blacklists — Spamhaus, SURBL, URIBL, Google Safe Browsing — share data with each other and update fast. If a site has been reported for phishing, malware, or spam by enough people, it usually ends up on at least one of these lists within 24 hours.

A clean blacklist result doesn’t mean the site is safe. But a hit on multiple lists is a hard stop. Close the tab.

5. Reverse-lookup the IP

Find the IP address the website resolves to, then look up what other domains share that IP. A real business will usually share an IP with a handful of related properties (their own subdomains, a CDN, maybe a sister brand). A scam site frequently shares its IP with dozens of unrelated, equally suspicious-looking domains — often clones targeting other brands.

If a single IP is hosting amaz0n-deals.xyz, flipkart-sale.top, and nike-india-offer.shop all at once, you’re looking at a scam farm. Don’t do business with anything on that IP.

Reverse IP lookup
See every domain hosted on the same IP — a fast way to spot scam farms.
Try it

6. Read the HTTP headers

Headers are the metadata a server sends back with every page. They tell you which web server the site runs, what security policies it has, and sometimes what platform the store was built on. They’re also where scammers get sloppy.

What to watch for:

  • Missing Strict-Transport-Security on a checkout page (legitimate retailers ship this by default).
  • A Server header that says nginx on a cheap default port, with no CDN in front. Real e-commerce sites are nearly always behind Cloudflare, Fastly, Akamai, or similar.
  • Headers that leak the original CMS — e.g., X-Powered-By: WordPress on a page claiming to be a global retailer.

7. Cross-check the brand

The last step is the simplest and the one most people skip. Open a new tab. Go to the brand’s official social media — Instagram, X, LinkedIn. Look at the link in their bio. If the domain you’re about to pay on doesn’t match that link, you’re on a fake site.

A surprising number of scam sites get caught at exactly this step. They’ve copied the website perfectly, but they can’t copy the brand’s verified social presence — and they’re counting on you not checking.

The 60-second checklist

Print this. Tape it next to your monitor. Run it before any payment to a site you haven’t paid before.

  1. Is the domain older than 90 days?
  2. Does the SSL certificate match the domain and look reasonable for the business size?
  3. Are the nameservers from a known DNS provider?
  4. Is the domain clean across major blacklists?
  5. Does the IP host a sensible number of related domains, not dozens of fake-looking ones?
  6. Do the HTTP headers look like a real e-commerce setup?
  7. Does the brand’s real social bio link to this exact domain?
Pass threshold
Six out of seven greens? Probably safe. Five or fewer? Don’t pay. The few minutes you save aren’t worth the money you can lose.

FAQ

Does the green padlock mean a website is safe?

No. The padlock only confirms the connection is encrypted between your browser and the server. It says nothing about who runs the server or whether they’re honest. Most phishing sites in 2026 have valid SSL.

How can I tell if a website is a fake online shop?

Check the domain’s age, look at the reverse-IP neighborhood, and verify the URL against the brand’s official social media. Fake shops almost always fail at least one of those three checks.

Is it safe to enter card details on a new website?

Only after running the seven-step check. If the site passes, use a virtual card or a payment method with strong fraud protection. Avoid bank transfers or UPI to unknown merchants — those are much harder to reverse than card payments.

What should I do if I’ve already paid a scam site?

Contact your bank or card issuer within 24 hours and request a chargeback. File a complaint on the national cybercrime portal. Change any passwords you reused on the fake site. Speed matters — recovery rates drop sharply after the first day.

DomainScan runs every one of these seven checks in a single dashboard. Paste a URL, get an answer in under five seconds. Free, no signup, no rate limit for casual use.

Run the full 7-step scan
WHOIS, SSL, DNS, blacklist, reverse IP, headers — one paste, one verdict.
Try it
#website safety#fake website check#verify website#online payment fraud#phishing detection#whois lookup#ssl check
T
Spends his days looking at WHOIS records and his nights explaining what they mean.
RELATED POSTS
Security
SECURITYSeptember 21, 2026 · 10 min·0

47-Day SSL Countdown: Live Timer + What Changes in Every SC-081v3 Phase

A live countdown to 2029-03-15, the day publicly-trusted TLS certificates cap at 47 days. Read what SC-081v3 actually voted, the four phase dates (200 → 100 → 47), the 10-day DCV reuse rule, the 8× renewal math against a 32% CLM adoption rate, and a phase-by-phase playbook you can start this quarter.

RRahul
Security
SECURITYSeptember 10, 2026 · 10 min·0

BigBear 2.0 (Sept 2026): 3,331 Microsoft 365 Victims and the End of MFA-Only Defense

CloudSEK exposed the BigBear 2.0 phishing-as-a-service network — 5,137 stolen credential records, 461 organizations across 40+ countries, and 474 fully MFA-authenticated Microsoft 365 sessions hijacked from a fleet of 42 Vultr proxies. Here is why passwords plus MFA no longer stop credential theft, and how infrastructure-level scanning catches the pattern.

SSindhu
Security
SECURITYSeptember 10, 2026 · 9 min·0

Diwali 2026 Phishing Playbook: 828 Fake Ad Domains, 1-in-3 Indians Duped, and the UPI + Deepfake Trap

McAfee's 2025 Global Holiday Shopping Scams Study — the last full-year India benchmark before Diwali 2026 — found one in three Indians duped by festive-season scams, 37 percent suffering financial loss, average loss over ₹41,500. Quick Heal's Seqrite Labs identified 828 distinct phishing domains running Facebook Ads campaigns in one festive window. Here is the 2026 playbook — the brands attackers impersonate, the domain patterns Domainscan catches, and the 30-second check to run before every festive payment.

AAvinash
NEW POSTS, NO SPAM

One short email when we publish.

~2 posts a month, no marketing, unsubscribe in one click.