A friend of mine almost lost ₹38,000 last month. The website looked perfect — same logo as the brand she trusted, same product photos, same checkout flow. The only thing that gave it away was a tiny detail in the URL she noticed three seconds before clicking Pay. She got lucky. Most people don’t.
Fake websites have stopped looking fake. Scammers buy real SSL certificates, copy entire product catalogs, and pay for Google Ads that put their phishing pages above the real brand. If your only defense is “does it look legit,” you’ve already lost.
Below are seven checks you can run on any website in under a minute each. None of them require technical skill. All of them have stopped someone, somewhere, from losing money this week.
Why a quick check matters
The economics of online fraud have flipped. A scammer can register a domain for $2, clone a brand in an hour, and run paid ads to it the same day. The cost of building a fake site is now lower than the cost of a single successful payment from it. That math is why fake checkout pages have exploded since 2024.
The good news: scammers cut corners. They reuse infrastructure, they skip steps real businesses can’t skip, and they leave fingerprints in places most users never look. Seven of those places are below.
1. Look up the domain age
The single highest-signal check. Most scam sites are less than 90 days old. Real businesses, even new ones, usually have at least a few months of history by the time they’re selling anything online.
Run a WHOIS lookup. You’re looking for the Creation Date field. If it’s less than three months ago and the site is asking you to pay for a brand-name product, treat that as a serious warning.
2. Inspect the SSL certificate
The padlock icon means the connection is encrypted. It does not mean the site is honest. Scammers know this and use it against you — most phishing sites in 2026 have valid SSL because free certificate authorities make it trivial.
What you actually want to look at:
- Issuer. A Let’s Encrypt certificate on a checkout page handling thousands of orders is suspicious. Real retailers usually pay for higher-validation certificates.
- Validity window. Certificates issued within the last week, on a domain less than a month old, paired with payment forms = strong red flag.
- Subject name. Make sure the certificate’s
Common Nameactually matches the domain you’re on. Mismatches are rare but lethal.
3. Check the nameservers
Real businesses use a small number of well-known DNS providers: Cloudflare, Route 53, Google Cloud DNS, GoDaddy. Scam sites often use obscure nameservers tied to bulletproof hosting, or run their own NS on the same IP as the website. Both are unusual for a legitimate brand.
It’s also worth checking whether the nameservers have changed recently. A site that switched nameservers in the last week, after months of stability, has either had a serious infrastructure migration — or been compromised.
4. Run a blacklist scan
Major blacklists — Spamhaus, SURBL, URIBL, Google Safe Browsing — share data with each other and update fast. If a site has been reported for phishing, malware, or spam by enough people, it usually ends up on at least one of these lists within 24 hours.
A clean blacklist result doesn’t mean the site is safe. But a hit on multiple lists is a hard stop. Close the tab.
5. Reverse-lookup the IP
Find the IP address the website resolves to, then look up what other domains share that IP. A real business will usually share an IP with a handful of related properties (their own subdomains, a CDN, maybe a sister brand). A scam site frequently shares its IP with dozens of unrelated, equally suspicious-looking domains — often clones targeting other brands.
If a single IP is hosting amaz0n-deals.xyz, flipkart-sale.top, and nike-india-offer.shop all at once, you’re looking at a scam farm. Don’t do business with anything on that IP.
6. Read the HTTP headers
Headers are the metadata a server sends back with every page. They tell you which web server the site runs, what security policies it has, and sometimes what platform the store was built on. They’re also where scammers get sloppy.
What to watch for:
- Missing
Strict-Transport-Securityon a checkout page (legitimate retailers ship this by default). - A
Serverheader that saysnginxon a cheap default port, with no CDN in front. Real e-commerce sites are nearly always behind Cloudflare, Fastly, Akamai, or similar. - Headers that leak the original CMS — e.g.,
X-Powered-By: WordPresson a page claiming to be a global retailer.
7. Cross-check the brand
The last step is the simplest and the one most people skip. Open a new tab. Go to the brand’s official social media — Instagram, X, LinkedIn. Look at the link in their bio. If the domain you’re about to pay on doesn’t match that link, you’re on a fake site.
A surprising number of scam sites get caught at exactly this step. They’ve copied the website perfectly, but they can’t copy the brand’s verified social presence — and they’re counting on you not checking.
The 60-second checklist
Print this. Tape it next to your monitor. Run it before any payment to a site you haven’t paid before.
- Is the domain older than 90 days?
- Does the SSL certificate match the domain and look reasonable for the business size?
- Are the nameservers from a known DNS provider?
- Is the domain clean across major blacklists?
- Does the IP host a sensible number of related domains, not dozens of fake-looking ones?
- Do the HTTP headers look like a real e-commerce setup?
- Does the brand’s real social bio link to this exact domain?
FAQ
Does the green padlock mean a website is safe?
No. The padlock only confirms the connection is encrypted between your browser and the server. It says nothing about who runs the server or whether they’re honest. Most phishing sites in 2026 have valid SSL.
How can I tell if a website is a fake online shop?
Check the domain’s age, look at the reverse-IP neighborhood, and verify the URL against the brand’s official social media. Fake shops almost always fail at least one of those three checks.
Is it safe to enter card details on a new website?
Only after running the seven-step check. If the site passes, use a virtual card or a payment method with strong fraud protection. Avoid bank transfers or UPI to unknown merchants — those are much harder to reverse than card payments.
What should I do if I’ve already paid a scam site?
Contact your bank or card issuer within 24 hours and request a chargeback. File a complaint on the national cybercrime portal. Change any passwords you reused on the fake site. Speed matters — recovery rates drop sharply after the first day.
DomainScan runs every one of these seven checks in a single dashboard. Paste a URL, get an answer in under five seconds. Free, no signup, no rate limit for casual use.