A few years ago, before I got properly paranoid about this stuff, I nearly typed my card details into a fake shoe store website. I say nearly because I got about halfway through the checkout form, paused for reasons I genuinely can’t fully explain even now, closed the tab, and Googled the site name out of some vague itch of doubt. Turned out there was an entire thread of people describing the exact same “ordered shoes, got nothing, card got charged twice” experience. I still think about how close I actually came to just clicking submit without that pause, and it’s honestly the reason I now have this slightly obsessive little checklist I run through before entering anything sensitive anywhere, which I figured was worth just writing down properly for once.

i almost typed my card into a fake shoe store. here

The first thing I actually look at, and I think most people already sort of know this one even if they don’t consciously check it, is whether the site is using HTTPS rather than plain HTTP  that little padlock icon next to the address bar. I want to be upfront though, because I think this gets oversold a bit in a lot of basic advice  HTTPS on its own just means your connection to the site is encrypted, it says absolutely nothing about whether the people running the site are trustworthy. Scammers can and do get HTTPS certificates too, it’s genuinely not hard or expensive anymore. So the padlock is a bare minimum, not a seal of approval. If a site doesn’t even have it, that’s an immediate red flag and I’d close the tab without a second thought. But having it just gets you to the starting line, not the finish line, and I think that distinction gets lost in a lot of the more surface-level advice floating around.

The next thing, and this is the one that actually caught the fake shoe site for a lot of people who fell for it before I dodged it, is looking really closely at the actual URL itself, character by character if you have to. Scam sites love using domain names that look almost identical to legitimate ones at a glance  swapping a lowercase L for a capital I, adding an extra letter, using a slightly different domain extension like .shop or .store instead of .com when the real brand only ever uses .com, or tucking the real brand name into a longer, weirder domain like “amazon-deals-today.net” instead of just amazon.com. I’ve genuinely trained myself to pause and actually read the full domain before doing anything sensitive on a site I haven’t used before, rather than just glancing at it and assuming it looks roughly right, because roughly right is exactly the trap.

Something I don’t see mentioned nearly as often as it should be is just checking how old a domain actually is, because this one single check has saved me from a couple of sketchy situations since. There are free WHOIS lookup tools where you can just type in a domain name and see when it was registered. If a site is presenting itself as an established, trusted brand but the domain was registered three weeks ago, that’s an enormous, glaring inconsistency, and it takes maybe fifteen seconds to check. I do this now almost reflexively for any site I’m about to buy something from that I haven’t personally used before, and I’d genuinely recommend building that same small habit, because scam sites tend to have a fairly short shelf life before they get reported and abandoned, so a suspiciously fresh domain paired with a professional-looking storefront is a pattern worth taking seriously.

I also make a point of actually looking for real, specific contact information before trusting a site with anything personal  a genuine physical address, a phone number that isn’t just a generic contact form with no other option, an actual company name you could theoretically search and find registered somewhere. Legitimate businesses, even fairly small ones, tend to have this stuff somewhere on the site, usually in the footer or an About page, because they’re not trying to be hard to trace. Scam operations, on the other hand, often deliberately keep this vague or missing entirely, because being hard to trace is sort of the whole point of the operation. If I land on a site and genuinely cannot find any real identifying information about who’s actually running it, that alone makes me hesitate, regardless of how polished the rest of the design looks.

Speaking of polish, actually  I used to assume a professional-looking website was itself a decent signal of legitimacy, and I’ve had to walk that assumption back considerably. Website templates are cheap and widely available now, and a scam site built on a nice template can look every bit as clean and trustworthy as a legitimate small business’s site, sometimes cleaner, honestly. So I’ve stopped treating visual polish as meaningful evidence of anything on its own. What I look at instead is whether the small details feel genuinely thought through  does the privacy policy actually read like it was written for this specific business, or does it look like generic filler text copy-pasted from somewhere else with the company name swapped in? Are product descriptions specific and detailed, or vague and slightly off in a way that feels translated or auto-generated? These smaller, less obvious signals have caught more sketchy sites for me over time than the overall visual design ever has.

For anything more high-stakes  a purchase involving a decent chunk of money, or a site asking for something more sensitive than just an email and shipping address  I’ll actually go check independent reviews, and specifically I try to look outside the site itself, because testimonials on the site’s own homepage are obviously not a neutral source. Searching the site’s name plus the word “scam” or “reviews” on Google, or checking a site like Trustpilot, tends to surface actual user experiences pretty quickly if there’s a real pattern of problems. I did this exact search for that shoe site after the fact and found the complaints within about ten seconds, which honestly made me feel a little silly for not doing it before I even opened the checkout page in the first place.

One habit I’d genuinely push back on, though it’s fairly common advice, is relying too heavily on browser warning popups as your main line of defense, because by the time a scam site has been flagged and blocked by Google Safe Browsing or a similar system, it’s already had time to actually scam a meaningful number of people first  that protection exists, and it does catch a lot, but it’s inherently reactive rather than something you can lean on as your primary check for a brand-new or lesser-known site. I still find it useful as a supplementary check, and there are free tools like Google’s Safe Browsing site status checker or VirusTotal’s URL scanner where you can paste a link and get a quick read on whether it’s already been flagged by security vendors, but I treat a clean result there as “no known red flags yet,” not as a genuine guarantee of safety, which is a subtle but important difference in how much weight I actually give it.

If I’m honest about the emotional side of all this, because I don’t think it gets talked about enough  there’s a real, slightly uncomfortable tension between wanting to move fast when you’re excited about a deal or a purchase, and forcing yourself to slow down enough to actually run through checks like these. Scam sites lean into that tension deliberately, with countdown timers and “only 2 left in stock” messaging designed specifically to short-circuit exactly this kind of careful pause. Recognizing that manufactured urgency for what it is has honestly become one of my most reliable personal red flags at this point  genuine businesses rarely need to rush you quite that aggressively, and if something’s pushing hard for you to skip the pause entirely, that pressure itself is usually worth listening to.