You found something you want online. The price looks good, the website looks professional, and there’s a padlock icon in the address bar.
But is it safe to buy?
That padlock used to mean something but today it doesn’t. Scammers can get SSL certificates for fake stores just as easily as real businesses do. The padlock just means your connection to the site is encrypted but it says nothing about whether the site itself is legitimate.
Knowing how to shop online safely means knowing what to actually look for. The FTC reports that Americans lost over $12.5 billion to fraud in a 2024, with online shopping scams among the top categories. This guide gives you the real checks, ones that actually separate a safe website from a fake one.
1. The myth you need to forget first: HTTPS doesn’t mean safe
Almost every “how to shop online safely” guide still leads with “look for the padlock and HTTPS.” It’s outdated advice.
HTTPS means the connection between your browser and the website is encrypted. That’s good, it means no one can intercept your data in transit. But it says absolutely nothing about what the website does with your data once it arrives.
A scammer running a fake store can apply for an SSL certificate in minutes. Their fake site gets the padlock. Your data travels securely from your browser to their server where they steal it.
The padlock is a necessary but not sufficient sign of safety. Use it as a minimum check, not a green light.
Read more- how to spot phishing emails?
2. How to tell if a website is safe before you buy: 8 real checks
These are the checks that actually matter in 2026.
1. Look at the domain name carefully
The single most reliable way to spot a fake website is the URL. Scammers create convincing lookalike domains that are easy to miss at a quick glance:
amaz0n.com(zero instead of the letter O)amazon-secure-checkout.com(real company name in a fake domain)amazon.com.au.secure-login.net(real domain is everything after the last dot before the slash so this issecure-login.net, not amazon)
Before you buy from any site, read the full URL carefully. The real domain is the last part before the first single slash. If it doesn’t exactly match the official company name with no additions, don’t enter your details.
2. Check how old the website is
Fake shopping sites are often created days or weeks before they launch a scam. You can check a website’s age for free using a tool called Whois.
Go to whois.domaintools.com enter the website address, and look at the “Created” date. A website claiming to be an established retailer that was created three weeks ago is almost certainly a scam.
A brand-new website isn’t always a scam, but if a site claims to have served customers for 15 years while the domain was registered last month, that’s a major warning sign.
3. Use VirusTotal to scan the website before you buy
Go to virustotal.com, click the URL tab, paste the website address, and hit enter. VirusTotal runs the URL against 90+ security scanners simultaneously and tells you within seconds if any of them have flagged the site as malicious, phishing, or suspicious. Its free to check.
A clean result doesn’t guarantee the site is legitimate. New scam websites may not have been detected or flagged yet. However, if VirusTotal shows any security warnings, treat them as a major red flag. Avoid buying from a website that has been flagged, no matter how professional or trustworthy it appears.
4. Search for the website plus the word “scam” or “reviews”
Before buying from any site you haven’t used before, search Google for the website name followed by “scam,” “review,” or “legit.” Look at Trustpilot, Reddit, and the Better Business Bureau for patterns in what people report.
One or two negative reviews are normal for any business. A flood of reviews saying “I never received my order,” “they took my money and disappeared,” or “the product looked nothing like the photo” is a major red flag.
Be aware that fake stores sometimes seed fake five-star reviews. Look for reviews on third-party sites like Trustpilot that the retailer doesn’t control, not just reviews displayed on their own website.
5. Check for real contact information
Legitimate businesses have real, findable contact details. Look for:
- A physical address (not just a PO Box)
- A working phone number or email address
- A clear returns and refund policy
- A privacy policy
Test it by sending an email or calling the number before you buy. If there’s no response, no working phone or the address leads nowhere on Google Maps, walk away.
Check for fake captcha also called click allow pop-up scam.
6. Check the About Us page
Scam sites are built fast. Their About Us pages are either blank, vague to the point of meaninglessness (“We are a global retailer committed to quality”), or copied from another site.
Look for specific details: where the business was founded, who runs it, how long it’s been operating. If the “About Us” page reads like it was generated by AI and tells you nothing concrete, treat that as a warning sign.
7. Look at the payment options
Legitimate retailers accept credit cards and reputable payment services like PayPal. If a site only accepts wire transfer, cryptocurrency, gift cards, or direct bank transfer, these are huge red flags. These payment methods offer little to no fraud protection, which is exactly why scammers prefer them.

8. Check if the deal is realistic
The “too good to be true” test still works. If a site is selling a $400 item for $79 with free shipping, ask yourself why. Legitimate retailers don’t discount that deeply on items that aren’t damaged or being discontinued.
AI-generated fake stores in 2026 are particularly common around major shopping events like Prime Day, Black Friday, the Christmas period. Scammers know that price-sensitive shoppers are less careful when they think they’ve found a bargain.
Today, scammers can build professional-looking online stores in a few hours using AI-generated product photos, fake reviews, and copied product descriptions. That’s why appearance alone is no longer a reliable way to judge whether a website is legitimate.
9. Use Google’s “About this result” tool
Next to any search result on Google, click the three dots. Select “About this result.” Google will show you when it first indexed the site and what other sources say about it. A site first indexed two weeks ago claiming to be an industry leader is a scam. A site with years of indexed history and external references is much more likely to be legitimate.
3. How to shop online safely: habits that protect you every time
Knowing how to shop online safely isn’t just about checking websites before you buy, it’s about the habits you build around every purchase. Even on a site you trust, these protect your money and your information.
Always use a credit card, not a debit card. Credit cards offer far stronger fraud protection than debit cards. If you’re charged for something you didn’t receive or authorize, your credit card issuer can reverse the charge also called a chargeback. Debit cards offer much weaker protection and the money comes directly from your bank account. For online shopping, always use a credit card if you have one.
Use PayPal or Apple Pay when available. These services act as a buffer between the retailer and your actual card details. The retailer never sees your card number just a payment authorization. If a dispute arises, PayPal’s buyer protection program gives you an additional layer of recourse.
Never save your card details on a new site. Only save payment details on sites you use regularly and fully trust major retailers like Amazon, your regular supermarket. Never tick “save card” on a new or unfamiliar site. If the site is breached, your saved card data goes with it.
Shop on your phone data, not public Wi-Fi. Public Wi-Fi in cafes, airports, hotels can be monitored. If you need to shop away from home, use your mobile data connection instead. If you regularly use public Wi-Fi, consider a VPN, which encrypts your connection regardless of the network you’re on.
Best VPN to protect your data and privacy even when travelling.
Type the website address yourself, don’t click links. Phishing links in emails, social media ads, and text messages can take you to convincing fake versions of real retailer websites. If you see an offer advertised somewhere, don’t click the link. Open a browser, type the retailer’s official address yourself, and look for the offer there.
Keep a record of your orders. Screenshot or email yourself the order confirmation, expected delivery date, and the retailer’s contact details. If something goes wrong, you’ll need this for a dispute or chargeback claim.
4. Red flags that a shopping site is fake
Even if a site passes most of the checks above, these individual signs should make you stop immediately:
- Prices dramatically lower than anywhere else for the same product
- No reviews anywhere outside the site’s own pages
- Only accepts wire transfer, crypto, or gift cards
- Pushes urgency: “Only 2 left!” or “Offer expires in 00:04:32” with a countdown timer
- No returns policy, or a returns policy that requires you to pay international return shipping to an address in another country
- Contact form only — no email address, no phone number
- The website domain was created recently (check Whois)
- AI-generated product photos that look slightly unreal (reverse image search them with Google Lens)
- Spelling errors or odd phrasing throughout the site
How Safe Is Your Digital Life?
Take our free 2-minute Digital Safety Check and find out how well you know the everyday habits that help protect your accounts, devices and personal information.
5. What to do if you’ve already bought from a suspicious site
If you’ve placed an order and now you’re not sure the site was legitimate:
- Contact your bank or credit card issuer immediately. Tell them you may have been scammed and ask about chargeback options. Act fast as there are time limits on disputes.
2. Report the site to Authority so that they can use these reports to identify and shut down scam operations.
- For US: report at ReportFraud.ftc.gov
- For Australia:- ReportCyber and Scamwatch
- UK: report to Action Fraud
- Canada: Canadian Anti-Fraud Centre
Also, remember you can visit your local police station to report fraud.
3. Report it to Google Safe Browsing at safebrowsing.google.com/safebrowsing/report_phish – this triggers a warning for anyone else who tries to visit the site in Chrome, Safari, or Firefox.
4. Monitor your card statements for the next 30 days. Scammers who have your card details often test them with a small charge before making larger purchases.
5. Change any passwords if you created an account on the site, especially if you used the same password elsewhere. Learn how to create strong password that you can actually remember.
While you’re at it, check out the signs of a compromised computer and learn what to do if you’ve been hacked. It could save you a lot of time, money, and headaches.
One more layer: protect your identity, not just your card
Card fraud can usually be reversed with a chargeback. Identity theft is harder to fix. If a fake site captures your name, address, email, and card details together, that combination is enough to open accounts in your name or file a fraudulent tax return.
Aura monitors your personal information across the dark web and financial accounts, and alerts you the moment your details appear somewhere suspicious giving you time to act before the damage is done.
The best way to shop online safely is to build a habit of pausing before you buy. Thirty seconds checking a URL, Googling the site name with “scam,” and verifying the contact details can save you hundreds of dollars and months of fraud recovery.
To help you further in your digital safety journey
Report a Facebook Scammer || How to use Public Wi-Fi safely || Phone safety Hub || Scam & phishing






I didn’t know that https: was outdated! Thanks for the tip to be extra careful!