Learn how to check a suspicious website before entering personal information. Discover URL, HTTPS, phishing, login, QR code and scam website warning signs.
A website can look completely normal and still be dangerous.
It may have a professional design, a familiar company logo, a contact page, customer reviews, and even a padlock next to the website address. None of those things, by themselves, prove that the site is trustworthy.
A suspicious website may be trying to collect your password, credit card number, phone number, address, or other personal information. Some fake websites are designed to look like real banks, shopping sites, delivery companies, social networks, government services, or popular online platforms.
The safest time to check a website is before you enter anything.
Here are practical checks you can use when you are not sure whether a website is legitimate.
Start with the URL.
Don't just look at the name shown on the page. Look at the actual website address in your browser's address bar.
Scammers sometimes create addresses that resemble legitimate websites by:
For example, if you are trying to visit a company called Example Bank, a website using a completely different domain should make you stop and investigate.
A suspicious URL does not automatically mean a website is a scam, but it is an important warning sign.
CISA has documented how attackers use URL tricks and other forms of URL obfuscation to make malicious websites appear legitimate.
You may have heard that you should look for HTTPS before entering personal information.
HTTPS is important because it helps encrypt information sent between your browser and the website. But it does not tell you whether the person operating the website is trustworthy.
A scam website can also use HTTPS.
So don't think:
"There's a padlock, so this must be a legitimate website."
Instead ask:
"Who operates this website, and how did I get here?"
That is a much more useful question.
Think about what happened immediately before you opened the site.
Did you type the address yourself?
Did you use a bookmark?
Did you click a link in an unexpected email?
Did you receive the link in a text message?
Did you scan a QR code?
Did you click an advertisement?
Did you find it through a search engine?
This matters because scammers often use messages and links to direct people toward fake websites.
The FTC advises consumers not to click unexpected links in emails or text messages and recommends contacting a company through a website or phone number that you already know is genuine.
If you receive a message claiming to be from your bank and it contains a link asking you to log in, don't use that link.
Open your bank's official app or type the known website address yourself instead.
Many people assume that the first result in a search engine must be the official website.
That isn't always true.
Search engines can display paid advertisements and other results that may not be the website you were actually looking for.
The FTC has warned that scammers sometimes use paid search results to impersonate businesses and government services or direct people to fraudulent websites.
Before entering sensitive information, make sure the website actually belongs to the organization you intended to visit.
If you already know the company's official web address, typing it directly into your browser can be safer than clicking an unfamiliar search result.
Suppose you receive a message saying:
"Your bank account needs verification."
You click the link and arrive at a page that looks like your bank.
Don't immediately enter your username and password.
Look at the website address.
Does the domain actually belong to your bank?
Does the page contain unexpected spelling mistakes?
Does the logo look distorted?
Are you being asked for information the company normally wouldn't request?
A fake website can copy logos, colors, layouts, and other visual elements from a legitimate company.
The appearance of the page is therefore not enough to establish that it is genuine.
If you are checking an unfamiliar online store, our guide on fake online shopping websites covers store-specific warning signs in more detail.
A legitimate organization should normally provide some reasonable way to contact it.
Look for:
But don't make the mistake of thinking that a contact page proves a website is legitimate.
Scammers can create fake contact information too.
If you are checking a bank, retailer, government service, or other established organization, compare the contact information with information from a trusted source.
If a website asks for personal information, look for its privacy policy.
You don't necessarily need to read every word, but check whether the policy appears to belong to the same organization.
Watch for obvious inconsistencies, such as a privacy policy mentioning a completely different company or website.
Also consider what information the website is asking for.
If a simple service wants your full financial information, government identification number, password, or other sensitive data without a clear reason, stop and investigate before continuing.
A good rule is simple:
Don't provide more information than the service actually needs.
A suspicious website may try to rush you.
You might see messages such as:
"Your account will be closed today."
"Verify your identity immediately."
"Your payment has failed."
"Your account has been compromised."
"Complete verification within 10 minutes."
The goal is to make you worry about what will happen if you don't act immediately.
The FTC identifies unexpected contact, pressure to act quickly, and requests for personal or financial information as common scam warning signs.
If a website is pressuring you to enter sensitive information immediately, slow down.
You can always leave the page and verify the situation separately.
Before filling out a form, stop and look at every field.
Does the website really need this information?
For example, a simple newsletter subscription may need an email address.
It probably doesn't need your bank account number.
A website asking you to create an account may reasonably need a password.
It should not automatically need information that has nothing to do with the service.
Be especially careful when a suspicious website asks for:
The FTC warns that phishing scams commonly attempt to steal passwords, account numbers and other personal or financial information.
This is especially important for login pages.
A fake login page can look almost identical to the real one.
The safest approach is to reach important accounts through a route you already trust.
For example, instead of clicking an unexpected "verify your account" link, open the official app or type the known website address yourself.
This is particularly important for:
If you reuse the same password on multiple websites, consider changing that habit too. A stolen password from one website can put other accounts at risk.
The FTC recommends using strong passwords and multi-factor authentication to add protection to online accounts.
A website or message may ask you to enter a one-time verification code.
Sometimes that is completely normal.
But if you reached the website through an unexpected message, be extremely careful.
A scammer may be trying to use that code to complete a login or transaction while you are unknowingly helping them.
Never assume that because a page says "security verification" it is automatically legitimate.
Verify that you are on the genuine website before entering the code.
Some websites display alarming messages such as:
"Your device is infected."
"Your account has been hacked."
"Critical security warning."
"Call support immediately."
"Click here to remove the virus."
Don't automatically believe these warnings.
A website can display a fake security alert simply to scare you into clicking something, downloading software, or contacting a scammer.
The FTC recently warned about fake CAPTCHA pages that can trick people into carrying out actions that install malware.
A browser page telling you that your computer has a serious problem is not the same thing as a verified security notification from your device manufacturer or security software.
These fake warnings often lead to a fake customer service number, where someone pretending to be support tries to take your money or access your device.
If you are still unsure, investigate the website before entering information.
Search for the domain or company name along with words such as:
Don't rely on just one review.
Look for information from several independent sources.
Also check whether the company has an established online presence and whether its official accounts and website point to the same domain.
The absence of complaints does not prove that a website is legitimate, especially if the website is new.
QR codes are convenient, but you shouldn't automatically trust where they take you.
A QR code can direct you to a fake website that looks like the real service.
The FTC recommends checking the URL after scanning an unexpected QR code and being cautious about QR codes received through unexpected emails or text messages.
If a QR code tells you to log into an account or confirm payment information, consider opening the company's official app or website directly instead.
You don't need to prove that a website is a scam before deciding not to enter your information.
If something doesn't feel right, leave the page.
You can investigate later.
This is especially important when the website is asking for information that could affect your money, identity, or important online accounts.
There is almost never a good reason to let a stranger's website rush you into giving away sensitive information.
Before entering personal or financial information, ask yourself these questions:
If several answers make you uncomfortable, don't enter your information.
Close the page and verify the website through a trusted source.
Don't panic, but don't ignore it either.
What you should do depends on what information you entered.
If you entered a password, change it through the legitimate website or official app. If you reused that password elsewhere, change it on those accounts too.
If you entered banking or card information, contact your bank or card provider using a phone number or website you know is genuine.
If you entered a verification code, check your account immediately for unusual activity.
If you downloaded something from a suspicious website, update your security software and run a security scan.
The FTC recommends acting quickly if you believe your personal information has been compromised.
Yes.
This is why checking only the design is not enough.
A fake website can copy the appearance of a legitimate service and use convincing logos, images, language, and forms.
The more useful checks are the ones that are harder for a scammer to fake, such as verifying the domain, checking how you reached the site, independently confirming the organization, and thinking carefully about what information the website is requesting.
If you reached a suspicious website because of an email or text message, the message itself may contain useful warning signs.
You can use the Scamlify Email Scam Checker to analyze a suspicious email or the Scamlify SMS Scam Checker to check a suspicious text message.
These tools can provide another layer of checking, but they should not replace independent verification when you are about to enter sensitive information.
If you are unsure about a website, the safest approach is simple:
Stop. Check the address. Verify the company independently. Then decide whether the website deserves your information.
Check the website address, how you arrived there, what information it requests, and whether you can independently verify who operates it. Be especially careful if the website creates urgency or asks for sensitive information unexpectedly.
No. HTTPS protects the connection between your browser and the website, but it does not prove that the website itself is legitimate. A scam website can also use HTTPS.
Don't rely on appearance alone. Open your bank's official app or type the bank's known website address yourself and log in from there. This avoids relying on an unexpected link that could lead to a fake login page.
Check the domain, research the company independently, examine what information the site wants, look for suspicious pressure or warnings, and verify that you reached the genuine website through a trusted source.
Yes. Search results can include paid advertisements and other results that may not be the official website you intended to visit. The FTC has warned that scammers use search results to impersonate businesses and government services.
No. The padlock indicates an encrypted connection. It does not verify the identity or honesty of the website operator.
First make sure you are on the genuine website and that you initiated the login or transaction yourself. Never enter a verification code into a suspicious page simply because it calls the request a security check.
Act according to the type of information you entered. Change compromised passwords through legitimate websites, contact your bank if financial information was exposed, check your accounts for unusual activity, and scan your device if you downloaded something suspicious.
Yes. QR codes can be used to direct people to spoofed websites designed to collect personal information. Check the URL after scanning and use the company's official website or app when possible.
If you already know the company's official web address, type it yourself or use a trusted bookmark. For important accounts such as banking or email, using the official app can also help you avoid following a fraudulent link.