Guides / Website

Is this website legit? A 3-minute check before you buy or sign up

Domain age, HTTPS, contact details, reviews, and the copy-paste tricks fake shops and fake login pages use. What to look at and in which order.

Updated 16 September 2026·2 min read

Flash sale! 70% off all sneakers - today only. Secure checkout. Pay by bank transfer for an extra 10% discount.

A site can look perfect and be three days old. Design is cheap; history isn't. Here's what to check, in the order that catches most scams fastest.

1. How old is the domain?

Most scam shops, fake login pages and "investment platforms" are registered days or weeks before they're used, and abandoned soon after. A legitimate business usually has years behind its domain. Scamed looks this up automatically when you paste a link (it queries the public registration record), and shows the registrar too.

A young domain isn't proof of a scam - real new businesses exist - but a young domain plus any of the signs below is a strong signal.

2. Is the domain what it claims to be?

Read the address carefully. paypal-secure-login.com is not PayPal. amazon.deals-today.shop is not Amazon. The real site is the part just before the first single slash: paypal.com, amazon.com. Brand names elsewhere in the address mean nothing.

3. Can you find a real company behind it?

  • A physical address and a phone number that work.
  • A company name you can find in a business register.
  • Terms, privacy policy and a returns policy that mention that company - not copied text with another shop's name still in it.

No contact details, or only a web form and a Gmail address, is a bad sign for anything you'd pay.

4. What do other people say?

Search the domain name plus "scam" and plus "reviews". Look at review dates - a flood of five-star reviews in one week is as suspicious as one-star reviews. Check Trustpilot and Reddit, not the testimonials on the site itself.

5. Signs on the page itself

  • Prices far below everywhere else.
  • Countdown timers, "only 3 left", "limited offer".
  • Payment only by bank transfer, crypto or gift card - no card, no PayPal (which would let you dispute).
  • A login form for a well-known brand on a domain that isn't that brand.
  • Spelling and grammar that a real company wouldn't ship.

HTTPS is not enough

The padlock only means the connection is encrypted. Scammers get free certificates in seconds. A padlock on a scam site is still a scam site.

Scamed fetches the page, checks the domain's age and registrar, looks for login and card forms, and tells you in plain language what it found.

More guides