← All articles

How to tell if a website is real before you type your credit card in

Scam sites in 2026 look better than they've ever looked. AI generates the product photos, AI writes the reviews, AI clones the checkout page pixel-for-pixel from a real store. The result is a storefront that looks completely legitimate right up until your money is gone and the site vanishes a week later.

Here's what I check before I type a credit card number into a site I haven't used before. None of it requires being technical.

Look at the domain, not the page

The single most reliable tell is the domain in your browser's address bar. Real brands sell from their real domain. Nike sells from nike.com. Yeti sells from yeti.com. If you're staring at nike-outlet-sale.shop or yeti-clearance-usa.com or yeticoolers-official.store, you are not on Nike or Yeti's website, no matter how convincing the page looks.

Scammers register lookalike domains by the thousands because they're cheap and disposable. The tricks are things like adding a word ("-outlet", "-official", "-sale"), swapping the ending (.shop, .store, .co instead of .com), or slipping in an extra character you won't notice at a glance. Read the domain slowly, left to right, and compare it to what you'd actually type if you were going to the real brand directly.

Check how old the domain is

A brand-new domain selling name-brand goods at deep discounts is almost always a scam. A three-week-old website offering Yeti coolers at 70% off is not a warehouse clearance — it's a storefront that will be gone before your "order" was ever going to ship.

You can look up a domain's age for free at a site like whois.com. Type in the domain, look at the "Created" or "Registered" date. If it's a few weeks or a few months old and the store is selling established brands at prices nobody else is matching, close the tab.

Watch the URL during checkout

A common trick is a site that looks fine on the product pages but hands you off to a completely different domain when you click Buy. Real stores keep you on their own domain (or a well-known payment processor's domain like paypal.com or checkout.stripe.com) all the way through. If you click checkout and suddenly the address bar shows a random domain you've never seen, stop.

Look at what payment methods they accept

Legitimate online stores take Apple Pay, PayPal, Google Pay, and major credit cards. Those payment methods exist partly because they give you dispute rights — if the store never ships the item, you can charge it back.

Scam sites don't want that. So they push payment methods that can't be reversed: wire transfers, Zelle, Venmo to a personal account, cryptocurrency, or — the classic — "pay us in gift cards." If a store selling physical goods is steering you toward any of those, it's a scam. There's no other reason for a real business to work that way.

Reverse image search the product photos

If a product photo looks a little too polished, right-click it, save it, and drop it into Google Images or TinEye. If the same image is showing up on the real brand's site, on a dozen unrelated "stores," or on a stock photo site, you're looking at a scraped or AI-generated listing, not an actual store's inventory.

The ad trap

This is the pattern that catches the most people, including sharp people. You're scrolling Instagram, TikTok, or Google, and an ad shows you something you'd actually buy at a price that seems too good. You tap it. You end up at a store you've never heard of, with a clean-looking site and glowing reviews. You check out.

Sponsored placements can be bought by anyone, and the platforms do a mediocre job of policing them. So the rule I use is simple: if I got to a store from an ad, I verify the domain before I type anything. If the ad claims to be an official brand sale, I open a new tab, go to the brand's real website directly, and see if the sale exists there too. If it doesn't, the ad was a fake.

The padlock icon means nothing about trust

One last thing, because this one confuses people. The little padlock icon next to the URL does not mean the site is legitimate. All it means is that the connection between your browser and the site is encrypted. Scammers have padlocks too — encryption certificates are free and take about five minutes to set up. A padlock tells you nobody's eavesdropping on you handing your credit card to the scammer. It doesn't tell you anything about who's on the other end.

Leave a comment

Comments are moderated — I read every one. Your email is only used if I need to follow up; it isn't published. Links aren't allowed.

← All articles