You're about to click a link, enter your card details, or sign up somewhere new — and a little voice asks, "is this website actually safe?" It's a smart instinct. Scam sites, phishing pages, and malware traps are everywhere, and they're better disguised than ever. The good news is that you don't have to guess: a few quick checks reveal whether a site is trustworthy or a trap. Here's how to tell if a website is safe before you visit it or hand over anything valuable.

1. Check for HTTPS — but don't stop there

The padlock and https:// in the address bar mean your connection to the site is encrypted. That's the baseline — but here's the crucial catch most people miss: HTTPS does not mean a site is safe or legitimate. Scammers can and do get free certificates for their phishing sites, so a padlock alone proves only that the connection is private, not that the site is honest.

So treat HTTPS as necessary but not sufficient. A site without it that asks for any personal data is an immediate red flag; a site with it still needs the rest of these checks.

2. Inspect the SSL certificate

Going a step further, you can look at the certificate itself to confirm it's valid and actually issued for the domain you're visiting. Our free SSL Certificate Checker shows the certificate's issuer, expiry, and which domain it covers — and our guide on how to check an SSL certificate explains what to look for. A mismatched or suspicious certificate is a warning sign worth heeding. (If a site throws a certificate warning, our guide on whether it's safe to bypass it covers when to walk away.)

3. Read the domain name very carefully

Scammers rely on you not looking closely. Before trusting a site, scrutinize the exact domain:

  • Look for misspellings and look-alikespaypa1.com, amaz0n.com, or g00gle.com. A single swapped character is a classic phishing trick.
  • Watch for subdomain tricks. In paypal.com.secure-login.ru, the real domain is secure-login.ru, not PayPal — the brand name is just a subdomain designed to fool you. Always read the domain from the last dot before the first slash.
  • Be wary of odd extensions and long, random-looking domains that impersonate a known brand.

The domain name is often the single biggest tell that a "familiar" site is fake.

4. Check the domain's age and registration

Most scam sites are thrown up quickly and taken down fast, so a brand-new domain impersonating an established brand is a major red flag. A WHOIS lookup shows when a domain was registered — our free WHOIS Lookup and our guide to checking a domain's registration show you how. If a "well-known store" is running on a domain registered two weeks ago, be very suspicious.

5. Check whether it's flagged or blacklisted

If a domain has been used for spam, malware, or phishing, it may already be on security blacklists. Checking a site's reputation before you interact with it is a smart move — our guide on how to check if a domain is blacklisted walks through it. A domain flagged across multiple lists is one to avoid entirely.

6. Look for trust signals — and red flags

Beyond the technical checks, judge the site itself:

  • Trust signals: a real physical address and contact details, a privacy policy and terms, professional design, working links, and legitimate customer reviews found off the site.
  • Red flags: lots of spelling and grammar errors, prices that are too good to be true, high-pressure countdown timers, demands for payment by gift card or bank transfer, and requests for unusual personal information.

Any one of these can be innocent; several together are a strong signal to leave.

7. Search for the site's reputation

A quick search for the domain name plus words like "scam," "review," or "legit" often surfaces other people's experiences. If a site is a known scam, chances are someone has already reported it. No reviews at all for a supposedly established business is itself a yellow flag.

Putting it together

A safe site generally checks these boxes: it uses HTTPS with a valid certificate for the correct domain, has a domain that's spelled correctly and has been around a while, isn't blacklisted, shows real contact and trust signals, and has a clean reputation when you search for it. A site that fails several of these — especially a brand-new look-alike domain asking for payment — should be avoided, no matter how convincing it looks.

If you simply want to confirm a site is genuinely reachable (and not a temporary fake), you can run it through our live website checker to see how it responds from a neutral server.

The bottom line

Telling whether a website is safe comes down to a handful of fast checks: confirm HTTPS but don't rely on it alone, inspect the SSL certificate, read the domain name character by character, check the domain's age and blacklist status, and weigh the site's trust signals against its red flags. None of these takes more than a minute, and together they'll catch the overwhelming majority of scams and phishing sites before you hand over anything you'd regret. When several signals point the wrong way, trust them — and close the tab.