You can’t judge a website by its design — scammers invest in professional templates. What they can’t easily fake are the technical and registration signals that exist independently of what the site shows you.
Check 1: Verify the Domain Age
Legitimate businesses have history. A website claiming to be an established retailer, service, or institution — but with a domain registered weeks or months ago — is almost certainly fraudulent.
How to check: Use DomainScan’s WHOIS lookup and look at the Registration Date field.
What to look for:
- Domain registered less than 6 months ago: treat with caution for any financial transaction
- Domain registered recently but site claims to be established: strong fraud signal
- Registration date matches their claimed founding year: reassuring signal
Fraudsters sometimes use older expired domains to bypass this check, but the registration history and traffic patterns will still look wrong.
Check 2: Check Blacklist Status
Phishing and scam sites get reported and listed on databases that track malicious domains. A site on Google Safe Browsing, Spamhaus DBL, or PhishTank has been confirmed as malicious by security researchers or automated systems.
How to check: Run the domain through DomainScan’s Trust Score checker. It queries 130+ reputation databases simultaneously.
- Any Google Safe Browsing listing: do not proceed — browsers will show a warning for a reason
- Phishing / malware listing: site has been confirmed malicious
- Spam listings: often associated with fraud operations
Check 3: Verify SSL Certificate Details
HTTPS alone is not a legitimacy signal (see FAQ above), but the SSL certificate details reveal who actually controls the domain.
How to check: Use DomainScan’s SSL checker and look at:
- Issued to: Does the organization name match who you expect?
- Certificate type: Domain Validated (DV) certificates are free and require no identity check — legitimate businesses often use OV or EV certificates that require identity verification
- Issuer: Is it a reputable CA (Let’s Encrypt, DigiCert, Comodo, Sectigo)?
- Expiry: Recently expired or very short-lived certificates are a signal
A major bank or retailer using a free Let’s Encrypt DV certificate is unusual. Most legitimate enterprises use OV (Organization Validated) or EV (Extended Validation) certificates.
Check 4: Look at the WHOIS Registration
The WHOIS record reveals who registered the domain, through which registrar, and sometimes their contact details.
How to check: DomainScan WHOIS lookup shows:
- Registrar: Is it a reputable registrar? Some registrars are associated with high abuse rates.
- Privacy protection: All private registrations look similar, so this alone isn’t suspicious — but combined with other signals, it matters.
- Registrant country: Does the claimed business location match where the domain is registered?
- Name servers: Are they using a major DNS provider, or an obscure one often associated with fraud hosting?
Check 5: Check the IP and Hosting Location
The IP address reveals where the site is hosted and whether the hosting infrastructure raises flags.
How to check: DomainScan’s IP lookup on the domain’s IP shows:
- Hosting provider: Is it a legitimate cloud/hosting provider?
- Country: Does it match where the business claims to be based?
- IP reputation: Is the IP on any reputation lists?
- Reverse DNS: Does the PTR record match what you’d expect?
A site claiming to be a US retailer hosted on a provider in an unusual jurisdiction, or sharing an IP block flagged for spam, warrants closer inspection.
Check 6: Check Security Headers
Legitimate websites implement basic security headers that protect their users. Sites that don’t bother are either poorly run or built quickly for short-term fraud.
How to check: DomainScan’s Security Headers checker shows which headers are present.
Key headers legitimate sites have:
Content-Security-Policy— prevents cross-site scripting attacks on their usersX-Frame-Options— prevents clickjackingStrict-Transport-Security— enforces HTTPS
A site with a security score of F (missing most headers) was likely not built by a security-conscious development team.
Check 7: Search for the Domain Outside the Site
Look for the domain (not the brand name — the actual domain) in external sources:
- Google: search
"exactdomain.com" reviewor"exactdomain.com" scam - Reddit:
site:reddit.com "exactdomain.com"— communities often report scam sites quickly - Trustpilot: search by domain or brand name
- ScamAdviser / WOT: dedicated scam site databases
This is particularly effective for fake shops — victims often leave reports before the site is blacklisted.
The 2-Minute Legitimacy Check
When time is short, run these three checks in this order:
- Domain age (/domain/lookup): If less than 6 months old and the site claims to be established, stop.
- Blacklist status (/domain/trust): Any phishing/malware listing, stop.
- SSL certificate details (/security/ssl-info): Does the org name match? EV/OV vs DV?
These three checks together catch the majority of phishing sites, fake shops, and fraud operations in about 90 seconds.
Red Flags Summary
| Signal | Risk Level |
|---|---|
| Domain < 3 months old | High |
| Listed on Google Safe Browsing or PhishTank | Critical — confirmed malicious |
| URL has a lookalike domain (paypa1.com, amaz0n.net) | Critical |
| No valid SSL certificate | High |
| Contact page has no verifiable details | Medium |
| Prices dramatically below market | High |
| Urgency tactics (“only 2 left!”) on a new site | Medium |
| Payment only via wire transfer, gift cards, or crypto | Critical |
| No independent reviews anywhere on the web | High |
If you see multiple red flags together, treat the site as fraudulent regardless of how professional it looks.
Common Questions
Does HTTPS mean a website is safe?
No. HTTPS means the connection between your browser and the server is encrypted — it says nothing about who operates the server. Phishing sites routinely use HTTPS and valid SSL certificates. A padlock icon confirms encryption, not legitimacy. Always check the domain name itself, not just the protocol.
What's the most reliable single check?
Domain age is hard to fake. Legitimate businesses operating for years have domains registered years ago. A site claiming to be a major retailer with a 3-month-old domain is almost certainly fraudulent. Combine domain age with blacklist status and you catch the vast majority of scam sites.
The site has 5-star reviews. Is it safe?
Reviews on the site itself prove nothing — they can be fabricated. Check independent review platforms (Trustpilot, Google Reviews, BBB) and look for patterns: all 5-star reviews within a short window, reviews with no detail, or a large number of 1-star reports that contradict the overall rating.
I already gave my details to a suspicious site. What now?
Act immediately: change any passwords you used on that site, especially if reused elsewhere. If you entered payment details, call your bank to flag potential fraud and monitor your statements. If you entered your email, watch for phishing follow-up. Report the site to Google Safe Browsing if it's fraudulent.