← Back to blog
|7 min read

How to Tell if a Website is Fake: 9 Warning Signs to Check Before You Click

phishingwebsite securitytips

Phishing websites are responsible for billions of dollars in losses every year. These sites impersonate banks, online stores, social media platforms, and government agencies to trick you into handing over your login credentials, credit card numbers, or personal information.

The good news is that fake websites almost always leave clues. Here are nine warning signs you can check before entering any sensitive information.

1. Check the URL Carefully

This is the single most important check. Scammers create domains that look nearly identical to the real thing at a glance.

Common tricks to watch for:

  • Letter substitutions: paypa1.com (number 1 instead of letter l), arnazon.com (rn instead of m)
  • Extra words: amazon-login-secure.com, paypal-verify-account.com
  • Subdomain tricks: amazon.com.secure-checkout.xyz (the real domain is secure-checkout.xyz, not amazon.com)
  • Wrong TLD: facebook.net instead of facebook.com, chase.io instead of chase.com
  • Hyphens and extra characters: face-book.com, g00gle.com

Always look at the root domain. Everything before the first single slash is the domain, and the part just before the TLD (.com, .org) is what matters.

2. Look for HTTPS and the Padlock

While HTTPS alone does not guarantee a site is legitimate (scammers can get SSL certificates too), the absence of HTTPS on a site asking for login credentials or payment info is a major red flag.

What to check:

  • The URL should start with https:// not http://
  • A padlock icon should appear in the address bar
  • Clicking the padlock should show a valid certificate

If a banking site, payment processor, or online store does not have HTTPS, do not enter any information.

3. Examine the Design Quality

Scammers clone real websites, but they rarely get every detail right. Look for:

  • Blurry or pixelated logos
  • Inconsistent fonts or colors compared to the real site
  • Broken links in the navigation (menus, footer links that go nowhere)
  • Missing pages (the "About Us" or "Contact" page is empty or does not exist)
  • Stock photos that do not match the brand

Open the real website in another tab and compare them side by side. Differences in layout, spacing, and branding often become obvious.

4. Read the URL on Payment and Login Pages

Legitimate companies host their login and payment pages on their own domain. Be suspicious if:

  • You are redirected to a completely different domain to sign in
  • The payment page URL does not match the store you were shopping on
  • The URL contains long strings of random characters

For example, if you are shopping on a site and the checkout page suddenly switches to a different domain, close the tab immediately.

5. Check for Contact Information

Real businesses provide real contact information. Fake sites often have:

  • No phone number or physical address
  • Only a contact form with no other way to reach them
  • A generic email address (gmail.com, yahoo.com) instead of a company domain
  • An address that does not exist (search it on a map)

If the only way to contact a business is through a web form with no phone number, email, or address, proceed with caution.

6. Look for Spelling and Grammar Errors

Professional companies invest in their web presence. Frequent spelling errors, awkward grammar, or mixed languages on what claims to be a major brand's website is a strong indicator of a fake.

Pay special attention to:

  • The homepage and product descriptions
  • Legal pages (Privacy Policy, Terms of Service)
  • Error messages and form labels

A single typo is not necessarily suspicious, but multiple errors throughout the site suggest it was thrown together quickly without professional oversight.

7. Investigate the Domain Age

Phishing sites are usually created days or hours before they start being used. You can check when a domain was registered using a WHOIS lookup tool.

Red flags:

  • Domain registered within the last few days or weeks
  • Registration information is hidden or uses a privacy service
  • The registrant country does not match the business location

A brand-new domain claiming to be a well-established bank or retailer is almost certainly fake.

8. Watch for Pressure Tactics

Fake websites often create artificial urgency to prevent you from thinking critically:

  • Countdown timers ("offer expires in 3:42")
  • Limited stock warnings ("only 2 left!")
  • Pop-ups that try to prevent you from leaving
  • Claims that your account will be locked if you do not act now

Legitimate businesses do run sales and promotions, but they do not use aggressive tactics to prevent you from closing the page or taking time to think.

9. Test with a Fake Login

If you suspect a login page is fake, try entering a completely made-up email and password. A real login system will reject invalid credentials. Many phishing pages accept anything you type because their goal is simply to capture whatever you enter.

Do not use your real credentials for this test. Use something obviously fake like test@test.com with the password "fakepassword123."

Use Technology to Help

Even careful users can be fooled by sophisticated phishing sites. PhishArmor adds an extra layer of protection in two ways:

Always-on safety indicator: As you browse, PhishArmor checks every website against known phishing patterns, lookalike domains, and suspicious signals. If something looks off, the extension icon shows a warning badge. This happens automatically with no action required.

Deep AI scanning: Click "Scan This Page" in the PhishArmor popup for a thorough analysis. The AI evaluates the domain, forms, links, page content, and dozens of other signals, then gives you a clear scam score from 0-100.

The Bottom Line

Before entering any personal information on a website, take 10 seconds to check the URL, verify HTTPS, and look for obvious signs of a fake. If anything feels off, trust that instinct and navigate to the real site directly by typing the URL yourself.

For an extra safety net, install PhishArmor. The always-on protection catches suspicious sites in real time, and the AI-powered scan gives you confidence before you click, type, or trust.

Try PhishArmor Free

Scan emails and webpages for phishing with AI-powered detection. 10 free scans per month, no credit card required.

Install PhishArmor