Most impostor sites do not appear to be fake. That’s the part that trips people up. Today’s scam page may look exactly like the real page, including the layout and even the same checkout procedure, and at times, even the live chat bubble in the corner typing a friendly greeting. That’s just under a million phishing attacks reported in the first quarter of 2026 and it’s only the ones someone reported. The difference doesn’t often show up in how refined a site appears, after years of seeing the same tricks being used in new packages. It appears in a very limited set of details in which most people do not think to look, and in understanding how you got there in the first place.
So skip the gut feeling. Do everything I do when I enter a card number, a password, or if crypto is a factor, approve a wallet connection.
How scammers actually get you there
Nobody would intentionally visit a fake site knowing how people actually get to one might help, as the tests below will only be useful if you will take time to perform them.
The most popular path at this time is a paid search ad. Sponsored placements for brand names are purchased by scammers and ads appear above the organic list, so if you’re in a hurry to download a wallet app or to track your order with a delivery company, the lookalike domain could be there first. The ad itself frequently passes review, as the destination page is replaced after it has been approved. The fix is a bit lame, but it works: When a sponsored result is related to logging in, downloading, or paying anything, ignore it and click the organic result instead, or enter the URL from memory.
With QR codes, you don’t get a URL to check out, you just get the same old ruse. The destination is whatever the owner of the sticker said it was, rather than what’s printed beneath the sticker, such as a sticker over a real code on a parking meter, a menu code at a restaurant table, or a flyer near a train station that you scan. Just like a link from a stranger, be wary of a QR code in a public place that asks for payment.
Then there’s the everyday version, a compromised or spoofed social media page with a giveaway or a text message disguised as a delivery notification or a direct message disguised as a customer support. This is all fairly basic. It works because you are not in the mindset to be assessing a site, checking a package, winning a prize or even responding to what appears to be your own bank. The tell is that what is driving you to click now, and blunting most of it is the habit.
Start with the URL, not the homepage
First, you should see what is actually displayed in the address bar. That’s what scammers hope you’ll do: most people scan a URL as they would while driving by a street sign, just enough to get what it’s about, not enough to notice the spelling mistake.
Once you know what to look for, the tricks remain relatively the same. A lowercase ‘l’ instead of a capital ‘I’. An “rn” used in place of an “m. A zero that takes the place of the letter O. An additional word or symbol stuffed into a well-known name, such as secure-paypal-login.com in place of paypal.com. Or a domain that doesn’t normally use .com at the end, such as .net or .biz. None of this is subtle once you’re actually looking for it. The issue is that very few people look, they click the link in the email or in the ad, and believe that it must be somewhere genuine.
Two habits catch most of this before it becomes a problem. When receiving an email, text or social message with a link to anything money-related, type the address yourself or use a bookmark you have saved in the past. When you come across a link to somewhere, hover over it or on mobile, hold down the link before tapping to see where it takes you.
HTTPS tells you less than people think
Everybody has been told to watch for the padlock icon, or for “https://” at the beginning of a web address, and that’s as far as advice goes. It means that your browser and server are using encryption. What it does not mean is that someone who is behind the site is legit.
This is the part that’s typically overlooked: In order to obtain a certificate, the process required paperwork and a fee, quietly screening out frivolous scammers. This is not the case anymore and hasn’t been for years. Services such as Let’s Encrypt provide certificates for free in a matter of minutes and don’t care which website is being operated. A fake page can be completed within an hour and still have the same padlock as your bank. Treat HTTPS as a floor, not a stamp of approval. It excludes one particular risk, data in transit that is not encrypted, and makes no comment on the others.
To get a little stronger signal, click on the padlock and look at the certificate details. A few companies still rely on Extended or Organization Validation certificates that show a validated company name instead of a generic name. It is not a death sentence if it isn’t present, as most sites don’t bother with these, but when it is there, it is a true sign, as it still requires money and paperwork, which scammers do not like.
Read the page like you’re looking for what’s missing
The easiest way to identify a scam was poor spelling and a sloppy layout. That signal has lessened, primarily because scammers now use the same writing and layout tools as everyone else and the copy can look pretty good. What’s harder to fake is completeness.
Real businesses accumulate boring pages over time: a return policy, shipping terms, a privacy policy that actually matches what the company does, contact details that go somewhere real. Scam sites are put up quickly and only once, so they will not include anything that does not directly benefit in getting a payment. Take notice of any page that lacks a return policy, or is just a few paragraphs about trust and innovation and no names are attached to the page. Legitimate companies are based on people, and most companies aren’t afraid to tell you who.
The same instinct applies to credibility claims, not just missing pages. When a site mentions partnerships, certifications, or familiar businesses, it’s not to be taken at face value, but is a quick two-minute search. Look for the claim in the context of the partner’s name and check to see if it is verified elsewhere on the internet. This is exactly what RCO Finance relied on prior to its demise: a slick website, a white paper with purported partners that never confirmed a relationship, and guaranteed returns touted as an AI trading advantage. If you want to see the pattern in full there’s a fuller account of how that one unfolded. It comes back up often enough to be worth noticing on sight, and as usual there are countless pressure tactics like: countdown timers that reset on refresh, ONLY 3 LEFT on each item, and prices that are 70% or more off on brand name items.
Payment options are worth checking before you ever reach a product page. If you can have it cancelled, a credit card, PayPal or buy now pay later option is what a legitimate retailer will want to be paid with. When the only payment methods are a wire transfer, a gift card or cryptocurrency, and there’s no card anywhere, it’s not a minor inconvenience. It’s the business model. Those approaches are irreversible once the currency has been sent, and this is the reason that scam operations rely on them.
The trust badges in the footer are no exception. Images like an award logo, a verified secure, or a payment processor’s seal are just images. Anybody can save one and stick it in a footer, and virtually everyone fails to follow the link to see what it’s really about. Click a badge if it’s actually being utilized in your choice. A sincere one leads you to the web page of the issuing organization to verify the listing. A fake one is not going anywhere, or anywhere that the badge can’t.
Confirm there’s an actual business behind it
This is the check that most people don’t bother to make because it requires an additional 2 minutes and is the one that nets the most scams.
Try searching for the company name with other words such as scam or complaints or reviews, and move past the first page of results because some operations purchase ads on their name just to push complaints down under. Look for a 5-star rating badge on the site, but don’t take it at face value, that’s just a picture and can say anything the site owner wants it to. Five-star reviews piled on in the same few days, all sounding like they were copied and pasted, are more of a red flag than a few real 3-star reviews for the shipping speed.
Then, search the domain name. A WHOIS look up, which is sometimes referred to as a domain age checker is free via ICANN’s WHOIS look up tool and clearly displays the date of a domain’s registration. Two weeks old does not necessarily mean it is a scam, there are plenty of good businesses that have new sites. It says it is an industry leader since 2009, but is only two weeks old – that tells you something, and it can be done in less than a minute. If the site claims a long history, the Wayback machine archive should be of interest as well, it will show what the site actually looked like and when it was first online, not what it claims today.
Then take this URL and feed it to a few free scanners. Google’s Safe Browsing check and VirusTotal will indicate if the address has been previously reported for phishing or malware and tools such as ScamAdviser give a trust score based on the age of the domain, where it was hosted and how many complaints had been received against it. Use that score as a jumping off point, not a diagnosis, a brand-new legitimate site can have a low score for no other reason than it’s new, hence, it’s best to know what is contributing to that score, rather than take it as gospel. There’s a fuller breakdown of how those scores actually get built, if you want the mechanics behind the number.
When it comes to crypto, it’s not a password problem
This is the part most general scam-checking advice skips entirely, and it’s the one I spend the most time on, because the mechanics are genuinely different from a fake login page.
A common scam site poses a threat when you enter your password or card number in a form. The risk with a cryptocurrency website is when you click on the wallet and approve a transaction, that click is more important than any password. The modus operandi of a fake airdrop, or NFT mint page, or staking page, is a request that you connect your wallet, which is harmless on its own. Then it asks you to approve something. Just like most click-through cookie notices, people click through that pop-up. What you’re really saying is that you allow a smart contract to withdraw tokens from your wallet at any point in time from now, whether that be weeks or immediately. The site may appear totally legitimate, as these drainer kits are sold, pre-built, to anyone who wants to buy one. Visual polish has not been a good indicator in crypto for quite some time now.
A few habits cut this risk down a lot. Don’t plug a wallet into a website that you arrived at via a DM, a rush message on Twitter about an exploit, or a message promising you a reward that you’re not expecting that act now before the airdrop closes is a scam, not a bonus. Don’t just click through the wallet pop up, actually read what it’s asking for permission to do. And if a token or contract address doesn’t sound familiar, a wallet scanner is just what it is for: to check an address before you connect to it, not after. It’s also a good idea to periodically review all your current approvals and revoke those you don’t recognize, as old approvals from sites you don’t recall remain active until you remove them.
If you already clicked, paid, or connected
Hurry up, since most of this will become more difficult to unwind the longer the time it sits.
If you’ve input card information, contact your bank and dispute the transaction before it is processed, rather than waiting for a statement to arrive in the mail. Change the password on all other sites that may have used it and enable two-factor authentication while you’re there if you re-used the password on the fake site. If you connected a wallet and approved something you no longer remember, treat that wallet as compromised, move remaining funds to a new wallet that uses a new seed phrase, revoke the approval of the old wallet, do not assume that it will expire on its own it will not. Notify google and the safe browsing team, or Microsoft’s equivalent form if it is likely to appear in Edge, to stop the next person who visits the page. If it involves any financial loss, report it to the FTC at ReportFraud.ftc.gov, if it appears to be an organized loss, report it to the FBI’s Internet Crime Complaint Center at IC3.gov as well. If they do follow up and say they can recover what you lost, be suspicious, by default, it is a common tactic.
None of this needs to be done by treating each and every web page as a threat. It involves the same few tests that the link that got to you, the URL, the certificate, the paper trail and, if it’s using crypto, what you’re actually approving, before you’re asked to pay, log in, connect. That’s when scam sites were created to get you. The fix is just to look closely anyway.