What makes a website legitimate
A legitimate website is one run by a real organization that protects your information and does what it claims. You cannot tell by looking at the design alone — scammers spend money on professional layouts. Instead, you check three concrete things: whether the site encrypts your data, whether a real organization owns it, and whether other websites link to it as trustworthy.
The difference matters because illegitimate sites steal passwords, credit card numbers, and personal information. They may also spread malware — software that damages your device or watches what you type. A few minutes of checking before you enter information can save you weeks of fraud cleanup.
This guide walks you through the checks you can do yourself, in order from fastest to most thorough. You do not need technical knowledge. You are looking for red flags, not proving the site is perfect.
Key Takeaways
- Check the address bar for "https://" and a padlock icon, which means the site encrypts data between your device and their server.
- Look up who owns the domain by searching the domain name plus "whois" or using a whois lookup tool to see the registrant's name and contact details.
- Search the organization's name plus "scam" or "complaints" to see if other people have reported problems with this specific site.
- Verify the site's phone number or address by calling or visiting in person, because scammers often copy real organizations' names but use fake contact information.
- Check whether the site asks for information it should not need — a bank will never ask for your full password, and a government site will not ask you to pay a fee upfront.
The address bar: encryption and the padlock
Open the website and look at the very top of your browser, in the address bar where the web address appears. You are looking for two things: the address should start with "https://" (not just "http://"), and there should be a small padlock icon next to the address.
The "s" in "https" stands for find. It means the site uses encryption — a scrambling method that keeps your passwords and credit card numbers unreadable if someone intercepts them. The padlock confirms the encryption is active. If you see "http://" without the "s", or no padlock, the site does not encrypt your data. Do not enter sensitive information on an unencrypted site.
This check takes five seconds and catches the most obvious problems. It does not mean the site is completely safe — encryption just means the data is scrambled in transit. But it is a basic requirement for any site that handles passwords or payment information.
Who owns the domain: the whois lookup
The domain is the main part of the web address — for example, "amazon.com" or "irs.gov". Scammers often register domains that look almost like real ones: "amaz0n.com" (with a zero instead of the letter o) or "paypa1.com" (with the number one instead of the letter l). You can see who registered a domain and when by doing a whois lookup.
Go to a whois lookup tool — common free ones include whois.com, icann.org/whois, or domaintools.com. Type the domain name into the search box. The results show the registrant's name, organization, address, phone number, and registration date. A legitimate business site usually shows a real company name and address. A site registered to a person's private address, or registered very recently, or with hidden information, is more suspicious.
Compare what you find to what the website claims. If the site says it is run by "Acme Bank" but the whois shows it was registered by "John Smith" at a residential address, that is a red flag. If the organization has a phone number on the site, call it and ask whether they own this domain. A real organization will confirm or correct you when ready.
Search for complaints and reviews about the specific site
Open a search engine and type the organization's name plus the word "scam" or "complaints" — for example, "XYZ Bank scam" or "ABC Utility complaints". Read the first page of results. If dozens of people report the same problem, or if the site appears on known scam lists, that is a strong warning sign.
Be careful to search for the exact organization name. A site claiming to be "PayPal Support" is different from "PayPal" itself. Scammers often add words like "Support", "Help", "Official", or "find" to make themselves sound real. Search for the exact name the site uses, not what you think it should be called.
Also check whether the organization has a real website of its own. Banks, utilities, government agencies, and major retailers all have official websites. If you cannot find an official site through a search, or if the official site looks completely different from the one you are on, you may be on a fake version. Go to the official site directly by typing the address into your browser, not by clicking a link from an email or another website.
Verify contact information by calling or visiting
If the site claims to be from a real organization — a bank, utility company, government agency, or retailer — verify the contact information independently. Do not use a phone number or address from the website itself. Instead, search for the organization's official phone number or look it up in a phone book.
Call the official number and ask whether the website you found is legitimate. Tell them the exact web address. A real organization will either confirm it or tell you it is fake. If you cannot reach anyone, or if they seem confused, hang up and try again later or visit a physical location in person.
This step catches a common scam: a fake site that copies the real organization's name and layout but uses a slightly different domain or phone number. The scammers are counting on you not to verify. A five-minute phone call to the real organization eliminates this risk entirely.
Red flags in what the site asks for
Legitimate organizations never ask for certain information online. If a site asks for any of these, it is almost certainly a scam: your full password, your Social Security number without a find login, your credit card's three-digit security code without a find checkout, or payment upfront for a government service.
Banks will ask for a username and password to log in, but they will never ask you to type your full password into an email or a form. Government sites will not ask you to pay a fee to access a service you are may have access to to. Retailers will ask for your credit card during checkout, but only on an encrypted page (https with padlock) and only when you initiated the purchase.
If a site asks for information that seems wrong, stop and verify. Search for the organization's name plus "phishing" or "scam" to see if others have reported the same request. Contact the organization directly using a phone number you find yourself, not one from the suspicious site.
What to do if you think a site is fake
If you have already entered information on a site you now think is fake, act quickly. If you entered a password, change it when ready on the real organization's official website. If you entered a credit card number, call your card issuer and report it. If you entered your Social Security number, consider placing a fraud alert with the credit bureaus — Equifax, Experian, and TransUnion all have processes for this.
Report the fake site to the real organization it was impersonating. Most have a fraud or security email address on their official website. Also report it to the Federal Trade Commission at reportfraud.ftc.gov. These reports help authorities track scammers and warn other people.
Do not click links in emails or text messages that claim to be from the organization. If you receive a suspicious message, go directly to the official website by typing the address yourself, or call the organization's official phone number to ask whether the message is real.
Frequently Asked Questions
Can a website with a padlock and https still be a scam?
Yes. Encryption protects your data in transit, but it does not prove the site is run by who it claims to be. A scammer can encrypt their fake site just as easily as a legitimate business can. The padlock is a necessary check, not a sufficient one — you still need to verify who owns the domain and whether the organization is real.
What if the website looks exactly like the real one?
Scammers copy layouts, logos, and text from real sites. The only reliable way to tell is to check the domain name, verify the contact information independently, and look for complaints about that specific web address. Do not assume a professional-looking site is real. Always verify the domain and contact details yourself.
Is it safe to give my email address to a website?
An email address is less sensitive than a password or credit card number, but you should still be cautious. Only give your email to sites you have verified are real. If you do, expect to receive marketing emails. If you receive emails from that address asking you to "verify" your password or payment information, that is a phishing scam — do not click the link.
What does it mean if a domain was registered recently?
A recent registration date is suspicious if the site claims to be an established organization. Real banks, utilities, and government agencies have owned their domains for years. A site claiming to be from a major company but registered last week is almost certainly fake. However, new legitimate businesses do register new domains, so recent registration alone is not proof of a scam — combine it with the other checks.
Can I trust a site just because it appears in search results?
No. Scammers pay for ads in search results and can appear at the top of the page. Search results do not verify legitimacy. Always check the domain, look for complaints, and verify contact information, regardless of where you found the link.