Run a lookup

Scams

Is this website a scam?

You are about to enter a card number into a site you have never used. Here is what can be established in about two seconds, and what cannot be established at all.

7 min read The DetectiveCheck team
ScamsGuideSafety
A shopfront lit hard against a dark street

The short answer

Check when the domain was registered before anything else. A storefront created weeks ago and selling discounted brand-name goods is the pattern fraud actually takes. The padlock proves only that traffic is encrypted, and no technical check tells you whether an order will arrive.

  • The padlock means encrypted, not honest. The FBI has said so since 2019.
  • Registration date is the strongest single signal. Most phishing domains are registered for the purpose.
  • WHOIS stopped telling you who in 2018. It still tells you when, and when is the useful half.
  • A site can pass every check here and still take your money. Non-delivery is its own category of complaint.

Does the padlock mean anything?

It means the connection is encrypted. It says nothing about who is on the other end.

The FBI put out a public notice in 2019 saying exactly that: do not trust a website just because it has a lock icon or https in the address bar, because criminals were banking on the public's trust in it.

The consumer guidance from the body behind the certificate rules is just as plain. A domain-validated certificate contains only the domain name, and the same page says a certificate does not guarantee a site is correctly implemented or free of malware.

Which is checkable rather than theoretical. If the certificate's organisation field is empty, nobody verified who runs the business — only that somebody controlled the domain for long enough to prove it.

wwwone domain inRegistered whenCertificate typeWho shares the IPWhat it runs onWhether they shipwwwone domain inRegistered whenCertificate typeWho shares the IPWhat it runs onWhether they ship
One domain in, and the facts a lookup can establish. Whether the parcel arrives is not among them.

What is the strongest single signal?

When the domain was registered.

The best measurement is of phishing rather than of shops, and it is worth naming that before leaning on it. An annual study found that 77% of the domains used were registered for the purpose rather than compromised, across roughly four million reports in the year to April 2025.

Attackers use them quickly, too. Interisle's 2022 study found 41% in use within a fortnight of registration, and the FBI's shopping-fraud notice describes sites registered within the previous six months.

A creation date needs no interpretation at all. A shop on a three-week-old domain discounting brand-name goods is not proof of anything on its own, and it is still the single fact most worth having in front of you before you pay.

What does WHOIS still tell you?

When, where and through whom. Not who.

Registrars have redacted registrant names, streets, phone numbers and administrative contacts by default on generic domains since ICANN's post-GDPR policy in 2018, consolidated into the registration data policy that took effect in August 2025.

Redaction never touched the chronology, because none of it is personal data. A live run against this site returned the creation date, the domain age, the expiry, the nameservers, DNSSEC status and the registrant country in one second.

So the standard advice to look up the owner is stale, and the advice to look up the domain is not. What a WHOIS record still gives up is the half that predicts fraud, and that half was never in scope for redaction.

A storefront takes an afternoon to build and a fortnight to abandon. The registration date is the one thing it cannot backdate.

A storefront takes an afternoon to build and a fortnight to abandon. The registration date is the one thing it cannot backdate.

Twenty thousand shops, two templates

The interesting signals are the ones that only mean something together.

A security firm mapped a network of more than 20,000 fake shops resolving to 36 IP addresses, all running the same platform, and the six apparently different designs turned out to be two base themes with cosmetic changes.

None of those facts is damning alone. Shared hosting is ordinary, and the platform underneath them is a legitimate commercial service that ordinary sellers use every day.

The conjunction is what reads: a domain under three months old, on an address shared with a cluster of near-identical new storefronts, running an off-the-shelf template. A reverse-IP lookup answers the middle part of that, and an HTTP probe answers the last part.

How do the scam-checker scores work?

From the same handful of signals, with a number on top.

The best-known of them, ScamAdviser, publishes its own inputs: domain age under six months, whether there is a certificate, whether the registration sits behind privacy, the reputation of neighbours on the same IP, review-site presence, social accounts and traffic estimates.

Every one of those except third-party reviews is a public fact you can read directly, and none of them is a judgement about the business. The score is a weighting somebody chose, presented as a verdict.

Worth knowing before you trust a number: a legitimate new business scores badly on nearly every one of those inputs, because being new is most of what the model is really measuring in the first place.

What can none of this tell you?

Whether they will actually send the thing.

The FBI's complaint centre logged 56,478 non-payment or non-delivery complaints in 2025, against 49,572 the year before. A real company, with a real certificate and a five-year-old domain, can take an order and not fill it.

Every technical check on this page would pass that company. Infrastructure describes how somebody built a site and nothing about whether they intend to deliver, which is why checking the people rather than the site is a separate job.

Which is why the last section is about payment rather than about checking at all. The checks narrow the odds; the payment method is what you still hold on the day the odds go against you, and it is the only part of this fully in your hands.

How should you pay?

With the method that lets somebody else reverse it.

The UK's national cyber authority is unusually direct: never pay by direct bank transfer, and use a credit card where you have one, because many card purchases carry statutory protection that a transfer does not.

The same logic rules out the methods fraud prefers. A gift card, a wire transfer, a payment app or a transfer to a wallet address are final the moment they leave, and a seller insisting on one has told you something the domain age only hinted at.

That is the whole defence in one sentence. Check the registration date, look at what else shares the address, and then pay in a way that somebody other than the seller can undo.

Common questions

How do I check if a website is legit?

Start with the registration date, which comes back in about a second and is the strongest single signal. Then look at what else shares its IP address, and whether the certificate names an organisation or only the domain. None of that is proof, and a domain registered three weeks ago selling discounted brand goods is the pattern fraud takes.

Does the padlock mean a website is safe?

No. It means traffic to the site is encrypted. The FBI issued a public notice in 2019 telling people not to trust a site because of the lock icon, and the body that writes the certificate rules states that a domain-validated certificate says nothing about whether the organisation is reputable.

How do I check how old a website is?

The domain's creation date is published in its registration record and was never subject to the privacy redaction that removed registrant names. A lookup returns it along with the expiry date, the nameservers and the registrar. Anything under a few months old deserves more caution than the site's own design can earn back.

Can a scam website have an SSL certificate?

Easily, and most do. Certificate authorities issue domain-validated certificates free and automatically to anybody who can prove control of the domain, which a fraudster controls by definition. An industry analysis of phishing sites in the first quarter of 2021 put 94.5% of their certificates in that weakest category.

What does WHOIS tell you about a website in 2026?

When it was registered, when it expires, which registrar sold it, its nameservers and usually a country. Registrant names, addresses and phone numbers have been redacted by default on generic domains since 2018, so the advice to look up the owner is out of date while the advice to look up the domain is not.

Are website scam checkers accurate?

They compute a number from public signals you can read yourself: domain age, certificate, registration privacy, IP neighbours, review-site presence. The score is a weighting somebody chose rather than a finding. A legitimate new business scores badly on all of them, because newness is most of what is being measured.

Can a website look legitimate and still be a scam?

Yes, and that case is common enough to have its own complaint category. The FBI's complaint centre logged 56,478 non-payment or non-delivery reports in 2025. A company with a real certificate and an old domain can take an order and never fill it, and no infrastructure check can see intent.

What payment method is safest on a site I do not know?

A credit card, because the money can be reversed by somebody other than the seller. The UK's national cyber authority advises never paying by direct bank transfer. Gift cards, wire transfers, payment apps and cryptocurrency are final on send, and a seller insisting on one has answered the question for you.

What should I do if I already paid a scam website?

Contact your bank or card issuer today and ask about a chargeback. Card scheme windows typically run around 120 days from the transaction or the expected delivery date, so being late is a reason to call rather than a reason not to. Keep the order confirmation, the URL and any correspondence. Then report it to your national fraud body, which is what builds the case that takes the site down for the next person.

In short

The padlock is encryption, not honesty, and the certificate rules say so in writing. The registration date is the signal that actually predicts fraud, and it is the one piece of the old WHOIS record that privacy redaction never touched.

Everything technical here describes how a site was built. None of it can tell you whether the parcel arrives, which is why the last decision — pay with something reversible — matters more than any of the checks before it.

Written by the DetectiveCheck team

We build the lookup engine this site runs on, so the numbers in these guides are the ones our own reports use: 71 sources against an email address, 71 platforms against a username, 13 registers against a name, and 8 against a phone number. Where a module is thin, we say so rather than round it up.

Run one yourself

Create an account and the first report is a couple of minutes away. Nobody you look up is told.

Create my account

Plans from $15 a month. Cancel in one click. Or read a sample report first.

Try it on something you already have