Consumer Review

How to Check if a Website Is Safe to Buy From in 2026: 8 Checks Before You Pay

Emily Rodriguez Emily Rodriguez Scam & Fraud Researcher Aug 21, 2026 10 min read Updated Aug 21, 2026
How to Check if a Website Is Safe to Buy From in 2026: 8 Checks Before You Pay
Share this review

Would you enter your credit card on a site you've never seen before? In 2025, that question got a lot more expensive. Global scam losses hit an estimated $442 billion in 2025 according to the Global Anti-Scam Alliance, with 57% of adults worldwide encountering a scam attempt and 23% losing money. In the US alone, the FBI's IC3 logged $20.9 billion in reported losses and the FTC another $15.9 billion — and researchers agree those numbers represent just 10–20% of real harm, because fewer than 5% of victims ever file a federal complaint.

Shopping scams were the most encountered scam worldwide (54% of victims), according to GASA 2025, and the US saw 384,946 online-shopping fraud reports in 2024 alone. Social media is now the costliest contact method: $2.1 billion in FTC-reported losses originated on social platforms in 2025, up 8x since 2020. No wonder the top question behind every "Is [site] legit?" search is really "Will I get what I paid for — or lose my money and data?"

This is the RatingFacts Editorial Team's 2026 guide to answering that question yourself, before you click "Pay." We built it the same way we verify every business on our platform: technical signals, domain intelligence, reputation data, and payment protection — layered, not a single "is it safe?" badge.

Why "Looks Legit" Is No Longer Enough

Attackers no longer need to look sketchy to steal from you. In 2025, over 1.5 million new phishing sites were created per month (APWG / Google Safe Browsing), many cloned pixel-perfect from real brands and served over HTTPS. The browser padlock no longer means "safe" — almost every phishing site today uses a free Let's Encrypt certificate. Attackers also buy aged domains, hijack abandoned ones, and run full fake storefronts that do ship something — just not what you ordered.

That is why a layered check beats any single tool. One signal can be faked. Five to eight together are very hard to fake at once. This guide gives you the eight checks we use internally, in the exact order to use them before you trust any site with a password or card.

The 8 Checks to Verify a Website Before You Buy

1. Check for HTTPS — and Actually Inspect the Certificate

Look for https:// and the padlock. Then click the padlock → Connection details → Certificate. Confirm:

  • Certificate is valid and not expired
  • Issued to the exact domain you see (not a typo variant)
  • Issuer is a real Certificate Authority (Google Trust Services, Let's Encrypt, Sectigo, DigiCert)

What it proves: your connection is encrypted. What it does NOT prove: the business is honest. Treat HTTPS as the baseline, not the verdict — free DV certificates take seconds to get, and scammers use them routinely.

2. Check Domain Age and History

Most scam shops are brand new. They register, burn through victims for weeks, get flagged, and vanish. Before you trust a store with your card, check when the domain was first registered:

  • <6 months old + impersonating a known brand = high risk.
  • >2–3 years + consistent history = much lower risk (not a guarantee, but a strong signal).

Use a WHOIS / Domain Age checker (e.g., WHOIS or RatingFacts' linked WHOIS data on every review page). Compare the "Created" date to the age claimed on the site's "About Us." A site claiming "Trusted since 2015" with a domain registered 47 days ago is lying.

3. Inspect WHOIS, Registrar, and Privacy Shield

Open WHOIS and ask:

  • Is the registrant country offshore and hidden behind a privacy service, while the site claims to be US/EU-based?
  • Is the registrar one commonly used for bulk cheap registrations?
  • Is the "Registered till" only months away (cheap one-year flip) vs. years in the future?

Privacy protection alone is not a scam signal — many legitimate sites use it. But combined with a new domain, anonymous offshore hosting, and no physical address, it becomes a cluster signal.

4. Run the Domain Through Reputation Scanners

Automated engines check blacklists, phishing patterns, malware hosts, and hosting signals in seconds. Run at least two:

  • Gridinsoft Website Reputation Checker — rates 0–100, flags phishing/malware/suspicious shop, shows registrar, hosting, blocklist hits, and user feedback.
  • ScamAdviser — trust score 0–100, SSL + traffic + domain + review signals.
  • Google Safe Browsinghttps://transparencyreport.google.com/safe-browsing/search — confirms if Google has flagged the URL for phishing or malware.

Example: a ScamAdviser 100/100 and Gridinsoft 95/100 "Verified Safe" with years of history is very reassuring. A Gridinsoft 9/100 "Suspicious Website" with "blacklisted by security providers" is a hard stop — even if the site looks polished.

Pro tip: copy the domain and search site:[domain] + site:trustpilot.com, site:reddit.com, and gridinsoft.com/online-virus-scanner/url/[domain] for instant reports.

5. Search for Independent Reviews (Not Just On-Site Testimonials)

On-site reviews are trivial to fake. Independent reviews are hard to fake at scale. Search:

  • "[site name] reviews"
  • "[site name] scam" and "[site name] complaints"
  • site:trustpilot.com "[site name]" and site:ratingfacts.com "[domain]"

On RatingFacts and Trustpilot, check:

  • Volume vs. rating. 2 reviews at 5.0 stars proves nothing. 2,000+ at 4.4 stars is meaningful. Be suspicious of perfect 5.0 from <50 reviews — often incentivized.
  • Does the business reply? On RatingFacts, a store that replies to 90%+ of negative reviews signals real customer service. "Hasn't replied to negative reviews" is a red flag.
  • What do people complain about? Non-delivery, wrong item, no refund, and "return loop" tickets-closed-without-resolution are classic dropship-scam patterns.

6. Verify Contact, Address, and Return Policy

A safe site makes it easy to reach a human and return a bad order. A risky site hides behind a form. Check:

  • Physical address: copy-paste it into Google Maps — is it a residential flat, virtual-office suite, or freight forwarder?
  • Phone: call it. Does anyone answer? Shared virtual-office numbers (e.g., same Camden/London suite used by many flagged shops) are a cluster signal.
  • Returns: is there a real return address in your country with a time window and who pays postage? Vague "contact us for return authorization" with no address is a trap.
  • Payment methods: does it accept cards/PayPal with buyer protection, or push you to wire, Zelle, crypto, or gift cards? The FTC's July 2026 warning was explicit: if the only way to pay is wire/crypto/gift card, it's a scam.

7. Inspect the URL for Typosquatting and Cloned Branding

Attackers rely on fast-reading eyes. Compare character-by-character:

  • amaz0n.com vs. amazon.com, shein-official-shop.com vs. shein.com, kiwi-com-booking.com vs. kiwi.com — extra hyphens, numbers, plurals, or TLD swaps (.shop, .store, .top).
  • Paste the link into Gridinsoft or VirusTotal and see if it redirects to a different domain after loading.
  • Never click a "refund is pending" link in an email — type the domain yourself or open your bookmark.

8. Check Payment Security and Order Confirmation

On the checkout page, confirm:

  • No browser warnings about mixed content or invalid cert.
  • Card form is on the same domain, not an unknown iframe host.
  • After payment, you receive an immediate order number and email receipt from the same domain with trackable shipping. No email at all = major flag.

Always pay with a credit card or PayPal — never debit, wire, or crypto — so you keep chargeback rights under Regulation Z / card-network rules. Store the URL, screenshot the checkout, and save the confirmation until the item arrives and is verified.

Red Flags That Say "Don't Buy Here"

Signal (alone)Why it mattersWhat to do
Domain <30–90 days oldScams peak in first weeks then vanishWait, or buy from the official store
Only crypto / wire / gift-card paymentNo reversible buyer protectionHard stop — per FTC, it's a scam
Price 70–90% off a luxury goodCounterfeit / bait-and-switchSearch "[item] + site:trusted retailer"
No address, or virtual-office suiteNo legal recourseReverse-search the address
Perfect 5.0 from <50 reviews, no repliesIncentivized / fake reviewsSearch independent reviews
Blacklisted by 1+ security scannersConfirmed phishing / malware hostDo not enter any data
Urgency pop-ups + "only 2 left!"Dark-pattern pressureClose and verify elsewhere

One flag can be noise. Two or three together are a pattern. We treat a site as high-risk when at least two cluster signals from this table appear.

What To Do If You Already Entered Data or Paid

  1. Stop further interaction. Do not pay "customs," "insurance," or "re-shipping" fees to release a parcel — classic second-stage scam.
  2. Change passwords if you entered one — immediately, on the real domain, plus any account that reuses it. Enable 2FA.
  3. Contact your card issuer. For "not-as-described" or non-delivery, file a dispute (chargeback). Credit-card protections under Reg Z are stronger than debit.
  4. Scan your device if you clicked a link or downloaded a file (Gridinsoft, Malwarebytes, or built-in OS scanner).
  5. Report the URL: to Google Safe Browsing, ReportFraud.ftc.gov, and FBI IC3. Reports feed the engine that blacklists the domain for others.
  6. Verify future purchases on RatingFacts — search the domain for verified reviews, complaint patterns, and our trust indicators before you pay.

How RatingFacts Evaluates Website Safety

On every RatingFacts business page we combine — like this guide — technical + reputation + experience signals: verified buyer reviews, complaint-tag clustering, domain age and WHOIS, SSL and hosting, payment methods, return-policy transparency, and scan-engine results (linked to Gridinsoft/ScamAdviser/WHOIS). No single score decides the verdict; we look for converging evidence. If you need a second opinion, paste any domain into our category directory and compare it to known legitimate alternatives before you decide.

Frequently Asked Questions

Is HTTPS enough to mean a site is safe?

No. HTTPS only means the connection is encrypted, not that the shop is honest. Almost all phishing sites today use HTTPS via free certificates. You still need domain age, reviews, blacklists, and contact verification.

What is the quickest safety check before paying?

Do 3 in 60 seconds: (1) check domain age, (2) search site:trustpilot.com "[domain]" and ratingfacts.com/reviews/[domain], (3) paste the URL into Gridinsoft or VirusTotal. If two of those are bad, stop.

Can a new site still be legitimate?

Yes — every store was new once. But a new site copying a famous brand, hiding its address, and offering extreme discounts is not "new + legitimate." For a truly new independent store, pay with a credit card, start with a small order, and verify the business registration before you commit.

What payment method gives me the most protection?

Credit cards and PayPal offer reversible buyer protection / chargebacks. Debit cards, wire, Zelle, crypto, and gift cards do not. If a site only accepts irreversible methods, the FTC warns that is a hallmark of a scam.

How accurate are automated safety scanners?

They catch most blacklist/SSL/malware signals but can misclassify very new legitimate sites as "caution" due to thin history. Use scanners as one layer, not the whole answer, and cross-check with reviews and WHOIS.

What if a scanner says "Safe" but reviews are terrible?

Trust the reviews. Scanners check technical hygiene, not whether the seller ships cheap counterfeits or refuses refunds. A technically "safe" site can still be a terrible place to shop.

Methodology & Sources

This guide was produced by the RatingFacts Editorial Team (author: Emily Rodriguez, Scam & Fraud Researcher). Scam-scale figures are from the Global Anti-Scam Alliance (GASA) State of Scams 2025 (46,000 respondents, 42 countries; fielded Feb–Mar 2025; published Oct 2025) as summarized by Axis Intelligence (July 17, 2026): $442B global losses, 57% encounter / 23% financial loss worldwide. US reported figures are from the FBI IC3 Internet Crime Reports 2024/2025 ($20.877B, 1M complaints for 2025; $12.5B for 2024) and FTC Consumer Sentinel ($15.9B for 2025; $1.9B social-media-origin in 2024, $2.1B in 2025) and the FTC's July 22, 2026 guidance on payment-method red flags. Shopping-scam frequency and monthly phishing-site creation figures are from the same GASA/APWG baselines cited via DigiMetrics Hub (May 1, 2026) and Norton. Scanner guidance references Gridinsoft and ScamAdviser product docs (2026). Review behavior norms (89% expect responses, etc.) are from BrightLocal's Local Consumer Review Survey 2025/2026 and Review42 (June 2026). All sources accessed August 2026; numbers are reported complaints and materially undercount actual harm.

Emily Rodriguez
Emily Rodriguez
Scam & Fraud Researcher

Emily researches online fraud, fake reviews, and phishing operations. Her guides teach readers to recognize manipulation patterns and verify businesses using independent, moderated sources.

Back to all articles
Stay Informed
Get Verified Review Insights

Subscribe to receive the latest consumer guides and website ratings.