You get a text saying a package is held up and you owe 1.99 for redelivery. The link opens a page that looks exactly like your postal service, right down to the logo and the tracking box. Your thumb hovers over the payment field. This is the moment that decides whether your card details stay yours.

Knowing how to check a website in a few seconds is one of the most useful skills you can carry around. It works on shopping sites, login pages, and any link a stranger sends you. Here is the routine I use, broken into checks anyone can do.

Key takeaways

  • Read the real domain in the address bar, not the logo or the page design, which are trivial to fake.
  • A padlock means encrypted, not trustworthy, so never treat it as the whole answer.
  • A quick search for the site name plus “reviews” or “scam” reveals most fakes in seconds.
  • When a link arrives by text or email, reach the real site yourself instead of tapping through.

Start with the address bar, always

The single most reliable clue lives at the top of your browser: the web address. Everything below it can be copied from a real site in minutes. The domain cannot be faked, only imitated, so that is where you focus.

close-up of a web browser address bar being checked
The domain in the address bar is the one thing scammers cannot fully fake.

Look at the main part of the address, the bit right before the “.com” or “.org”. For a real bank, that reads “yourbank.com”. A scammer’s version might read “yourbank-secure.com”, “yourbank.account-login.com”, or “yourbank.com.verify-me.net”. Read from the right side inward, because the true owner of a site is the word directly to the left of the final slash.

Good to know

The part after the last dot before the first slash is the real domain. In “login.paypal.com”, the owner is “paypal.com”. In “paypal.com.secure-login.info”, the owner is “secure-login.info”, which is not PayPal at all. Scammers stack familiar words on the left to hide the real name.

What the padlock actually tells you

Years of advice told people to “look for the padlock.” That advice is now half true and half dangerous. The padlock means traffic between you and the site is encrypted, so nobody can snoop on what you type in transit.

What it does not mean is that the site is run by honest people. Free certificates are available to anyone, scammers included, so a fake page can show the exact same padlock as your bank. Use it as a floor, never as a green light.

Watch out

A missing padlock on a login or payment page is a hard stop. But a present padlock proves almost nothing on its own. Never let the little icon end your judgment.

A layered check you can run in seconds

No single test is perfect, so I stack a few fast ones. Together they catch nearly everything.

Check How Green light Red flag
Domain spelling Read the full address slowly Exact, familiar name Extra words, hyphens, odd endings
Encryption Look for the padlock Padlock present No padlock on a form page
Reputation Search “site name reviews” or “+ scam” Real, mixed reviews over time No trace, or fresh complaints
Contact info Find the About or Contact page Real address and phone Only a form or free email
Link source Note how you got here You typed it or used a bookmark Arrived via a text or email link

The reputation search is my favorite because it is so fast. Type the site name and “scam” into a search engine, and if the shop has burned anyone before, you will usually see it on the first page. If nothing comes up at all for a store claiming to be a big brand, that silence is its own warning.

Half the danger comes from links you did not go looking for. A text, an email, a message from a “friend” whose account was hijacked. The safest habit is to never tap the link and instead reach the real destination on your own.

On a computer

Hover your mouse over the link without clicking. The true destination appears in the bottom corner of the browser or email window. If the visible text says one thing and the preview shows another, that mismatch is the trap.

On a phone

Press and hold the link instead of tapping. A menu pops up showing the full address at the top. Read it the same way you read the address bar, then close the menu. When I set this up for my dad, this one habit stopped more scam texts than any app ever did.

Tip

For any message about money, deliveries, or account problems, ignore the link entirely. Open your browser, type the company’s name yourself, and log in the way you always do. If the alert is real, it will be waiting for you inside your account.

When a site fails your checks

If a page trips two or more of your flags, close the tab. Do not enter anything, not even an email address, because that alone confirms to scammers that your account is active and worth targeting again.

If you reached a suspicious page from a message, it is worth flagging so others get protected. Our walkthrough on reporting phishing and scams the right way shows exactly where to forward a scam text or email. The same instincts feed directly into spotting a bad shop, which we cover in how to spot fake online stores before you pay.

These skills all sit under one bigger habit: pausing before you trust. If you want the full picture of how these tricks are built, start with our beginner’s guide to spotting scams and phishing, then sharpen your inbox instincts with spotting a phishing email before you click. For a deeper reference on evaluating links, the nonprofit National Cybersecurity Alliance keeps up-to-date guidance too.

Your afternoon checklist

  • Open a site you use often and practice reading the true domain from the right inward.
  • Bookmark the login pages for your bank, email, and main shopping sites.
  • Practice pressing and holding a link on your phone to preview its real address.
  • Run a “site name plus scam” search on any store you are unsure about.
  • Set a personal rule to never enter details from a link you did not go looking for.
  • Teach the address-bar check to one family member who shops or banks online.
  • Save the reporting link so you can flag a bad site in under a minute.

None of this requires special software or a security background. It is a two-minute habit that puts you back in control of which sites earn your trust. Do it a few times and it becomes automatic, the way you glance both ways before crossing.