Counterfeit websites come in two species. The lookalike login page exists to take your password and is usually reached through a link someone sent you. The fake shop exists to take your card and is usually reached through an ad: the brand-name jacket at 80 percent off, the sold-out gadget miraculously in stock. Both are defeated by the same thirty seconds of inspection, applied before you type, because after you type is too late.

Check one: read the domain, right to left

The only part of a web address that cannot be faked is the real domain, the last two pieces before the first slash. Read it right to left: in amazon.account-verify.shop, the site is account-verify.shop, and "amazon" is set dressing. Scammers rely on left-to-right skimming, on subdomain tricks like this, and on near-misses: swapped letters, added hyphens, a different ending like .shop or .top where you expected .com. The padlock icon, incidentally, proves only that your connection to the site is encrypted, not that the site is honest; counterfeit sites have padlocks too, so do not let one reassure you.

Check two: interrogate the storefront

Fake shops are clones: stolen product photos, stolen descriptions, a template theme. What they cannot clone is a history. Check the contact page for a real physical address and phone number, then search the domain name plus the word "scam" or "reviews." A shop with no findable history, no working contact channel, and prices dramatically below everyone else is answering your question. On price specifically, the old rule has no exceptions worth betting on: a discount nobody else can offer is a product that does not exist.

Check three: arrive through your own door

The strongest habit is the one that runs through every guide on this site: navigate yourself. If an ad or message shows you a deal from a brand you know, close it and type the brand's address by hand; if the deal is real, it is on their site. If a login page appeared after you clicked something, close it and log in from the app or a typed address instead. Counterfeits depend entirely on controlling your route in.

Pay in the right order

When you do buy somewhere new: credit card, or a virtual card number, and never a debit card. Credit card fraud is the bank's money while it is disputed, and US law plus network policy caps your liability at little to nothing. Debit card fraud is your money gone while you argue. Wire transfers, crypto, and gift cards are not payment methods online, they are donations: no dispute process, no reversal, which is exactly why every scam eventually asks for one of them.

If a fake site got your card, call the bank and kill the number; got your password, change it everywhere it was reused, starting with your email. And if it got both, run the full first-day sequence and let the bank fight about the money.

Keep reading

Prevention fails sometimes. When it does, there is an actual recovery process, and knowing it turns a catastrophe into paperwork:

What to Do If Your Identity Is Actually Stolen

The official recovery path, in order: the FTC report, the freezes and disputes, and the paper trail that makes companies take you seriously.

← Back to all guides