A website is likely a scam if the domain is a lookalike, the page demands a password or payment you did not start, or a checker already flags the URL. A clean scan is not proof it is honest — new fake shops often miss the lists. Last updated: August 2026.
“Is this website a scam?” is the question people type after a TikTok shop, a too-cheap listing, or a login page that appeared from an email. You can answer it well enough to walk away. You cannot answer it as a courtroom verdict from one tool.
The FTC has reported for years that online shopping and impostor scams sit among the most common consumer frauds, with losses in the hundreds of millions of dollars annually in the United States as of the mid-2020s. Separately, as of 2026 more than 12 billion stolen credentials are in known breach datasets — which is why fake “verify your account” pages convert.
How do you tell if a website is a scam without guessing?
Use three layers. Stop at the first hard no.
- List lookup. Paste the URL into a website scam checker. A match on phishing or malware lists is enough to leave.
- Domain reading. The brand should own the domain. A folder named after the brand on someone else’s site is a copy.
- Deal and payment sense. If the only way to pay is crypto, gift cards, or a wire, or the price is a fraction of every other retailer, you are not getting a bargain. You are funding the next template.
For the step-by-step list lookup, see how to check if a website is safe. For “is this a real business,” see how to tell if a website is legit.
Why do scam websites look so real now?
Because the hard parts are automated. Product photos are stolen. Themes are sold. Certificates are issued in minutes. The remaining weak point is the domain and the money flow — that is what you inspect.
Urgency is the other tell. Countdown timers, “your package is held,” “unusual sign-in, confirm now.” Real companies let you log in from a bookmark tomorrow.
What are the most common website scam types?
- Fake login (phishing). Harvests the password you use on the real site.
- Fake shop. Takes payment, never ships, or ships a junk item.
- Tech-support overlay. Claims the device is infected; sells a remote session.
- Job or crypto “investment” page. Asks you to send money to unlock earnings.
If the bait arrived as a message, check whether the email is a scam and whether the link is safe before you argue with the design.
Paste the URL first: Check if this website is flagged →
Why does a data breach make scam sites more convincing?
When your address is in a breach, the next email can greet you by name and mention a service you actually use. That is not proof the sender is that company. It is proof someone has a list.
Check whether your email was exposed →
If a password was in the mix, treat reused logins as burned. The Adobe breach is a long-running example of how old password dumps keep feeding new phishing years later.
What should you do if you already used a scam website?
- Stop sending more money or codes.
- Tell your bank or card issuer the same day if you paid.
- Change the password you typed, on the real site only — then run the password reuse change checklist for every other login that shared it.
- Check the password and enable 2FA / passkeys after a breach.
- Watch that inbox for follow-up phishing. Attackers sell “this person pays.”
- If this started from a leak notice, follow what to do after a data breach.
You cannot un-send a wire. You can stop the next login.
When should you walk away even if the checker is clean?
When you cannot explain the domain, the seller, or the payment method in one calm sentence. When a stranger in a comment section is the only review. When the site will not let you use a normal card.
A clean result means “not on these lists.” It does not mean “this shop will refund you.” Walking away is allowed. No site is owed your card because it looks busy.
If you are comparing two shops, prefer the one whose domain you can say out loud and whose payment screen is a processor you already recognise. The extra ten minutes is cheaper than a chargeback.
Social proof on the page itself is advertising. A comment saying “just got mine!!!” with no photo is not a receipt. If the only reviews live on the shop, you do not have independent evidence yet.