10 ways to check if a website is safe or a scam
Google recorded two million phishing websites in 2020. Now, thanks to AI, their numbers are growing, and spotting them isn’t always easy. Learn how to check if a website is safe before you click, and find out how Cyber Safety tools can help block malicious websites, phishing attempts, and other online threats before they reach you.
- 1. Look for an SSL certificate
- 2. Examine the URL
- 3. Look at the content and claims
- 4. Watch out for pop-ups
- 5. Look for the site’s privacy policy
- 6. Search for contact information
- 7. Check the age and owner of the domain
- 8. Read reviews of the site
- 9. Use a website checker
- 10. Trust your web security tools
- Browse safely with Norton 360
- FAQs
We’re constantly being directed to websites — from texts with appointment confirmation links or QR codes on parking signs. Because links are such a routine part of everyday lives, it's easy to do it without a second thought. But not all links are legit. Cybercriminals create fake, realistic-looking sites to trick you into handing over sensitive information, entering payment details, or clicking downloads that install malware.
And fake sites are getting even harder to detect. Scammers are increasingly using AI-powered web builders to create convincing phishing sites from simple prompts or screenshots. Our Threat Researchers have dubbed this new tactic VibeScams, because these sites pass the “vibe check,” perfectly mimicking the look, feel, and branding of trusted companies.
To highlight the scale of the threat, between January and the end of August 2025, Gen’s Cyber Safety products, including Norton 360, blocked about 140,000 unique AI-generated scam websites, averaging roughly 580 newly detected scam sites every day, according to our internal telemetry data.
Knowing what to look for is your first line of defense, so here’s exactly how to check if a website is safe.
1. Look for an SSL certificate
A Secure Sockets Layer (SSL) certificate is what encrypts the data exchanged between you and a site you visit. This helps protect sensitive information, such as passwords and payment details, from being intercepted in transit.
An SSL certificate is a basic security feature that legitimate websites are expected to have, so if one is missing, that’s a red flag. While a lack of encryption doesn't necessarily mean a site is fake, it does mean your connection is less secure.
Scammers can obtain free, valid SSL certificates for websites they control, and many do, as it makes their scams seem more trustworthy. But many others skip this step because their goal is to quickly launch large numbers of scam websites at scale — so the absence of an SSL certificate is still a strong warning sign, especially in combination with other red flags.
To check if a website has an SSL, look at the address bar when you visit a site:
- “https://” at the beginning of the URL signals encryption. The “s” stands for secure. Non-encrypted sites begin with “http://” (no “s”).
- A lock icon on the left side of the address bar signifies a secure connection. Click it for more details about the site’s security credentials.
2. Examine the URL
A close look at a website’s URL can help you find out whether you’re on a legitimate site or a fake copycat. Cybercriminals often spoof websites, creating sites that look nearly identical to real ones to steal your logins. In some cases, they’ll even register domains with common misspellings of well-known sites to catch users who mistype a URL, a tactic known as typosquatting. Always check the address bar for these common red flags:
- Misspellings or extra characters: “gooolge.com” or “arnazon.com” instead of “google.com” or “amazon.com”
- Added words or hyphens: “apple-support-login.com” instead of “apple.com”
- A different domain extension: “netflix.net” or “netflix.org” instead of “netflix.com”
- Long, confusing URLs with multiple subdomains or random strings: “login.paypal.verify-account.example.com.”
If something looks off, close the window immediately, then clear your browsing history and data to prevent being redirected there again. Report the site if you believe it’s running a scam.
Where might you encounter an unsafe website?
Links to fake and unsafe websites can appear in Google search results, social media ads, QR codes, or messages in your inbox. In one analysis by Gen's Threat Researchers, nearly one in three ads on Meta's European platforms led to a scam, phishing, or malware site, while Reuters reporting suggests similar issues affect users in the U.S.
3. Look at the content and claims
Even if a URL looks legitimate, the site itself can give away red flags. Spoofed and pharming sites often contain subtle mistakes that the real site wouldn’t, like misspelled words, awkward phrasing, or mismatched logos — although thanks to AI, these slip-ups are becoming rarer.
You should also pay close attention to broken page elements. While an AI-generated scam site might look highly realistic on the surface, it’s often a house of cards that starts to crumble as you dive deeper into the website. A legitimate brand will have a deep, functional website, whereas a scam site is usually just a few pages designed to steal your data.
To verify a site’s legitimacy, try exploring beyond the homepage:
- Click the navigation links: Do pages like “About Us” or “Shipping Policy” actually load, or do they just refresh the page and do nothing at all?
- Test the footer: Check whether the social media icons actually link to the brand’s official profiles or are just static images.
Another warning sign to watch out for is a deal that seems too good to be true. If you land on a luxury retailer's website and everything is heavily discounted, don't rush to buy. Close the window, clear your cookies, history, and cache, and then visit the brand's official website by typing the URL directly into your browser. If the discounts disappear, you were likely on a fake site designed to lure shoppers with unrealistic bargains.
Look out for unrealistic claims. If you chance upon a website promising pills that will make you look ten years young for just $18.99 (dermatologists hate this simple trick), chances are you’re on an unsafe site.
Likewise, watch out for ticking timers telling you a sale will end in mere hours. Scammers love urgency, since they want you to take action before you have time to think critically.
4. Watch out for pop-ups
Excessive or irrelevant pop-ups are a common sign of an unsafe site. If you’re being bombarded before you can even navigate the page, or the pop-ups have nothing to do with the site you intended to visit, treat it as a red flag. Here are the most common types to watch out for:
- Scareware: Pop-ups warning you that your device is infected, designed to panic you into clicking a link that actually installs malware rather than removing it.
- Malvertising: Malicious ads that look legitimate but can infect your device with a single click, even on sites you’d normally trust.
- Browser-in-browser attacks: Fake login windows designed to mimic real sign-in pages, like Google or Microsoft, to steal your credentials. If a login window appears unexpectedly, close it and navigate to the site directly instead.
Installing a pop-up blocker on your phone and computer can stop many of these before they appear.
5. Look for the site’s privacy policy
A legitimate website should have a privacy policy, and most are legally required to provide one. It should clearly explain what data is collected, how it’s used, and how it’s protected. You can usually find it linked in the footer or via a site search.
Just keep in mind that scammers can now use AI to generate realistic-sounding privacy policies in seconds. To see if a policy is real, look for specific details like:
- Company name: The policy should mention the company’s full legal name and reference the types of products and services it offers.
- “Last Updated” date: Most companies update these annually. If you see a date from five years ago, or if a brand-new site claims it was updated this morning, something is probably off.
- Functional links: Click the links inside the policy that lead to things like Terms of Service or Community Guidelines. Broken links or pages that just refresh are signs a site is fake.
If a site doesn’t have a privacy policy, it may mean they don’t collect any data, but it’s more likely that they don’t want to let you know what information they do collect.
6. Search for contact information
A legitimate website should make it easy to get in touch. Look for a contact page with an email address, phone number, and physical address. While this isn't a guarantee that a site is legitimate, it does suggest there's a real business behind it.
Check that the contact details make sense. For example, a site claiming to be Apple shouldn't use a Gmail address or list a phone number from an unrelated country. You can also verify a physical address using Google Maps.
That said, scammers sometimes copy the genuine contact information of the brands they're impersonating, so treat this as one signal rather than proof. If you're about to enter payment details and something feels off, contact the business to verify the site. And if there's no contact information at all, consider it a warning sign, especially for sites asking for personal or financial information.
7. Check the age and owner of the domain
Another way to tell if a website is secure is to run a Whois domain lookup to see when a website was created and who is behind it. Often, temporary websites are created to host questionable offers and are shut down once they’ve served their purpose.
If a site is brand new or owned by someone other than the purported owner (or you can’t find a way to contact them), you’re probably better off taking your business to a more reputable company.
8. Read reviews of the site
Before shopping on an unfamiliar website, check what other customers have to say. Search for the site's name followed by "reviews" to find feedback on platforms like Trustpilot, Yelp, or Consumer Reports.
A few negative reviews are normal, but repeated complaints about scams, missing orders, or poor customer service are worth taking seriously. Be equally cautious of pages filled with generic, overly enthusiastic five-star reviews — they may be fake or manipulated. Look for detailed, balanced feedback that reflects genuine customer experiences.
9. Use a website checker
A straightforward way to verify a site is by using a website checker. A tool like Norton Safe Web analyzes a site’s reputation by combining community feedback with a technical scan for vulnerabilities. It’s a quick, practical step to take before you start browsing.
If a URL checker indicates that a site may not be secure, it is best to close the window. You can always check the address again later, but sticking to sites that receive a clear rating is a reliable way to reduce your risk online.
10. Trust your web security tools
Even if you know what to look for, some fake sites are designed well enough to slip through the cracks, so make sure you have Cyber Safety software as an extra layer of protection. Proper Scam Protection tools will alert you about potentially dangerous websites, so you aren’t fooled by cleverly disguised AI threats.
Browse safely with Norton 360
Knowing what to look for is important, but having the right tools helps make staying safe online a lot easier. Norton 360 uses AI technology to analyze content patterns and help warn you about threats like phishing sites and scam texts before they reach you.
It also includes a Secure VPN, a Private Browser, and Dark Web Monitoring, providing a comprehensive solution to help keep your personal information and devices protected around the clock.
FAQs
How can I check if a link is safe?
If you’re using a computer, hover over the link before clicking. If the URL that appears doesn’t match where you’d expect to go, don’t click it. You can also copy the link and run it through a URL safety checker for a second opinion. When in doubt, skip the link entirely and navigate to the site directly by typing the official URL into your browser.
How do scam websites work?
Scam websites are designed to trick you into handing over personal information or account credentials, usually by impersonating something familiar and trustworthy. Phishing sites lure you into entering details like passwords or financial information that can be used to access your accounts.
What happens if you visit an unsafe website?
Most browsers will warn you before you get there, typically with a full-screen alert flagging that your connection isn't private or that you’re heading toward a deceptive site. If you proceed anyway, the consequences can be serious. Your identity could be stolen, malware could be installed on your device, or you could become the target of a scam.
Does clearing my cache get rid of viruses?
Clearing your cache won’t get rid of viruses or malware that have already been installed on your computer or phone. However, it can help remove malicious “scripts” that live inside your browser and cause annoying pop-ups or redirects.
Editors’ note: Our articles offer educational information and are written to raise awareness about important topics in Cyber Safety. Norton products and services may not protect against every type of threat, fraud, or crime we write about. For more details about how we research, write, and review our articles, see our Editorial Policy.
Want more?
Follow us for all the latest news, tips, and updates.