Home› Blog› Articles
Articles

Businesses: Stop Online Scams in Under 2 Minutes with a 0–100 Trust Check

Protect your business with a seven-point pre-purchase checklist and a quick 0–100 trust check you can run in under two minutes. Then confirm contact and...

V verified.fyi
16 min read
On this page Table of Contents Protect Your Business From Online Scams: The 7-Point Pre-Purchase Checklist How Do You Verify a Website Is Safe Step by Step? What Are the Most Common Online Scam Red Flags? What Do Website Trust Scores Actually Measure? What Should You Do If You Already Paid a Scammer? Educate Your Team on Scam Tactics and Social Engineering Set Up Multi-Factor Authentication and Strong Password Rules Why Software Updates and Patches Matter More Than You Think Monitor Accounts for Suspicious Activity Before It Escalates Build an Incident Response Plan Before You Need One Filter Email and Block Phishing Before It Reaches an Inbox The Publisher's Perspective on Combining Automated and Manual Checks Run a Free Trust Check Before Your Next Online Purchase Sources FAQ Recommended

Decorative website trust check title card

The fastest way to protect yourself from an online scam is to verify a website's trustworthiness before you visit, register, or pay. Run a quick manual check: look at the URL, confirm there's real contact information, and be suspicious of anything demanding gift cards or wire transfers. Then back that up with an automated verifier which returns a trust score in seconds.


TL;DR:

  • Verify website URLs carefully for unusual characters or domain extensions that differ from normal brands before making a purchase.
  • Check for genuine contact details like a physical address and working phone number, and verify the site’s safety with free tools like Google Safe Browsing.
  • Avoid sites that only accept gift cards, wire transfers, or cryptocurrency, and prioritize paying with a credit card for better dispute options.
  • Use automated trust scores to quickly assess website safety, but always combine this with manual checks like reading policies and searching for scam reports.
  • Enable transaction alerts, set strong passwords with MFA, and have an incident response plan ready to minimize damage from scams or account breaches.

Table of Contents

Protect Your Business From Online Scams: The 7-Point Pre-Purchase Checklist

You don't need twenty minutes to spot a bad site. You need seven checks, done in order, before you click "buy" or hand over any personal details.

  1. Read the URL like a proofreader. Scammers count on you skimming. Look for extra letters, swapped characters, or an odd domain extension (.shop, .top, .xyz) standing in for a brand's usual .com.
  2. Find real contact information. A legitimate seller lists a physical address, a working phone number, and clear return, shipping, and terms-of-service pages. If those pages don't exist or read like a single paragraph copied from somewhere else, that's a problem.
  3. Run the domain through Google Safe Browsing and a general site checker. This flags known phishing and malware domains at no cost, according to CISA's phishing guidance.
  4. Search the brand name plus "complaint" or "scam." Do this on a search engine, not just inside the site's own reviews, since FTC consumer alerts note this surfaces experiences sellers won't show you themselves.
  5. Pay by credit card whenever possible. Avoid any checkout that only accepts gift cards, wire transfers, or cryptocurrency.
  6. Look up the domain's registration through an RDAP or WHOIS lookup, and note whether the registrant hides behind a privacy or proxy service.
  7. When something feels off, stop. Call the company directly using a number you found independently, or take your business elsewhere.

Treat this as your baseline before every unfamiliar purchase, not just the ones that already look suspicious.

How Do You Verify a Website Is Safe Step by Step?

Verification works best in two stages: the human checks first, then the technical ones. Rushing straight to a padlock icon skips the checks that actually catch most scams.

Start with the non-technical pass. Open the site's "Contact," "Returns," and "Terms" pages side by side. A real business explains how refunds work, how long shipping takes, and how to reach a human. Compare the price against two or three competitors; a jacket priced far below typical market rates is a lure, not a deal, as noted in FTC's online shopping guidance. Search the seller's name alongside "reviews" or "scam" before you search anything else about the product itself.

Move to the technical pass once the site clears that first filter.

  • Click the padlock icon to view certificate details, including the issuer and expiration date, a step CISA recommends for confirming a connection is actually encrypted.
  • Run the domain through Google Safe Browsing to check for phishing or malware warnings.
  • Use an ICANN RDAP or WHOIS lookup to view registration details. A domain registered three weeks ago, or one hidden behind a privacy proxy, isn't automatically fraudulent, but it removes one layer of reassurance you'd otherwise have.

Pro Tip: If a WHOIS lookup shows a private registrant, don't treat that alone as a red flag. Millions of legitimate small businesses use privacy services too. Treat it as one more data point, not a verdict.

Set your own thresholds going in. Clear contact details, a domain older than a year, and no Safe Browsing warnings mean you can likely proceed. One missing piece means slow down and dig further. Two or more missing means abandon the purchase and buy elsewhere.

What Are the Most Common Online Scam Red Flags?

Scammers reuse the same handful of tactics because they still work. Once you know what to look for, most attempts become obvious within seconds.

  • Social-media ads with impossible prices. A recognizable brand name paired with a steep discount and advertised via social media is a common tactic used by counterfeit and scam storefronts.
  • Payment demands outside normal channels. Any checkout that insists on gift cards, wire transfers, or cryptocurrency, with no credit card option, is close to a guaranteed scam signal.
  • A padlock icon used as false reassurance. HTTPS means your connection is encrypted. It says nothing about whether the business behind it will ship your order, since FTC guidance confirms encryption is a baseline, not a legitimacy test.
  • Reviews that all sound alike. Watch for five-star reviews posted within the same week, generic phrasing repeated across multiple "customers," or trust badges that link to nothing when clicked.
  • Contact information that doesn't check out. A phone number that rings dead, an address that maps to a residential lot, or a returns page that simply doesn't exist.

Scammers rely on urgency and emotion to keep you from pausing long enough to notice these details, which is why CISA's core defense recommendation is simply to slow down and verify independently before acting.

What Do Website Trust Scores Actually Measure?

An automated verifier doesn't replace your own judgment. It compresses the research you'd otherwise do by hand into a single, fast readout.

Some tools analyze over 200 signals across six broad categories:

  • Security — SSL certificate validity, malware and phishing flags, blocklist status
  • Ownership — domain registration age, registrant transparency, hosting history
  • Reputation — review patterns, complaint mentions, social proof consistency
  • Infrastructure — hosting quality, server behavior, technical configuration
  • Transparency — visible contact details, clear policies, business identity
  • Compliance — adherence to standard e-commerce and privacy practices

Those signals feed an AI model that outputs a score from 0 to 100, sorted into plain verdicts: dangerous, suspicious, caution, mostly safe, or trusted. A site scoring in the trusted range has cleared many of the checks a careful shopper might run manually, just faster.

Automated verifiers are valuable because they aggregate many signals quickly, but the smartest use of them is alongside manual checks like searching for complaints and confirming contact details, not instead of those checks.

Treat any score as an informed indicator, not a legal guarantee. No automated tool can promise a seller will ship your order or that a company won't fail tomorrow. For deeper reading on the difference between authenticity and appearance, Verified fyi's guide on verifying business website authenticity walks through the distinction in more detail.

What Should You Do If You Already Paid a Scammer?

Speed matters more than anything else here. The first hour after you realize something is wrong determines how much of your money you can recover.

  1. Call your credit card issuer immediately if that's how you paid, and ask them to dispute the charge and place a fraud hold on the account. FTC guidance confirms credit cards give you the strongest built-in dispute protection of any common payment method.
  2. If you paid by wire, cryptocurrency, or gift card, report it to your bank and local police anyway, even though recovery odds are low. Documentation matters more than optimism here.
  3. File a report at ReportFraud.ftc.gov and keep every screenshot, order number, and confirmation email in one folder.
  4. Change passwords on any account that shared login details or payment information with the scam site, especially if you reuse passwords elsewhere.

Pro Tip: Save your Verified fyi report alongside your evidence folder. A documented trust score at the time of purchase can support a dispute claim if your card issuer asks why you believed the seller was legitimate.

Educate Your Team on Scam Tactics and Social Engineering

Most scams that hit a small business don't target the owner directly. They target whoever answers the phone, checks the shared inbox, or has purchasing authority that day. A brief training session covering the patterns scammers use again and again does more to prevent losses than any single piece of software.

Walk your team through what urgency-based manipulation looks like: a fake vendor email demanding an invoice paid within the hour, a "CEO" texting from an unfamiliar number asking for gift cards, a caller claiming to be from a bank who already knows your business name. CISA's guidance on phishing emphasizes that these attacks work by exploiting emotion and time pressure, not technical sophistication. The fix is procedural, not technical: anyone can pause a request and verify it through a second channel before acting.

Make that pause a written policy, not a suggestion. Require a phone call to a known number before wiring money based on an email request alone. Require a second person's sign off on any purchase over a set dollar amount. Post a short reference list of common scam formats near shared workstations, since recognition is easier when someone has seen an example recently.

Revisit this training twice a year at minimum. Scam scripts evolve fast enough that a policy written eighteen months ago may not cover the newest impersonation tactics your team will actually encounter.

Set Up Multi-Factor Authentication and Strong Password Rules

A stolen password stops being useful to a scammer the moment multi-factor authentication (MFA) is turned on, because they'd also need your phone or authenticator app to get in. Enable it on every account that touches money, customer data, or your domain registrar, starting with email, banking, and payment processors.

Pick an authenticator app over SMS text codes where the option exists. Text messages can be intercepted through SIM-swapping attacks, while an app like Google Authenticator or Authy generates codes locally on your device.

Password policy matters just as much as MFA. Require passwords of at least twelve characters, and push your team toward a password manager rather than memorized patterns, since reused or simplified passwords are exactly what credential-stuffing attacks rely on. A single compromised password reused across five accounts turns one breach into five.

Set a policy, in writing, that no one shares login credentials over email or chat, even internally. Scammers who compromise one inbox routinely search it for exactly those kinds of messages. If your business handles customer payment data, confirm your payment processor requires MFA on its own dashboard too. That account is often a higher-value target than your email.

Why Software Updates and Patches Matter More Than You Think

Unpatched software is one of the most common doors scammers walk through, because known vulnerabilities are public information the moment a vendor releases a fix. Every day you delay an update is a day attackers can exploit a flaw that's already documented online.

Turn on automatic updates wherever your software allows it: operating systems, browsers, plugins, and any e-commerce platform or content management system running your business site. Manual updates get postponed indefinitely when they depend on someone remembering to run them.

Pay particular attention to browser extensions and third-party plugins. A shopping cart plugin or a WordPress add-on that hasn't been updated in two years is a common entry point, since attackers scan for exactly those outdated versions. Remove any plugin or tool you're no longer actively using rather than leaving it installed and unpatched.

If your business relies on point-of-sale systems, invoicing software, or a customer relationship platform, confirm the vendor still supports the version you're running. Software that's reached end-of-life stops receiving security patches entirely, which turns a familiar tool into an open risk over time.

Monitor Accounts for Suspicious Activity Before It Escalates

Catching fraudulent activity within hours instead of weeks is usually the difference between a minor inconvenience and a serious loss. Most banks, payment processors, and major platforms offer free alert settings that go unused simply because no one turned them on.

Enable transaction alerts on every business bank account and credit card, set to notify you for any charge above a threshold you choose. Do the same for login alerts on email, cloud storage, and any platform tied to customer payment data. Getting a text the moment someone logs in from an unfamiliar device gives you a chance to lock the account before damage spreads.

Review account activity logs on a fixed schedule rather than only when something feels wrong. Weekly is reasonable for a small operation; daily makes sense if you handle high transaction volume. Look specifically for login times outside normal business hours, password reset requests you didn't initiate, and small test transactions, since scammers often run a $1 charge to confirm a stolen card works before attempting a larger one.

Assign monitoring to a specific person, even in a business of one. "Someone should check this eventually" is how suspicious activity sits unnoticed for weeks. A calendar reminder tied to a name gets checked; a vague good intention doesn't.

Build an Incident Response Plan Before You Need One

Deciding what to do during an active scam attempt, in the moment, under pressure, is how mistakes happen. A short written plan drafted in advance turns a panic response into a checklist.

Start with a single question your plan needs to answer clearly: who does an employee contact first if they suspect a scam attempt, whether that's a suspicious email, an unauthorized charge, or a caller requesting sensitive information? Name that person and their backup, not just a department.

List the immediate containment steps: disconnect the affected device from the network if malware is suspected, freeze the account in question, and preserve rather than delete any suspicious message. Screenshots and headers matter for later reporting, so instruct your team to capture evidence before closing anything.

Include reporting obligations in the plan itself. If customer data was exposed, some states require notification within a set window. Note where you'll file a report, whether that's ReportFraud.ftc.gov or a sector-specific regulator, so no one has to research that mid-crisis.

Test the plan once a year with a walkthrough, not just a document review. A plan nobody has practiced tends to fall apart on the exact details that matter, like who actually has authority to freeze a bank account on a Saturday.

Filter Email and Block Phishing Before It Reaches an Inbox

The best phishing defense is the one your team never has to make a judgment call on, because the message never lands in their inbox at all. Modern email filtering catches a large share of scam attempts before a human even sees the subject line.

Enable your email provider's built-in spam and phishing filters at the strictest setting your workflow can tolerate, and add sender authentication protocols, SPF, DKIM, and DMARC, to your domain's DNS records. These three standards work together to confirm a message claiming to come from your domain actually did, which blocks a common impersonation tactic where scammers spoof your own company name to target your customers or vendors.

Layer on a dedicated anti-phishing tool if your email volume or industry risk justifies it. These tools scan links inside messages in real time rather than trusting them at face value, which catches the newer domains that generic spam filters haven't flagged yet.

Train your team on one habit that filtering software can't replace: never click a link inside an unexpected message, even one that looks internal. Type the company's known URL directly or find the verified contact separately, a step CISA's phishing guidance specifically recommends because spoofed links are built to survive a casual glance.

The Publisher's Perspective on Combining Automated and Manual Checks

Some website verification models are built around a simple bet: no single signal tells you whether a site is safe, but many of them together tell you a lot. A 0-100 score exists to compress that complexity into something you can act on in seconds, not to replace your own judgment.

The strongest results come from combining both. Automated scoring catches infrastructure and reputation patterns a shopper would never think to check manually, while human checks catch context a machine can't weigh, like whether a "too good to be true" price actually matches the brand. Treat verification as one input into your final purchase decision, alongside your own read of the seller's online reputation, never as a substitute for it.

— Nick

Run a Free Trust Check Before Your Next Online Purchase

Every checklist in this article boils down to research you'd otherwise do by hand across five or six browser tabs. Verified fyi condenses that into one step: paste a URL into the free website trust checker, and you'll get a 0-100 score with a plain-language breakdown of exactly which security, ownership, and reputation signals pushed that number up or down.

Verified fyi

A score in the "trusted" or "mostly safe" range means the site cleared the categories that matter most: security, transparency, and reputation among them, though pairing that result with your own quick contact-and-terms check never hurts. If you run a storefront yourself, the trust badge gives your own customers that same signal before they check out, which matters more the less recognizable your brand is. Curious what a real verification report looks like before you run your own? Browse recently checked websites to see the scoring in action, then run your own check the next time an unfamiliar seller asks for your card number.

Sources

The guidance in this article draws directly from government consumer protection resources. The FTC's online shopping advice covers payment safety and common scam patterns in more depth. CISA's phishing recognition guidance explains social engineering tactics and Google Safe Browsing. For domain lookups, ICANN's RDAP and WHOIS resources explain registration transparency and its limits.

FAQ

Is a Padlock Icon Proof a Website Is Safe?

No. The padlock only confirms your connection to the site is encrypted, not that the business behind it is legitimate. FTC guidance confirms scammers routinely run HTTPS-secured sites.

What's the Fastest Way to Check if a Site Is a Scam?

Paste the URL into a verifier like Verified fyi to get a 0-100 trust score in seconds, then confirm the contact page and return policy exist. Combining both takes under two minutes and catches most obvious scams.

Should I Ever Pay by Wire Transfer or Gift Card?

Avoid it whenever a seller insists on gift cards, wire transfers, or cryptocurrency with no credit card option. This is one of the clearest scam indicators the FTC tracks, since these payment methods offer almost no dispute protection.

Does Verified fyi Cost Anything to Use?

The website trust checker is free to use at Verified; current pricing for any additional products, including the trust badge, is listed on the site itself.

What Should I Do First if I Realize I Was Scammed?

Contact your credit card issuer immediately to dispute the charge if that's how you paid, since this offers the strongest recovery odds. Then file a report at ReportFraud.ftc.gov and save every screenshot and order confirmation as evidence.

Wondering about a site right now?

Paste the address — we'll run 200+ checks and give you a plain-English verdict in seconds.

Frequently asked questions

Is a Padlock Icon Proof a Website Is Safe?

No. The padlock only confirms your connection to the site is encrypted, not that the business behind it is legitimate. FTC guidance confirms scammers routinely run HTTPS-secured sites.

What's the Fastest Way to Check if a Site Is a Scam?

Paste the URL into a verifier like Verified fyi to get a 0-100 trust score in seconds, then confirm the contact page and return policy exist. Combining both takes under two minutes and catches most obvious scams.

Should I Ever Pay by Wire Transfer or Gift Card?

Avoid it whenever a seller insists on gift cards, wire transfers, or cryptocurrency with no credit card option. This is one of the clearest scam indicators the FTC tracks, since these payment methods offer almost no dispute protection.

Does Verified fyi Cost Anything to Use?

The website trust checker is free to use at Verified; current pricing for any additional products, including the trust badge, is listed on the site itself.

What Should I Do First if I Realize I Was Scammed?

Contact your credit card issuer immediately to dispute the charge if that's how you paid, since this offers the strongest recovery odds. Then file a report at ReportFraud.ftc.gov and save every screenshot and order confirmation as evidence.

V
verified.fyi

We build free, plain-English safety reports for any website — 200+ checks in seconds. More about us.

More from the blog

View all posts →
Articles

Parents: Stop Before You Tap, 5 URL Checks for Teen Social Safety

Sep 24, 2026 · 15 min read
Articles

5 Quick Checks to Vet B2B Partner Sites in 5 Minutes, Use Verified fyi

Sep 22, 2026 · 13 min read
Articles

Shoppers: 7 Checks to Validate Websites in 5 Minutes with Verified.fyi

Sep 19, 2026 · 12 min read

Check before you trust

Free, instant, no account needed — paste any site and get a plain-English verdict.

Check a site →