
A legitimate business website is one you can verify as safe and non-fraudulent using technical, ownership, and reputation checks, not one that simply looks polished. That means confirming real HTTPS encryption, a traceable business behind the domain, and a reputation that holds up outside the site's own pages. Groups like the FTC and CISA publish guidance for exactly this kind of check, and tools like a website trust checker can run much of it for you in seconds.
TL;DR:
- A valid HTTPS certificate encrypts your connection but does not verify the seller; check the exact URL, domain age, and certificate details before checkout.
- Search the business name, phone number, and address independently, then compare reviews, public records, and social profiles rather than trusting claims on its site.
- Choose a credit card, which offers dispute rights; reject wire transfers, cryptocurrency, and gift cards, especially when a seller pressures you to act immediately.
- A domain registered only weeks ago, with no search history or recent hosting changes, deserves extra scrutiny; automated scans cannot settle ambiguous results.
- A free automated scan can assess over 200 security and reputation signals, but follow ambiguous results with manual checks of contact details and independent reviews.
Table of Contents
- Quick verification checklist: checks to run before you buy
- Technical signals: HTTPS, certificates, and domain history
- Confirming the business is real, not just the website
- Payment red flags the FTC wants you to know
- If a site looks suspicious: what to do right away
- How verification tools speed up the process
- A practical note on verification habits
- Check any site in seconds with Verified.fyi
- FAQ
- Sources
Quick verification checklist: checks to run before you buy
Before you type in a card number or an email address, run through a short list of checks. None of these take more than a minute, and together they catch most of the scams that slip past a casual glance.
- Look at the exact URL character by character for misspellings, extra words, or an odd extension like ".shop" or ".xyz" standing in for a brand's usual domain.
- Confirm the connection uses HTTPS and click the padlock to check that the certificate matches the site you think you're on.
- Search the business name alongside words like "review" or "complaint" to see what independent sources say.
- Call the listed phone number or look up the address separately. A real business answers or shows up in public records.
- Refuse to pay by wire transfer, cryptocurrency, or gift card, and treat urgency or pressure to "act now" as a warning sign.
- Run the URL through a verification tool such as Verified when you're still unsure after the manual checks.
CISA's own guidance echoes several of these points directly, recommending that shoppers type a known retailer's URL rather than clicking a link from an email or text, since copycat sites are built to look identical to the real thing.
Pro Tip: Bookmark the real site once you've confirmed it, so you never have to retype or re-search the URL on a future visit.
Technical signals: HTTPS, certificates, and domain history

A site's technical footprint tells you things its homepage never will. HTTPS encrypts the data you send, but a certificate alone doesn't prove the business is trustworthy. It proves the connection is private. CISA recommends checking the padlock icon and reviewing certificate details, including the issuer and expiration date, which you can usually see by clicking the padlock in your browser's address bar.
Domain age and registration history matter just as much. A WHOIS lookup shows when a domain was registered and by whom, and a domain that's only a few weeks old is worth a second look, especially if it's selling something urgent or heavily discounted. Watch for these additional clues:
- A registrar or hosting provider in a country that doesn't match the business's claimed location.
- Recent changes to DNS records or hosting, which can signal a site that was recently hijacked or stood up quickly.
- No cached history in search engines, suggesting the domain is brand new.
When you can't interpret a certificate or WHOIS record yourself, CISA suggests running the URL through Google Safe Browsing or a similar automated checker, which flags known malicious domains instantly. Our own safe browsing habits checklist walks through configuring your browser to catch many of these signals automatically.
Confirming the business is real, not just the website
A professional-looking site doesn't guarantee a real business sits behind it. Verifying that takes a few extra steps, but they're straightforward.
- Search the company name alongside "review," "complaint," or "scam," and weigh the pattern you find rather than a single bad review. CISA advises independently searching for a company's name and contact information rather than trusting what the site itself claims.
- Call the listed phone number and look up the physical address on a map or public records search. A disconnected line or a residential address listed as a warehouse is a red flag.
- Check that social media profiles linked from the site are active, consistent in branding, and have a real posting history rather than a handful of stock photos.
- Search business registries or state filing databases when the site claims incorporation, licensing, or a specific legal structure.
- Be skeptical of testimonials that read like marketing copy, use stock photography, or can't be traced to a real review platform. Fabricated reviews often cluster in tone and timing.
Our guide on spotting fake company websites walks through several real examples of these patterns if you want to see what they look like in practice.
Payment red flags the FTC wants you to know
How a site asks you to pay says almost as much as anything else on the page. The FTC's guidance on common scam signs lists impersonation, manufactured urgency, and unusual payment demands as the clearest indicators something is wrong, and payment method is often the easiest of the three to spot.
- Wire transfers, cryptocurrency payments, and gift cards are all irreversible once sent, which is exactly why scammers prefer them, as explained in our detailed push payment fraud prevention steps for businesses.
- A seller who refuses credit cards or insists on a single, unusual payment channel is worth walking away from.
- Pressure to decide immediately, a countdown timer, or threats of a lost deal are classic urgency tactics designed to stop you from checking.
- Paying by credit card gives you dispute rights that other methods don't, so default to it whenever you have a choice.
In 2025, reported losses to scams topped $4 billion, with many cases tied to exactly these irreversible payment methods. That figure reflects just what was reported, so the real total is almost certainly higher.
If a site looks suspicious: what to do right away
If something feels off after you've already entered information or paid, speed matters more than anything else.
- Stop entering any further information and take screenshots of the site, the URL, and any receipts or confirmation emails.
- Report the site to its hosting provider or platform if you can identify one, and file a report with the FTC.
- Contact your bank or card issuer immediately to dispute the charge or freeze the card if you paid by credit or debit.
- Change your password on that site and anywhere else you reused it, then watch your accounts for unusual activity over the following weeks.
Our walkthrough on staying safe on unfamiliar websites covers this process in more depth, including how to word a dispute letter to your card issuer.
How verification tools speed up the process
Manual checks work, but they take time you don't always have when you're mid-checkout. Automated verification tools pull the same signals a careful person would check by hand and compile them into a single read.
- Security blocklists like Google Safe Browsing flag domains already tied to malware or phishing.
- WHOIS data shows domain age and registrar history without you running a separate lookup.
- Certificate checks confirm the encryption is valid and matches the domain.
- Reputation signals pull from mined reviews and complaint patterns across the web.
We built Verified around this exact idea: paste any URL and our system weighs over 200 of these security and reputation signals with AI, then returns a trust score from 0 to 100 along with a plain verdict ranging from dangerous to trusted. It's free, requires no registration, and gives you a breakdown of exactly which signals pulled the score up or down.
Pro Tip: Run the automated scan first, then spend your manual checking time only on whatever it flags, rather than repeating steps the tool already covered.
A tool speeds up triage, but an ambiguous result, like a new domain with no red flags yet and no track record either, still benefits from a quick manual look at contact details and reviews before you commit.
A practical note on verification habits
After writing guides on how to tell if a website is legit and digging through hundreds of flagged domains, the pattern that stands out is how often people skip the thirty-second checks, not the hard ones. A checklist paired with a quick automated scan catches nearly everything a casual shopper runs into, and neither step takes real effort once it's a habit.
— Nick
Check any site in seconds with Verified.fyi
We make this entire process available for free: paste a URL into our trust checker and get a 0 to 100 score, a categorized verdict, and a breakdown of exactly which signals pushed it there, no registration required.

If you run a business and want to show visitors you've been vetted, our trust badge option lets you display a verification result directly on your own site. Start with a free check on any site you're unsure about before your next purchase.
FAQ
What makes a business website legitimate?
A legitimate business website checks out on technical grounds (valid HTTPS, a traceable domain history), ownership grounds (a real, independently verifiable business behind it), and reputation grounds (reviews and complaints that hold up outside the site itself). Visual design alone never confirms any of this, which is why CISA recommends verifying contact information independently rather than trusting what a page claims.
How can I tell if a website is safe before I pay?
Check that the URL matches the brand exactly, confirm HTTPS with a valid certificate, and search for independent reviews before entering any payment details. The FTC advises paying by credit card rather than wire transfer, cryptocurrency, or gift card, since those methods can't be reversed once sent.
What payment methods should I avoid on an unfamiliar site?
Avoid wire transfers, cryptocurrency, gift cards, and peer-to-peer payment apps when buying from a seller you haven't verified, since none of them offer dispute protection. The FTC's guidance points to credit cards as the safer default because disputes are possible if something goes wrong.
What should I do if I think I've been scammed?
Stop sharing any further information, take screenshots of the site and any receipts, and contact your bank or card issuer immediately to dispute the charge. File a report with the FTC and change any reused passwords right away.
How does a tool like Verified.fyi help verify a website?
Verified.fyi analyzes over 200 security, ownership, and reputation signals from a single URL and returns a 0 to 100 trust score with a plain-language verdict, which saves you from running each manual check separately. It works best as a first step, with any flagged results followed up by a closer manual look at contact details and reviews.
Sources
- Tips to stay safe while surfing the web, part 2: Accessing websites securely | CISA
- How to avoid a scam | Consumer Advice (FTC)