How to Tell If a Website Is Safe (the Padlock Is Not Enough)
The browser padlock does NOT mean a site is trustworthy — scam pages have it too. These are the signals that actually reveal a fake site.
We were all taught to "look for the padlock", and today that advice is actively dangerous. The padlock only means the connection is encrypted. A page built to steal from you can have one too — and nearly all of them do.
The signal that matters: the domain
Read the address character by character. Fake pages imitate known brands using tricks like:
- A changed or doubled letter that is easy to miss at a glance.
- An extra word attached to the brand name.
- The brand name used as a subdomain of some unrelated site.
- A different ending than the one the brand actually uses.
Other warning signs
- You arrived via a link: from an email, message or ad. Almost no scam finds you if you type the address yourself.
- Urgency: "your account will be suspended in 24 hours". The rush exists so you do not think.
- It asks for more than it needs: a store selling digital goods does not need your banking password.
- Sloppy writing and odd translations.
- An offer that makes no sense: if the price cannot possibly work, something is broken in the middle.
The golden rule
If a message tells you to log in somewhere, do not use that link. Close it, open the official app or type the address yourself. If the alert was real, you will see it there too.
If you already entered your details
- Change that password immediately
- Change it anywhere else you reused it
- Turn on two-factor authentication where you can
- If you entered banking details, contact your bank
Frequently asked questions
Does the padlock mean the site is trustworthy?
No. It only means the connection is encrypted. Scam sites can and do have padlocks — this is the most dangerous security myth around.
What is the most reliable signal?
The exact domain name. Read it character by character — most fake pages imitate a known brand with one letter changed or an extra word.
How do people end up on these sites?
Almost always through a link in an email, message or ad. Rarely by typing the address themselves.
What if I already entered my details?
Change that password immediately, and anywhere else you reused it, then enable two-factor authentication.