THE SHORT ANSWER
Verify a site by checking the exact domain, how you reached it, whether official channels point to it, and whether its contact and payment claims hold up independently. Spelling and browser warnings can reveal problems, but their absence does not guarantee safety.
Treat visual checks as clues, not guarantees
| Question | Why it helps | Limit |
|---|---|---|
| Domain | Is the exact spelling and ending expected? | A plausible domain can still be malicious |
| Route | Did an official app or saved bookmark lead here? | Search results and ads can misdirect |
| Offer | Is price or scarcity implausible? | A realistic price does not prove legitimacy |
| Payment | Are protected methods available? | A familiar checkout can still be copied |
Leave the site to verify the site
Find the organization through a known app, a saved address, a statement or another authoritative source. Compare contact details and policies. For a seller, check independent history and the marketplace's own protection process rather than testimonials displayed by the seller.
Evidence & context: United States Federal Trade Commission
Respect browser and security warnings
Do not dismiss certificate, reputation or unsafe-download warnings simply because the page looks familiar. Stop and navigate independently. A padlock indicates an encrypted connection to a domain; it does not certify the business behind it.
Use a low-risk next step
- Do not sign in through an unexpected link.
- Do not move a marketplace payment off platform under pressure.
- Do not install software for unsolicited support.
- If credentials were entered, start account recovery from the official service.
For seller and buyer situations, continue to Digital Fraud in Marketplaces & Online Commerce.
Sources & further reading
- How To Avoid a Government Impersonation Scam
United States Federal Trade Commission. Official consumer guidance on urgency, payment demands, caller-ID limits and contacting an organization through a known channel. Agency examples and reporting routes are United States-specific.
- Phishing Guidance: Stopping the Attack Cycle at Phase One
Cybersecurity and Infrastructure Security Agency. Current defensive guidance on phishing resistance, MFA and organisational controls. Specific authentication choices depend on service support and risk.
Examples and exercises are illustrative unless attributed to a source. No independent expert review is claimed.
A correction, a counterexample or an experience worth sharing?
Join the conversation ↗