How to Spot a Fake or Spoofed Website
By Aisha Khan · · 7 min read
The single most reliable check is to read the exact web address before you log in or pay. Look at the domain just before the first single slash, make sure it is the real brand and not a lookalike with swapped characters or extra words, and be suspicious of any page that pressures you to act fast. The padlock proves encryption, not honesty — your eyes on the address are what protect you.
Why fake sites are so convincing
A spoofed website is a copy designed to look exactly like a real one — same logo, same colours, same login form — but it sends whatever you type straight to a scammer. Because building a convincing copy is easy, the giveaway is rarely the appearance. It is almost always the address. That is why learning to read a URL is the most valuable skill in this article.
Read the domain, not the decoration
The important part of a web address is the domain: the name that sits immediately before the first single slash. In https://shop.example.com/account, the domain is example.com. Everything to the left can be made up by the scammer. So example.com.login-secure.net is not example.com — the real domain there is login-secure.net, and the brand name is just dressing placed in front to fool a quick glance.
Tricks to watch for in the address
- Look-alike characters: a letter swapped for a number, a doubled letter, or a near-identical character from another alphabet.
- Extra words and hyphens: additions like "-secure", "-verify" or "-support" bolted onto a brand name.
- The brand as a subdomain: the real name placed before the true domain, as in the example above.
- Unusual endings: a familiar brand on an unexpected or obscure domain ending.
Other warning signs
Beyond the address itself, a few patterns recur on fake sites:
- Pressure and urgency. "Verify within 24 hours or lose your account" exists to rush you. Real companies seldom work this way.
- No real contact details. A missing address, no phone number and no proper company information are red flags.
- Odd wording or layout. Awkward phrasing, mismatched fonts or broken links suggest a hasty copy.
- Unexpected requests. Being asked for your full password, a card PIN or a one-time code by a site or message is a strong sign of a scam.
- A login form you reached from a link. Many spoofs arrive as a link in an email or text that drops you straight onto a fake sign-in page.
The habit that defeats most spoofs
If a message claims there is a problem with one of your accounts, do not use its link. Open a new tab and reach the company yourself by typing the address or using a bookmark, then log in there. If the warning is genuine, you will see the same notice once you are signed in directly. This one habit — never log in from a link in an unexpected message — neutralises the vast majority of spoofing attempts.
A password manager helps here too. Because it only offers to autofill on the exact domain where you saved your details, a lookalike site will quietly fail to trigger autofill — a handy early warning that you are not where you think you are. Our browser security guide explains how to set that up safely.
If you have already been caught
If you entered details on a site you now suspect is fake, act quickly but calmly. Change that account's password from the genuine site, and change it anywhere you reused it — create fresh, unique ones with our password generator and confirm their strength in the analyser. Turn on two-factor authentication, watch for unusual activity, and if you entered card details, contact your bank. For a full walkthrough, see how to recover a hacked account.
Frequently asked questions
What is the most reliable way to tell a fake site from a real one?
Read the exact domain in the address bar, focusing on the part just before the first single slash. Make sure it is the real brand's domain and not a lookalike with extra words, swapped characters or an unusual ending. The padlock alone does not prove a site is genuine.
What are look-alike characters in a web address?
Scammers register domains that resemble real ones by swapping similar-looking characters, adding hyphens or extra words, or using a different ending. Examples include replacing a letter with a number or using a near-identical character from another alphabet. Reading the domain slowly helps you catch these.
Are pressure tactics a warning sign?
Yes. Genuine companies rarely demand that you act within minutes or your account will be lost. Countdown timers, threats of suspension and urgent payment requests are designed to stop you thinking clearly, so treat strong urgency as a reason to slow down and verify independently.
What should I do if I am unsure about a link?
Do not click it. Open a new tab and reach the company yourself by typing its address or using a saved bookmark, then log in there. If a message claims there is a problem with your account, you will see the same notice when you log in directly if it is real.
What if I already entered my details on a fake site?
Change the password for that account immediately from the genuine site, and change it anywhere you reused it. Turn on two-factor authentication, watch for unusual activity, and if card details were entered, contact your bank. Acting quickly limits the damage.
This article is general online-safety education, not professional security advice.