How to Check If a Website Is Safe Before You Pay: Spotting Fake Sites and URL Red Flags
Before you pay online, knowing how to check if a website is legit can protect your money and personal details. This guide walks you through the key URL and domain red flags every Filipino shopper should know.
Why Website Safety Checks Matter Before You Pay
Online shopping and digital payments have made life more convenient for Filipinos — from buying gadgets on e-commerce platforms to sending money via GCash or Maya. But that same convenience has opened the door for fraudsters who build convincing fake websites designed to steal your money or personal information. Knowing how to check if a website is legit is no longer just a tech skill; it is a basic self-defense habit for anyone who pays, shops, or banks online. A fraudulent website can look almost identical to a trusted brand's page, complete with logos, product photos, and even fake customer reviews. The difference often hides in small details — and that is exactly what this guide will help you catch. Learn the full range of tactics scammers use so you know what you are up against before you even open your browser.
Start With the URL: The First Line of Defence
The web address — or URL — in your browser bar is the single most revealing piece of information about a website's legitimacy. Scammers invest heavily in making their pages look real, but they almost always have to use a web address that is slightly different from the genuine brand they are imitating. Before you do anything else on an unfamiliar site, pause and read the full URL carefully. Look at it on a desktop if you can, because mobile browsers often hide part of the address. If something about the address feels off — a jumbled string of characters, an unexpected word, or a domain you have never heard of — trust that instinct and investigate further.
Warning signs
- Extra words or hyphens inserted into a brand name (e.g., 'shopee-ph-promo.net' instead of 'shopee.com')
- Numbers substituted for letters (e.g., 'l' replaced by '1', or 'o' replaced by '0')
- The real brand name appears as a subdomain rather than the main domain (e.g., 'lazada.fake-shop.com' — 'fake-shop.com' is the actual site)
- Unusual country-code or generic top-level domains you did not expect, such as .xyz, .top, .click, or .shop
- Extremely long, cluttered URLs full of random characters after the domain name
- URLs that were shared via text message, chat, or social media rather than found through a search engine
On your phone, tap the address bar and scroll all the way to the left to reveal the full URL — mobile browsers often cut it short.
HTTPS Is Not Enough: What the Padlock Really Tells You
Many people were taught that a padlock icon in the browser bar means a site is safe. That advice is now outdated and dangerously misleading. HTTPS and the padlock simply mean that your connection to the website is encrypted — they say nothing about whether the website itself is honest or legitimate. Scammers routinely obtain free HTTPS certificates for their fake domains, so a padlock on a phishing site is completely normal. Use HTTPS as a minimum requirement — avoid any site that does not have it — but never use it as proof of trustworthiness on its own.
Warning signs
- A site asks for payment or personal details but shows 'Not Secure' or no padlock at all
- The SSL certificate belongs to a company name that does not match the site you think you are visiting (click the padlock to check)
- The padlock is present but the domain still shows all the other red flags listed in this article
Click or tap the padlock to view the certificate details. Check that the organisation name matches the brand you expect.
How to Check If a Website Is Legit: A Step-by-Step Process
Going through a quick mental checklist before you pay can save you from losing thousands of pesos. This is not about being paranoid — it takes less than two minutes and becomes second nature quickly. If you receive a link in a message and are unsure whether it is real, you can run a free scam check on TsekMuna to help assess it before clicking.
- Copy the full URL and read it carefully from left to right, focusing on the domain name — the part just before the first single slash.
- Search for the brand independently. Open a new tab, type the company name into a search engine, and compare the official domain with the one you were sent.
- Check the domain age. Free tools like WHOIS lookup services can show when a domain was registered. A site that registered its domain only days or weeks ago is a major red flag.
- Look for real contact information. A legitimate business will have a physical address, a working phone number, and a verifiable business registration. Absence of these is suspicious.
- Search for reviews on independent platforms — not reviews displayed on the site itself. Look for the domain name plus words like 'legit', 'scam', or 'review'.
- Check if the business is registered with the Securities and Exchange Commission (SEC) or the Department of Trade and Industry (DTI) for Philippine-based companies.
- Look for a clear, specific privacy policy and terms of service. Scam sites either have none or paste in generic boilerplate text copied from other sites.
- Trust your gut. If the deal seems impossibly good, the site looks hastily built, or you feel pressure to pay immediately, stop and verify more.
Suspicious Payment Methods: Another Layer of Risk
Even if a website passes a basic look-over, the payment options it offers can reveal a lot. Legitimate Philippine e-commerce stores typically accept credit cards via established payment gateways, GCash, Maya, or bank transfer to a verifiable company account. Scam sites often push payment methods that are hard to reverse or trace. Understanding GCash and Maya safety practices is especially important because e-wallet transfers are instant and, once sent to a fraudster, very difficult to recover.
Warning signs
- The only accepted payment is a direct bank transfer to a personal account (not a company account)
- GCash or Maya transfers requested to a personal number rather than a registered merchant account
- Requests for payment via remittance centres, cryptocurrency, or gift card codes
- No option for credit card payment through a recognised payment gateway (e.g., PayMongo, Dragonpay, PayPal)
- Pressure to pay immediately before you can do any additional research
BSP-regulated payment gateways are required to follow consumer protection rules. If a site bypasses them entirely, treat that as a warning sign.
Fake Delivery and Order Confirmation Links: A Related Threat
Scammers do not only build fake storefronts. A common follow-up tactic is sending fraudulent shipping or delivery notification messages containing unsafe links — often after you have already shopped somewhere legitimate. These messages mimic courier companies and ask you to click a link to 'track your parcel' or 'pay a customs fee'. The link leads to a phishing page designed to harvest your login credentials or payment details. Apply the same URL checks described in this article to any delivery-related link you receive. For a deeper look at this specific tactic, see our guide on spotting fake delivery notification links.
What to do instead
- Never click tracking links sent via unsolicited SMS or chat messages — go directly to the courier's official website instead.
- Type the courier's URL manually into your browser rather than copying from a message.
- If a 'customs fee' or 'redelivery fee' is requested via an unfamiliar payment page, call the courier's official hotline to verify before paying.
- Report suspicious delivery messages to the PNP Anti-Cybercrime Group (PNP-ACG) via their official channels.
What to Do If You Already Paid a Suspicious Site
If you realise you may have paid a fraudulent website, acting quickly gives you the best chance of limiting the damage. This guidance is advisory only and not legal advice. Contact your bank, GCash, or Maya immediately to report the transaction and ask whether a dispute or reversal is possible — speed is critical here. Document everything: screenshots of the website, your transaction history, and any messages you received. Then file a formal report. Our step-by-step guide to reporting a scam explains exactly where and how to report to the NBI Cybercrime Division, PNP-ACG, and the BSP Financial Consumer Protection Department.
What to do instead
- Contact your bank or e-wallet provider immediately to flag the transaction.
- Screenshot the suspicious website, the URL, your payment receipt, and all related messages before the site disappears.
- File a complaint with the NBI Cybercrime Division or PNP-ACG — both accept online reports.
- Report the domain to the Cybercrime Investigation and Coordinating Center (CICC) through their official channels.
- Warn others by sharing the domain name (not the link itself) in trusted community groups so others can avoid it.
- Change passwords on any accounts where you used the same credentials as on the fake site.
Frequently asked questions
Does a padlock icon mean a website is safe to pay on?
No. The padlock (HTTPS) only means the connection between your browser and the site is encrypted. Scammers routinely use free HTTPS certificates on fake websites. Always check the actual domain name and look for other trust signals alongside the padlock.
How do I check if a website is legit in the Philippines?
Start by reading the full URL carefully for typos, hyphens, or unexpected words. Then search for the business name on the SEC or DTI databases to verify registration, look for independent reviews using the domain name, check the domain age via a WHOIS lookup, and verify that contact information is real and specific.
What are the most common domain red flags for scam websites?
Watch for brand names with hyphens or misspellings (e.g., 'sh0pee' or 'lazada-sale'), the real brand appearing as a subdomain of an unknown domain, unusual extensions like .top or .xyz, recently registered domains, and URLs that were sent to you unsolicited via SMS or chat.
Is it safe to pay via GCash on an unfamiliar website?
Only if you have verified the site through multiple checks. Confirm the domain is correct, that the GCash payment is processed through a registered merchant account (not a personal number), and that the site has verifiable contact details and reviews. Transfers sent to a fraudster are very hard to recover, so verify first.
Who do I report a fake or scam website to in the Philippines?
You can report to the NBI Cybercrime Division, the PNP Anti-Cybercrime Group (PNP-ACG), the Cybercrime Investigation and Coordinating Center (CICC), and the BSP Financial Consumer Protection Department if money was involved. Your bank or e-wallet provider should also be notified immediately.
Can I check if a link is a scam before clicking it?
Yes. You can copy the URL and paste it into TsekMuna's free scam-check tool to help assess it. Never click unknown links directly — hover over them on desktop to preview the URL first, or check them through a safe verification tool before opening.