Before you type your card number anywhere, it pays to check if a website is safe to avoid handing your details straight to scammers. Fake shopping and payment pages look almost identical to real ones, but a few quick checks reveal the difference. This guide gives Indian shoppers a step-by-step way to verify a site before entering card details.
1. Look for HTTPS and the padlock
The first thing to check is the address bar. A secure site uses HTTPS and shows a small padlock icon before the web address.
- The link should begin with https://, where the “s” stands for secure.
- Tap the padlock to see the connection is encrypted.
Important caveat: HTTPS only means the connection is encrypted, not that the owner is honest. Many scam sites now have padlocks too, so treat this as a minimum requirement rather than full proof.
2. Read the domain name carefully
Fraudsters register look-alike domains that are easy to misread. To check if a website is safe, study the spelling letter by letter.
- Watch for swapped or extra characters, such as “amaz0n” with a zero or “flipcart” instead of the real spelling.
- Check the ending; a trusted Indian store rarely uses an odd suffix like “.xyz” or a long string of words before the real brand.
- Be careful with links in SMS and email; hover or long-press to preview the true destination before tapping.
The real brand name should sit immediately before the “.com” or “.in”, not buried inside a longer string.
3. Check for contact details and policies
Genuine merchants publish ways to reach them and clear terms. Before paying, look for:
- A physical address, phone number and working email on the “Contact Us” page.
- A clear return, refund and privacy policy.
- Terms and conditions written in proper language without heavy spelling errors.
A store that hides who runs it, or offers only a web form, deserves extra caution. As a quick test, call the listed number or send a short email before a big purchase; a real business usually responds, while a scam page often gives a number that never connects.
4. Be suspicious of unrealistic deals and pressure
Scam sites lure shoppers with prices that are too good to be true and timers that rush you:
- Branded electronics at a fraction of the normal price.
- Pressure tactics like “only 2 left, pay in 5 minutes”.
- Requests to pay by direct UPI transfer to a personal number instead of a proper checkout.
If a deal feels rushed or strange, close the tab and look for the product on a known store instead.
5. Verify the payment page and reviews
- At checkout, confirm the padlock and HTTPS are still present on the payment page itself.
- Check that card payments route through a recognised gateway and that an OTP step appears, as the Reserve Bank of India requires an additional factor of authentication for online card payments.
- Search the store name with words like “review” or “fraud” to see other shoppers’ experiences.
- Prefer cards or trusted gateways over direct transfers for better dispute protection.
6. Extra tools to check if a website is safe
For an added layer of confidence, keep your browser and phone updated so built-in warnings work, and avoid entering card details on public Wi-Fi; use mobile data or a trusted network instead.
Building these habits matters across all payments. See our guide on how to spot a fake payment app before you download it, and learn to enable two-factor authentication on your bank account so a stolen card number alone cannot be misused. The habits in UPI frauds and how to stay safe while paying online add further protection.
Safe site versus likely-scam site: a signal-by-signal comparison
When unsure, compare what you see against how a genuine store usually looks:
| Signal | Safe site | Likely-scam site |
|---|---|---|
| Domain | Correctly spelled, brand just before .com or .in | Misspelled or padded, like “bigbillion-deals.xyz” |
| HTTPS / padlock | Present on every page, including checkout | Missing on some pages, or padlock with a warning |
| Contact details | Real address, phone, email and GST number | Only a web form, or a dead phone number |
| Prices | Near market rate, normal discounts | Flagship phone at ₹6,999 with a timer |
| Payment routing | Recognised gateway with an OTP step | Direct UPI to a personal ID, gift cards or crypto |
| Reviews / age | Years of reviews; domain registered long ago | No history; domain registered days earlier |
One red entry may be innocent, but two or more together is reason to walk away.
How to check a website on desktop versus mobile
The same checks work on both, but the steps differ slightly.
On a desktop or laptop
- Read the full web address; Chrome, Edge and Firefox show it in full.
- Hover over any link without clicking; the real destination shows at the bottom-left.
- Click the padlock and open the certificate details to confirm the connection is valid and not expired.
On a mobile phone
- Tap the address bar once so the browser shows the complete URL, not just the brand name.
- Long-press a link to preview where it really leads before opening it.
- Tap the padlock for connection details, and take extra care with links opened inside WhatsApp, Instagram or SMS, where the address bar can be hidden.
If a link arrives in a message, ignore it and type the store’s name into your browser or open its official app instead.
Free tools that confirm whether a website is trustworthy
Three free tools give independent evidence about a site, no account needed:
- Google Safe Browsing site-status: paste the address into Google’s Transparency Report tool; it flags any known malware or phishing.
- VirusTotal URL scan: enter the link and it checks against dozens of security engines at once, showing how many call it harmful.
- WHOIS domain-age lookup: a free WHOIS search shows when the domain was registered. A site selling branded goods that is only days or weeks old is a serious warning sign, since real stores build over years.
A clean result is not proof of honesty, but a flag or a brand-new domain is reason to stop.
A real scenario: the festive-sale link from an Instagram ad
Suppose an Instagram ad offers a ₹79,999 phone for ₹8,999, “today only”. The page looks like a well-known store, but the checks play out fast:
- The address bar reads “festivemegasale-india.shop”, not the brand’s real .in address.
- The price is a tenth of market rate, with a ten-minute countdown.
- The footer has no GST number, no company name, only a chat form.
- Checkout wants UPI to a personal ID and skips the OTP step.
Any one alone justifies caution; all four mean you close the tab and shop elsewhere.
India-specific checks before you pay
Some signals are specific to Indian e-commerce:
- GST number and registered name: genuine sellers usually show a GST identification number and a registered company name in the footer or “About” page.
- Verified social handles: check the brand’s official Instagram, X or Facebook for a verified badge and long history, and confirm the website link matches.
- Recognised payment gateway: checkouts routed through Razorpay, PayU or BillDesk are handled by regulated providers, far safer than a raw UPI request to an individual.
- RBI additional-factor authentication: domestic online card payments must trigger an OTP or in-app approval; a checkout that skips this has bypassed a core safety rule.
A legitimate gateway never asks for your card PIN or net banking password on the merchant’s page; only your bank’s own screen handles authentication.
Red flags that should make you stop
Even after the basic checks, some signs mean you should not enter card details:
- The browser itself shows a warning such as “Your connection is not private” or “Deceptive site ahead”.
- The page asks for your full card number, expiry, CVV and your card PIN or net banking password together; legitimate gateways never need your card PIN online.
- The checkout skips the bank’s OTP or in-app approval step entirely.
- The site insists on payment by gift cards, cryptocurrency or a direct transfer to an individual’s UPI ID.
- Pop-ups claim you have “won” a prize and ask for card details to release it.
Any one of these is reason enough to close the page. When you check if a website is safe and something feels off, trusting that instinct usually protects you.
Extra protection for your card
You can limit the damage even if a site proves fraudulent.
- Set a low online or international transaction limit on your card through your bank app, and switch it on only when needed.
- Turn on instant transaction alerts so you spot any misuse within seconds.
- Use a one-time virtual card, where your bank offers it, for unfamiliar stores.
- Never save card details on small or unknown websites.
These controls, paired with the checks above, mean a single risky purchase can never expose your whole account.
Frequently asked questions
Does the padlock mean a website is safe?
Not entirely. The padlock and HTTPS confirm the connection is encrypted, but scammers can obtain them too. Treat the padlock as a minimum check, then verify the domain spelling, contact details, policies and reviews before you decide to enter card details.
How do I check if a website is safe on my phone?
Look for https:// and the padlock in the address bar, long-press links to preview the real destination, and read the domain name carefully for misspellings. You can also paste the URL into Google’s Safe Browsing site-status tool to see if it is flagged.
Is it safe to save my card on shopping sites?
Saving cards is convenient but riskier if the site is breached. In India, card details are tokenised for added safety, yet it is safest to save cards only on large, trusted merchants and to avoid storing them on unfamiliar or one-time stores.
What if I already entered card details on a fake site?
Contact your bank immediately to block the card and watch for unauthorised charges. Change related passwords, enable alerts, and report the fraud on cybercrime helpline 1930 or cybercrime.gov.in so the transaction can be investigated quickly.
How can I tell how old a website’s domain is?
Run a free WHOIS lookup and paste in the web address. It shows the registration date. A domain created only days or weeks ago, yet selling branded products at huge discounts, is a classic scam pattern and a strong reason to avoid entering any card details there.
Is paying through Razorpay or PayU safer than direct UPI?
Generally yes. Gateways like Razorpay, PayU and BillDesk are regulated providers that route money to the merchant and support an OTP step, so you have a clear record and dispute path. A direct UPI transfer to a personal ID offers almost no protection if the seller turns out to be fake.
Conclusion
When you check if a website is safe before entering card details, you move from hoping to knowing. Confirm HTTPS and the padlock, study the domain, look for real contact details, and verify the payment page. Steps and screens vary by browser, bank and store, so confirm anything unclear with your bank. This article is general safety guidance, not financial advice.

























































