How to tell if a shop link is legit before you pay

Read the domain first, and read it one character at a time. Most fake shops are not clever — they are a real brand's name with a hyphen inserted, a letter doubled, or a .com swapped for a .shop. That single check catches more bad links than every other check combined.
The rest of this is the order worth working through when a link comes from a video, a story, or a comment, and you have never heard of the store.
The checks, in order of what they catch
- The domain, character by character.Lookalike domains are the entire category. Compare it against the brand's own site, which you should reach by searching the brand name yourself rather than by following the link you are checking.
- The returns page. Not whether one exists — whether it says anything. Real policies name a window, an address, and who pays return postage. Fake ones are three vague sentences, or a page that links back to the homepage.
- A way to reach a human. A contact form alone is weak. A physical address and a working email is strong. An address that turns out to be a residential flat or a car park is a decisive no.
- The price, against the brand's own. A genuine retailer discounts. A fake store discounts everything, permanently, by 60–80%, across brands that never appear on sale together.
- Reviews somewhere the store does not control. The testimonials on the site itself are worth nothing. What matters is whether the store exists anywhere else at all.
What the padlock does and doesn't mean
The padlock in the address bar means the connection is encrypted. That is all it has ever meant. Certificates are free and issued in minutes, so a scam site has one for the same reason a real one does.
Its absence is still a red flag — a checkout page without HTTPS in 2026 is genuinely alarming. But its presence is not evidence of anything except that the traffic is private, including the traffic carrying your card number to a stranger.
Pay in a way that can be undone
The most useful protection is not a check at all, it is the payment method. A card or a payment provider with buyer protection gives you a dispute process. A bank transfer, a gift card, or a “friends and family” payment gives you nothing, which is precisely why fake stores nudge you toward them at the last step.
If the checkout suddenly asks for a different payment method than the one advertised, that is the moment to close the tab.
Two checks for when it still feels off
If the store passes the list above and something still itches, two more checks take about a minute each:
- Reverse-search the product photos. Save an image from the store and run it through a reverse image search. If the same photos appear on a dozen storefronts under different brand names, you have found a dropshipping front at best and a fake at worst. Real stores shoot their own product; their photos live in one place.
- Look up the domain's age. A WHOIS lookup is free and takes seconds. A store claiming years of five-star service on a domain registered eleven days ago has answered your question for you. Scam stores burn domains constantly because blocklists catch up — youth is not proof of fraud, but a claimed history that predates the domain itself is.
The 60-second version
When the video is good and the urge is strong, this is the minimum worth doing before the checkout page: read the domain character by character, open the returns page, check one price against the brand's own site, and pay by a method with a dispute process. Four checks, one minute, and it catches the overwhelming majority of what's out there.
The uncomfortable part
None of this is a guarantee. A well-built fake store passes four of the five checks above, and a small legitimate brand with a bad website fails two of them. Checks shift the odds; they do not settle the question.
Which is the reason we do this server-side rather than asking anyone to do it by hand. Every link in Stealsy is opened and checked before it reaches you: the page has to be alive, and it has to be about the product it claims to be about. A page we could not reach is marked unverified rather than dressed up as certain.
Get Stealsy for iPhone — links you don't have to vet yourself.
Common questions
- What is the fastest way to check if an online store is legit?
- Read the domain character by character before anything else. Fake stores overwhelmingly rely on lookalike domains — an inserted hyphen, a doubled letter, a .shop or .store version of a well-known .com. If the domain is not exactly the brand's own, nothing else on the page matters.
- Does a padlock icon mean a shopping site is safe?
- No. The padlock only means traffic to the site is encrypted, and any site can obtain a certificate for free in minutes. It tells you nobody is reading your connection; it tells you nothing about who is on the other end of it.
- What should I do if I already paid a fake shop?
- Contact your card issuer or payment provider immediately and ask about a chargeback rather than waiting for the order to arrive. Keep the order confirmation, the listing, and any messages. Paying by card or through a provider with buyer protection is what makes this recoverable at all.