← All posts

How to tell if a shop link is legit before you pay

· 5 min read

A clay-style clipboard with a gold checkmark

Read the domain first, and read it one character at a time. Most fake shops are not clever — they are a real brand's name with a hyphen inserted, a letter doubled, or a .com swapped for a .shop. That single check catches more bad links than every other check combined.

The rest of this is the order worth working through when a link comes from a video, a story, or a comment, and you have never heard of the store.

The checks, in order of what they catch

What the padlock does and doesn't mean

The padlock in the address bar means the connection is encrypted. That is all it has ever meant. Certificates are free and issued in minutes, so a scam site has one for the same reason a real one does.

Its absence is still a red flag — a checkout page without HTTPS in 2026 is genuinely alarming. But its presence is not evidence of anything except that the traffic is private, including the traffic carrying your card number to a stranger.

Pay in a way that can be undone

The most useful protection is not a check at all, it is the payment method. A card or a payment provider with buyer protection gives you a dispute process. A bank transfer, a gift card, or a “friends and family” payment gives you nothing, which is precisely why fake stores nudge you toward them at the last step.

If the checkout suddenly asks for a different payment method than the one advertised, that is the moment to close the tab.

Two checks for when it still feels off

If the store passes the list above and something still itches, two more checks take about a minute each:

The 60-second version

When the video is good and the urge is strong, this is the minimum worth doing before the checkout page: read the domain character by character, open the returns page, check one price against the brand's own site, and pay by a method with a dispute process. Four checks, one minute, and it catches the overwhelming majority of what's out there.

The uncomfortable part

None of this is a guarantee. A well-built fake store passes four of the five checks above, and a small legitimate brand with a bad website fails two of them. Checks shift the odds; they do not settle the question.

Which is the reason we do this server-side rather than asking anyone to do it by hand. Every link in Stealsy is opened and checked before it reaches you: the page has to be alive, and it has to be about the product it claims to be about. A page we could not reach is marked unverified rather than dressed up as certain.

Get Stealsy for iPhone — links you don't have to vet yourself.

Common questions

What is the fastest way to check if an online store is legit?
Read the domain character by character before anything else. Fake stores overwhelmingly rely on lookalike domains — an inserted hyphen, a doubled letter, a .shop or .store version of a well-known .com. If the domain is not exactly the brand's own, nothing else on the page matters.
Does a padlock icon mean a shopping site is safe?
No. The padlock only means traffic to the site is encrypted, and any site can obtain a certificate for free in minutes. It tells you nobody is reading your connection; it tells you nothing about who is on the other end of it.
What should I do if I already paid a fake shop?
Contact your card issuer or payment provider immediately and ask about a chargeback rather than waiting for the order to arrive. Keep the order confirmation, the listing, and any messages. Paying by card or through a provider with buyer protection is what makes this recoverable at all.