How to Recognise Fake Websites
Check a website's real address, warning signs, and safer alternatives before entering personal or payment details.
Start the guide
Start with the first step, try it on your own device, and use the next-step section at the end if you want a clear follow-on guide.
Guide details and who this is for
Guide details
- Published
- January 15, 2025
- Updated
- July 18, 2026
- Country scope
- Global
Who this is for
Best for anyone checking whether a message, website, payment, or request is safe.
Be careful
Pause if anything asks for passwords, OTP codes, money transfers, or urgent action. Real organisations do not need you to panic to prove they are genuine.
Before you begin
What this guide helps you do
This guide shows the main warning signs to check before you click, reply, log in, share details, or pay.
Best time to use it
Use it when something feels urgent, unusual, or asks for personal information, codes, or money.
Common mistake to avoid
Do not act while pressured. Slow down first, then verify the sender, website, or request.
Helpful tech words
Open a plain-English term first if you need it
Phishing
A trick where someone pretends to be a trusted company or person — like your bank, CPF Board, or the police — to steal your passwords or personal details. It usually comes as a fake SMS, email, or phone call.
OTP (One-Time Password)
A temporary code sent to your phone or email that can only be used once for a single login or transaction.
Two-Factor Authentication (2FA)
A security step that asks you to prove who you are in two ways — usually your password plus a code sent to your phone. It makes your accounts much harder to break into.
Check a Website Before You Trust It
Fake websites copy the colours, logos, and wording of banks, delivery companies, government services, shops, and social networks. A page can look professional and still be controlled by a criminal. The website address is usually more useful than the design.
Start with the registered domain
The domain is the main part of the address that identifies who controls the site. It appears after https:// and before the next /.
- In
https://www.gov.uk/check-passport/, the domain isgov.uk. - In
https://gov.uk.verify-account.co/login, the domain isverify-account.co. - In
https://secure.example-bank.com/, the domain isexample-bank.com;secureis only a subdomain.
Read the address carefully from left to right, then identify the final registered name before the path begins. Watch for swapped letters, extra hyphens, unexpected words, and endings that do not match the organisation’s normal website.
Do not treat the padlock as approval
The padlock and https mean the connection is encrypted. They do not prove that the owner is trustworthy. Scam sites can obtain encryption certificates automatically, so check both the domain and the purpose of the page.
Warning signs on the page
Pause when a website:
- says an account will be closed unless you act immediately
- asks for a password, one-time code, recovery phrase, or remote access
- promises a prize, refund, investment return, or parcel release for a small payment
- offers a price that is dramatically lower than every established seller
- provides no verifiable company name, address, returns policy, or support channel
- prevents you from navigating to other parts of the supposed organisation’s site
Spelling mistakes can be a clue, but polished grammar is not proof of safety. Modern scam pages are often well written.
Use an independent route instead
If a message tells you to open a website, avoid its link. Use one of these safer routes:
- Open the organisation’s official app from your phone.
- Type an address you already know or use a trusted bookmark.
- Find the organisation through an official government directory or a statement you already possess.
- Call the number printed on your bank card, bill, or official document.
Do not rely on the phone number or contact details shown on the suspicious page.
If you already entered information
Close the page and act according to what you shared. Change an exposed password from the genuine service, enable two-step verification, and sign out other sessions. If you entered card or banking information, contact the bank immediately using the number on the card. If you installed software or allowed remote access, disconnect the device from the internet and seek trusted technical help.
For more guidance, read the US Cybersecurity and Infrastructure Security Agency’s advice on recognising and reporting phishing, or use the equivalent national cybersecurity authority in your country.
Try it yourself — follow along now Click to expand
Follow along and tick each step as you go. You can use a real device right now!
✨ Tip: Ticking these boxes only works on your screen — nothing is saved or sent anywhere.
You finished this guide
What do you want to do next?
Move to the next recommended guide if you want a clear progression, or ask a real person if you would rather check before trying something new.