We build websites for a living, which means we spend a lot of time looking at other people's. And the thing that has changed most in the last couple of years isn't the good ones - it's the fake ones.
The old advice was basically "look for bad spelling and a dodgy logo". That advice is now worthless. A convincing fake shop can be stood up in an afternoon: a clean template, product photos lifted from the real manufacturer, an About page written in perfect English, a hundred five-star reviews and a comment section full of happy customers who don't exist. It will have the padlock. It will look better than plenty of legitimate small businesses.
So the tells have moved. They're no longer about how a site looks - they're about what's underneath it, and whether anything on it can be checked anywhere else. Here's what we actually look for, and how you can do the same in about five minutes.
Why these things are so much more convincing now
Three things have made fake sites harder to spot, and it's worth understanding them because they explain every check further down.
Writing is free and flawless. The broken-English tell is gone. Product descriptions, About pages, returns policies, review text - all of it can be generated in seconds, in fluent, chatty, entirely plausible English. If you're still relying on spotting a typo, you're checking for something that stopped being evidence a while ago.
Looking professional is free too. A polished e-commerce template costs nothing. HTTPS certificates are free and automatic. The padlock, which a lot of people were taught meant "safe", only means the connection is encrypted - it tells you nobody can eavesdrop on your card details on the way to the fraudster. That's not the reassurance it sounds like.
Social proof can be manufactured wholesale. This is the big one, and it's the bit that catches careful people. The reviews on the site are fake. The comments underneath are fake. And - this is the clever part - the independent-looking review site that rated the product a "best buy" with some very specific-sounding score is often owned by the same people, built for no other purpose than to be the thing you find when you sensibly decide to look for a second opinion.
That's the pattern worth internalising. A good scam doesn't just build the shop. It builds the evidence you'll go looking for.
Checking a shop you've not used before
Here's the order we'd do it in, quickest and most revealing first.
1. How old is the domain?
This is the single most useful check and almost nobody does it. Most fake shops are weeks old, because they get shut down and rebuilt constantly under new names.
Put the domain into a WHOIS lookup - who.is works fine, and for .uk domains Nominet's own lookup is authoritative. You're looking for the registration date.
A household-name-stocking bargain emporium on a domain registered six weeks ago is not a plucky new startup. An established retailer will typically have a domain that's years old. This isn't conclusive on its own - genuine new businesses exist, and we register domains for them most months - but a brand-new domain plus deep discounts plus no checkable company behind it is three strikes, not one.
2. Is there a real company behind it?
Scroll to the footer. A legitimate UK retailer will normally give you a registered company name, a company number and an address, because they're required to. Take the company number and look it up on Companies House, which is free.
What you want to see is a company that existed before the website did, whose name matches, and whose filings look like a trading business. What you often find instead is: no number at all, a number that belongs to a completely different company, a company incorporated a month ago, or a name that doesn't match anything.
Then check the address. Paste it into Google Maps and look at the Street View. A distribution unit is fine. A residential flat above a chip shop, for a company claiming to be a national appliance retailer, is not. And an address that turns out to belong to the genuine business they're impersonating is the clearest answer you'll get.
3. Do the reviews exist anywhere the seller doesn't control?
Reviews on the site itself are worth precisely nothing - they're just text in a database the seller owns. So go and look elsewhere.
Search the shop's name plus the word "review", plus "scam", plus "not arrived". Look for results on Trustpilot, Google, Reddit, and consumer forums. Then read them properly, because the pattern matters more than the score:
- All the reviews landed in the same short window - forty glowing reviews in one week and nothing before or since is a purchase, not a reputation.
- They're all generic. "Great product, fast delivery, would recommend." Real reviews mention the specific thing: the colour was darker than the photo, the courier left it with next door, the filter's a pain to clean.
- There's a split. Five-star reviews full of praise, one-star reviews all saying the same thing - never arrived, no reply, no phone number. When you see that shape, the one-stars are the real customers.
Be equally suspicious of the glowing review site. If you find a page rating the product a "best buy" with a suspiciously precise score, check that site with the same eyes: does it have a named author with a history? Does it explain how it tested anything? Does every single product it recommends link to the same shop? Is its own domain three months old? An affiliate funnel wearing a lab coat is still an affiliate funnel.
4. Is the price plausible?
The uncomfortable truth about most of these is that the bait is greed - and it works on sensible people because it's dressed up as a bargain rather than a windfall.
A well-known item at a fraction of its normal price, in stock, from a retailer you've never heard of, is the oldest signal there is. Nobody sells recognised brands at seventy per cent below everyone else and survives. If a price looks too good, check what the same item costs at three retailers you have heard of. If the answer is "everywhere else it's £400 and here it's £119", you have your answer, and no amount of good reviews should override it.
5. Are the words and pictures actually theirs?
Two quick tricks that catch a lot of these.
Take a distinctive sentence from the About page - not a product description, an "our story" type sentence - put it in quote marks, and search for it. If the identical sentence appears on eleven other shops with different names, you've found the template farm they all came from.
Then right-click a product photo and do a reverse image search (Google Lens will do it from your phone). If the photos come straight from the manufacturer's press pack or, better yet, from a completely unrelated retailer's listing, nobody at this shop has ever had the item in their hands.
6. Can you actually reach a human?
Before you buy, try. Ring the number. Send the contact form a simple question - "is this in stock and what's the delivery time?" A real small retailer will answer, possibly grumpily, usually within a day.
The tells here: a phone number that rings out permanently or isn't there at all; a contact page with a form and nothing else; a "live chat" that's a bot with no escalation; an email address on a free webmail account rather than the shop's own domain. A business that wants your money but has arranged to be uncontactable has told you something important.
7. How do they want to be paid?
Pay attention to the checkout, because this is where the mask often slips. Warning signs: bank transfer being pushed as the only or "cheaper" option; a request to pay by "friends and family" on PayPal, which removes your buyer protection; gift cards or cryptocurrency, which are never a legitimate way to buy a vacuum cleaner; or a checkout that bounces you to an unrelated domain you've never heard of.
Use a credit card. For anything over £100, Section 75 of the Consumer Credit Act 1974 makes your card provider jointly liable with the seller. That is the single most effective piece of consumer protection you have, it costs nothing to use, and it's the reason most of these stories end with the money coming back.
A worked example
Here's a composite of the shape these usually take, stitched together from the ones we've been asked to look at.
You see an advert on social media for a cordless vacuum at about a third of the usual price. The site looks clean and modern. It has a padlock. Product page has 300-odd reviews averaging 4.8. You're a careful sort, so you search for a second opinion - and you find a reviews site that's tested it and rated it a best buy with a 98% score. That's enough. You pay by credit card. You get an order confirmation.
Then nothing. No dispatch email. Emails go unanswered. A month later there's no vacuum and no seller.
Now run the checks backwards. The shop's domain was registered eleven weeks ago. There's no company number in the footer, just an address that belongs to a warehouse in a different county. The 300 reviews were all posted within nine days. Off-site, Trustpilot has fourteen one-star reviews all saying "never arrived". The "best buy" review site was registered two weeks after the shop, has no named author, and every product it recommends links to the same place. The product photos are the manufacturer's press images. And the price was never real - it was the hook.
Not one of those checks takes more than a minute. Any one of them, done before paying, ends the story differently.
Scam emails and texts
Same principle: stop judging the design, start checking the things that can't be faked as easily.
Check the real sending address, not the display name
The name you see in your inbox - "DPD", "HMRC", "Royal Mail" - is just a label the sender chose. It means nothing. Tap it, or hover over it, to expand the actual address.
What you're looking for is the bit immediately before the first single slash. Some real examples of the trick:
service@royalmail.delivery-notice.co- the real domain here isdelivery-notice.co. "royalmail" is just a word someone typed.no-reply@dpd-parcel-uk.com- hyphens are how you smuggle a brand name into a domain you own.support@arnazon.co.uk- "rn" reads as "m" at a glance, especially on a phone at seven in the morning.hmrc.refunds@gmail.com- government departments do not email from webmail.
Check where links actually go
On a computer, hover over the link without clicking and read the URL your browser shows at the bottom of the window. On a phone, press and hold the link without releasing - a preview appears, and you can then cancel.
Apply the same rule: read from the right. In https://secure.hsbc.co.uk.account-verify.net/login, the actual site is account-verify.net. Everything to the left of it is decoration.
Check what's being asked of you
Strip the branding away and look at the request on its own. A short list of things legitimate organisations do not do:
- Email or text asking you to confirm card details, passwords, PINs or full security answers.
- Ask for a small "redelivery fee" of £1.99 or similar. This one isn't really about the £1.99 - it's about getting your card details and confirming the card works.
- Tell you that you're due a tax refund and to claim it via a link. HMRC doesn't do this.
- Ring you, as your bank, and ask you to move your money to a "safe account". No such thing exists.
- Send an invoice or a delivery note as an attachment you weren't expecting.
And watch for the two emotional levers, which are in almost every one of these: urgency ("your account will be closed within 24 hours", "your parcel will be returned today") and a single easy action (one button, one link). The pressure exists to stop you doing exactly the checks on this page.
The one habit that beats all of it
Never use the link. If a message says there's a problem with your bank account, your parcel or your tax, close it and go to the organisation yourself - type the address in, or use the app you already have installed, or ring the number on the back of your card. If the message was genuine, the same information will be waiting for you there. If it isn't there, it wasn't real.
That single habit defeats phishing almost entirely, and it requires you to remember nothing else.
What to do if it's already happened
Quickly, and in this order:
- Ring your card provider. Credit card, over £100 - claim under Section 75, where the provider is jointly liable with the seller. Debit card, or under £100 - ask for a chargeback, which normally needs to be raised within 120 days of when you expected delivery. If you entered card details anywhere you now doubt, ask them to block the card.
- Change any password you reused. If you typed a password into a fake login page, change it everywhere you've used that password, starting with your email account, because that's the key to everything else.
- Report it. Action Fraud (0300 123 2040) for England, Wales and Northern Ireland; Police Scotland on 101 in Scotland. Forward scam emails to
report@phishing.gov.ukand scam texts to7726, free. It genuinely contributes to sites being taken down. - Keep everything. Order confirmation, the emails, screenshots of the site with the URL visible, the advert if you can still find it. Your card provider will ask, and the evidence makes the claim straightforward.
- Tell people. These adverts are targeted locally and by interest. Saying so publicly is often what stops the next five people.
One thing worth saying plainly: being taken in by one of these is not a sign you were careless. They're designed by people who do this full time, tested on thousands of targets, and specifically built to survive the checks a sensible person makes. The person who searched for an independent review before buying did more due diligence than most - the scam just anticipated it.
The other side of this: being the business that looks real
If you run a small business, there's a flip side to all of the above, and it matters more than most owners realise.
Every one of the checks in this article is a check your genuine customers are learning to make. Which means the trust signals aren't decoration - they're now part of whether people buy from you:
- A real address, phone number and company details in the footer, on every page. Businesses leave these off for privacy reasons and then wonder why conversion is poor.
- Reviews somewhere you don't control - Google and Trustpilot especially. Ten real Google reviews beat two hundred testimonials on your own site.
- Photographs of actual work and actual people, not stock images. Stock photography now reads as suspicious in a way it didn't five years ago.
- Clear returns, delivery and contact information written like a human wrote it.
- A domain you own outright, that matches your business name, with your email on it. A quote sent from a free webmail address costs you work you'll never hear about.
There's a security side too. If your domain doesn't have SPF, DKIM and DMARC set up, it's considerably easier for someone to send emails that appear to come from your address - to your customers, with your name on them. That's a half-day job for whoever looks after your domain, and it's worth asking them about. If you're not sure who that is or what to ask, our piece on questions to ask before hiring a web developer covers the ownership and access questions that tend to matter here.
And if you ever find a site impersonating your business: screenshot everything with the URL visible, report the domain to its registrar and host through their abuse contacts, report it to the NCSC, and put a short plain-English notice on your own site and social pages. Tell customers what you will never ask them for. That last bit does more good than anything else.
The five-minute version
If you remember nothing else from this, remember these:
- Check the domain's age. A WHOIS lookup takes thirty seconds.
- Check the company on Companies House. Free, and it's where most fakes fall over.
- Look for reviews off-site. On-site reviews are just text the seller typed.
- Sense-check the price. Too good is the bait, not the bargain.
- Read links and email addresses from the right. The real domain is the bit before the first single slash.
- Never use the link in the message. Go to the site or app yourself.
- Pay by credit card. Over £100, Section 75 has your back.
The padlock isn't the check. The design isn't the check. The reviews aren't the check. The check is whether anything about this business can be verified somewhere its owner doesn't control - and that's still surprisingly hard to fake.
If you run a local business and you'd like an honest look at whether your own site is doing the trust job properly - or you think someone's impersonating you and you're not sure where to start - get in touch. We're happy to give you a straight read, whether or not there's a job in it.