That ad with the sneakers you wanted at half price, the site with the «only 3 left» counter, the «-70% ends today.» Sometimes it’s a real deal. And sometimes it’s a fake store set up to take your money or your card details. The good news: almost all of them leave the same fingerprints, and with five minutes of checks you can protect yourself before paying. This guide walks you through the exact method, including the technical check most articles don’t even mention.
How a fraudulent online store works
Understanding the pattern helps you spot it. Almost all fake stores follow the same script:
- Bait price. A high-demand product at an impossible price. The discount isn’t a promotion: it’s the hook.
- Artificial urgency. Countdowns, «last units left,» «offer expires in minutes.» The goal is to stop you from pausing to think or check.
- Copied branding. Logos, photos and text lifted from a real store or a brand’s official site, to feel legitimate.
- Short lifespan. Many last only weeks: set up, capture payments, and disappear before visible complaints pile up.
The defense against this script isn’t intuition — it’s a checklist. Let’s go through it.
8 signs of a fake store
No single sign is a verdict on its own, but the more that stack up, the clearer the picture. Treat them as a risk score.
1. Recently registered domain
This is the king signal, the one that almost never fails. A store that claims «years of trust» but whose domain was registered two weeks ago is a huge red flag. Below, we’ll show you how to check this yourself.
2. No legal details or business information
A legitimate store is required to identify itself: company name, tax ID, address, terms of sale, return policy. If there’s no legal notice, or it’s generic with no concrete details, be suspicious.
3. Only bank transfer or crypto payment
Card gateways and platforms like PayPal offer dispute mechanisms. That’s why fake stores push you toward bank transfer, a peer-to-peer payment app, or cryptocurrency: these are hard to reverse. If the «safe» method isn’t available and you can only pay through unprotected channels, that’s a very strong signal.
4. Impossible prices
If the price is far below every other store’s, including the official brand, assume there’s a catch. Nobody gives away high-demand products.
5. Fake or missing reviews
All five-star reviews written in the same style with no recent dates, or no verifiable review at all outside the site itself. Search for the store on independent sources — don’t rely only on testimonials the site shows about itself.
6. Fake certificate or trust seal
The browser padlock (HTTPS) only means the connection is encrypted, not that the store is honest: anyone can get a free certificate. And the «trust seals» you see in the footer are often just pasted images that don’t link to any real verification. Click the seal: if it doesn’t lead to a page confirming the certification, it’s worthless.
7. Flimsy contact info
Just a form, a Gmail or Hotmail address instead of one on the store’s own domain, a phone that never answers. A serious store provides several real contact channels.
8. Errors and machine-translated text
Odd translations, mixed languages, copied descriptions. Not conclusive proof on its own, but combined with the rest, it reinforces the diagnosis.
How to check a domain’s age yourself
This is the most powerful check, and the one almost nobody explains well. A domain’s registration date is public information and is looked up via RDAP (the system that replaced the old WHOIS). Method:
- Find the store’s actual domain (the main part of the address, without the slashes).
- Look up its creation date. Public RDAP lookups exist that return the date the domain was first registered.
- Compare it with what the store claims about itself. A site that boasts of a long track record but has a domain that’s days or weeks old is lying about its history. It’s one of the most reliable signals there is.
To do this without hassle and with added context — beyond age, also public ownership, infrastructure and domain reputation in a single read — you can check the domain’s age and registration details.
One honest caveat: some fraudulent stores reuse old, second-hand domains precisely to appear established. That’s why age is a very strong signal, but it should be read together with the rest of the checklist, not in isolation.
Technical signs: hosting, IP and certificate
Without being technical, there are clues «behind the scenes» of a website that help:
- Where it’s hosted (hosting/IP). The server’s IP address has a public reputation and an approximate geolocation. A supposed «long-established local store» hosted on low-cost infrastructure associated with abuse, or with a poor-reputation IP, doesn’t fit a legitimate business.
- The certificate. Check who it’s issued to and since when. A certificate issued just a few days ago, coinciding with a domain that’s also new, reinforces suspicion.
You can check the hosting and IP reputation where the store is hosted to complete the picture. This is OSINT applied to safe shopping; if you want to understand the full framework, see what OSINT intelligence is.
How to check payment methods and reputation
- Insist on a protected payment method. Card or platforms with dispute resolution. If you’re pushed away from those channels, cancel the purchase.
- Search the store’s name + «reviews» / «scam» on a search engine. If there are complaints, they usually show up. A total absence of any trace also says something: a real, active store leaves a public footprint.
- Be wary of a generic contact email. A domain that sells things but communicates from a free email account is inconsistent. In fact, many fake stores also send fraudulent «confirmation» emails: learn to verify if an email is trustworthy.
What to do if you’ve already bought from a fake store
If the fraud has already happened, act fast — time works against you:
- Contact your bank immediately. If you paid by card, ask about the dispute or chargeback process. The sooner, the better.
- Gather evidence. Screenshots of the site, the order, the payment and any communication.
- Report it. To your local police and your national consumer protection or cybercrime reporting body — for example, in the US the FTC (ReportFraud.ftc.gov) or the IC3, in the UK Action Fraud, and in Spain the National Police or Civil Guard, INCIBE’s 017 helpline and the Internet Security Office (OSI).
- Watch your card. If you shared your details, consider alerting your bank to possible fraudulent use.
Checking a store’s domain and IP
Before paying at a store you don’t know, spend five minutes checking two things: the domain and the hosting. It’s the difference between shopping with judgment and shopping blind.
- For the domain: check the domain’s age and registration details.
- For the server: check the hosting and IP reputation.
Both checks are based on public data, give you a risk score and a plain-language report with dated evidence via an RFC 3161 timestamp, in case you need to keep proof of what you saw before buying.
Frequently asked questions about fake online stores
No. The padlock only encrypts the connection; a fraudulent store can have HTTPS too. It’s necessary but not sufficient: you also need to check the domain, legal details, payment methods and reputation.
By checking its domain’s public registration date (via RDAP). If the site claims a long track record but the domain was registered weeks ago, that’s a red flag.
Not recommended. Bank transfers and cryptocurrency offer almost no way to dispute a payment. Always use buyer-protected methods, such as a card.
To your local police and national consumer protection or cybercrime body, with your evidence gathered — for example the FTC or IC3 in the US, Action Fraud in the UK, or the National Police / Civil Guard in Spain, along with INCIBE’s 017 helpline and the OSI.
