The padlock icon means your connection is encrypted — nothing more. Scam sites get HTTPS certificates free and automatically, so the real two-minute check is: does the domain exactly match who you think you're paying, did you reach the site by typing the address or via a suspicious ad, and does a card-processor (or PayPal/Apple Pay/Google Pay) handle the payment rather than a wire transfer? The catch: none of these checks catches a skilled fake on a first visit, which is why payment-method protections are your backstop.
What does the padlock actually prove?
HTTPS encrypts traffic between you and the server. Since legitimate certificate authorities issue domain-validation certificates free and automatically, every phishing site today loads with a padlock too. The FTC's own online-shopping guidance tells consumers plainly: the padlock isn't a trust badge. What it still does guarantee — and why you should never enter details on a page without it — is that nobody on your network can read what you send.
What should you actually check, in order?
- The domain, character by character: "amazom.com," "amazon-deals.shop," and "amazon.com.store.example.com" are not Amazon. Read the part just before the first single slash.
- How you got there: typed or bookmarked is safest; a link in a text about a "delivery problem" or a search-engine ad above the real results is the documented phishing pattern — the FTC's complaints are full of ad-driven lookalikes.
- Checkout handling: recognizable processors (Stripe, PayPal, Apple Pay, Google Pay, Shopify) or your card's own 3-D Secure pop-up are good signs; requests for bank transfers, gift cards or crypto are documented fraud signatures — no legitimate retailer asks for gift cards.
- The site's paper trail: a physical address, a refund policy, and reviews that exist outside the site itself.
Which payment method gives you the most protection?
US law and card networks document the hierarchy: credit cards cap your liability at $50 and most issuers waive it entirely; debit cards expose your actual bank balance during dispute windows; and the FTC documents that paying by wire, gift card or crypto means essentially no reversal path. Virtual card numbers — offered by several issuers and wallets — add a merchant-specific number you can shut off, a documented feature worth using on unfamiliar shops.
What about the scam-site red flags?
- Countdown timers and 90-percent-off prices on brand-name gear — pricing that exists to stop you from checking.
- Contact page with only a web form and no address or phone.
- New domain selling familiar brands — registration dates are visible in WHOIS lookups, a documented trick that exposes week-old "established stores."
What if you already paid a shady site?
The FTC's documented sequence: call the card issuer immediately to dispute or freeze, change passwords if you created an account (reused passwords are the second loss), and report at reportfraud.ftc.gov. Fast disputes on credit cards have strong documented outcomes; wire transfers and gift cards mostly don't.
FAQ
For more context, read How to Check if Your Data Was Exposed in a Breach — and What to Do Next.
For more context, read buy refurbished electronics guide.
For more context, read Warranty vs Insurance for Phones: What's Actually Covered.

