Why the Padlock Is Only the Beginning

Most people have been told to look for the padlock icon and the https prefix before entering any personal information online. That advice is not wrong — but it is dangerously incomplete. HTTPS means your data travels in an encrypted tunnel, but it does not mean the destination is safe. Anyone can get a free HTTPS certificate in minutes, including people running phishing sites.

The real skill is reading the fuller picture a browser and a few quick checks can give you. Once you know what to look for, vetting an unfamiliar site takes less than two minutes — and it is one of the most practical habits you can build. See our guide to safer digital habits for a broader foundation to build on.

The Padlock Is Not a Trust Badge

A padlock icon only means the connection between your browser and the server is encrypted — it says nothing about whether the site owner is trustworthy. Fraudulent sites routinely obtain HTTPS certificates because they are free and automatic. Do not treat the padlock as proof that a site is legitimate.

Step-by-Step: Vetting a Site Before You Enter Information

Follow these steps whenever you land on an unfamiliar site that is asking for personal data, payment details, or account credentials. You do not need any special software — just your browser and the free tools listed below.

What you will need

A web browser on any device (desktop, tablet, or smartphone)
Basic familiarity with typing a web address into a browser
Required

Browser address bar

Reveals the full URL, HTTPS status, and domain name — your first line of inspection.

Optional

ICANN WHOIS Lookup (lookup.icann.org)

Shows when a domain was registered, helping flag newly created or anonymised sites.

Optional

Google Safe Browsing Transparency Report

Lets you paste a URL and check whether Google has flagged it for phishing or malware.

1

Read the full URL in the address bar

Click or tap the address bar so the full URL is visible — browsers sometimes hide part of it by default. Look at the domain name: the real domain is the segment immediately before the first single slash (e.g., example.com/checkout — the domain is example.com). Watch for subtle misspellings like paypa1.com or extra words like amazon-secure-login.com. The legitimate organisation's name should be the domain itself, not a subdomain or added word.

Tip: On a smartphone, tap the address bar and look for the full address — mobile browsers often show only the domain by default, which can hide deceptive subdomains.
2

Confirm HTTPS — but do not stop there

Check that the URL begins with https://. This confirms your connection is encrypted in transit. However, as noted, HTTPS alone is not proof of legitimacy. Treat it as a minimum requirement, not a green light.

Warning: A site without HTTPS should be avoided for any information entry, but a site with HTTPS still requires all remaining checks.
3

Search for the site independently

Open a new tab and search for the organisation by name. Compare the domain in those search results against the domain you are on. If they do not match exactly, you may be on an impersonator site. Also check whether the organisation has a verified social media presence and whether it links to the same domain.

Tip: If you arrived at the site via a link in an email or text message, this step is especially important — phishing links often point to convincing copies of real sites.
4

Check the domain's registration age

Go to lookup.icann.org, paste the domain name, and look at the creation date. Fraudulent sites are often registered days or weeks before they are used. A domain that is less than a few months old and is asking for payment or personal data warrants significant caution. Established businesses typically have domains registered years ago.

5

Run the URL through Google Safe Browsing

Visit transparencyreport.google.com/safe-browsing/search, paste the full URL, and check the result. If Google has detected phishing or malware on that site, it will say so. This check takes under 30 seconds and can confirm suspicions raised by earlier steps.

Tip: This tool reflects Google's database, which is extensive but not exhaustive. A clean result reduces risk but is not a guarantee — use it alongside the other steps, not instead of them.
6

Inspect the site's contact and policy pages

Navigate to the site's "Contact Us" and "Privacy Policy" pages. A legitimate business will have a physical address, a working email that matches its domain, and a substantive privacy policy that names the company. If these pages are missing, vague, or list contact emails at free providers like Gmail, treat that as a strong warning sign.

Warning: Do not enter any information until you have completed this review. Once you submit data, you cannot unsend it.

Reading the Signals Beyond the URL

Even after a URL passes the basic checks, the page itself tells you a great deal. Legitimate organisations invest in their web presence; signs of neglect or inconsistency are meaningful.

  • Grammar and design quality: Odd phrasing, inconsistent fonts, or broken images do not definitively mean a site is fraudulent, but they warrant extra caution — particularly on financial or health-related sites.
  • Payment methods accepted: Pressure to pay by wire transfer, cryptocurrency, or gift cards is a near-universal indicator of fraud. Legitimate businesses accept standard card payments through recognised processors.
  • Urgency language: Phrases like "your account will be suspended" or "act in the next 10 minutes" are designed to override your judgment. Pause and verify independently before doing anything.

Never Enter Payment Details Under Pressure

Legitimate retailers and services do not impose countdown timers that claim your cart or price will expire in seconds. Artificial urgency is a manipulation tactic used to stop you from pausing to verify. If a site is pressuring you to act immediately, leave and research the organisation independently before returning.

If something about the site still feels off after these checks, trust that instinct. The assumptions that leave people vulnerable online often involve overriding a quiet sense of doubt. You can always exit, find contact details through an independent search, and reach the organisation another way.

When in Doubt, Navigate Directly

If you received a link by email or text, avoid clicking it at all. Instead, open a fresh browser tab and type the organisation's known address yourself. This sidesteps the most common phishing technique entirely. Bookmark sites you use frequently so you never rely on incoming links.

For readers who want to extend this vigilance to travel situations — where public Wi-Fi and unfamiliar networks add another layer of risk — our article on protecting your devices and data while traveling is worth reading before your next trip. And if you are helping an older family member apply these habits, online safety for older adults offers accessible, targeted guidance. Building on these checks with broader practices is also covered in online privacy habits worth building before you need them.