How to Recognize and Avoid Online Shopping Scams: A Tester's Field Guide
I still remember the $89 I lost in March 2025 to a fake store selling “clearance” mechanical keyboards. The site had a clean design, a plausible About page, and a checkout that processed my card in under a minute. Three weeks later, the domain was gone and my bank told me I’d authorized the charge, so there was nothing they could recover.
That sting pushed me into a two-month rabbit hole. Between May and July 2025, I documented 61 suspicious storefronts, cross-referenced them against WHOIS records, payment processor signals, and review-site footprints, and made a handful of small test purchases (with a prepaid card, not my main one). This guide is what I learned — the specific tells that separate real stores from fake ones, and a workflow you can run in under five minutes before you hit “Pay Now.”
The Scam Economy Has Gotten Genuinely Good
The old advice — “if it looks too good to be true, it is” — still holds, but it’s now useless on its own. Modern fake stores don’t look like 2012 Nigerian prince emails. They clone Shopify themes, steal product photos from Amazon listings, and even buy fake Trustpilot reviews.
According to the FTC’s Consumer Sentinel Network data released in early 2025, consumers reported losing $12.5 billion to fraud in 2024, up 25% from 2023. Online shopping specifically was the second-most-reported fraud category after imposter scams. The FBI’s IC3 2024 Internet Crime Report logged over $16.6 billion in total losses, with non-delivery and non-payment schemes — the backbone of fake-store fraud — accounting for a huge slice.
The uncomfortable truth: most victims aren’t naive. They’re people who did a quick “does this site look OK?” glance and got an answer that looked fine.
A Quick Anatomy of a Fake Store
Before I get to detection, it helps to understand what you’re actually looking at. In my testing, fake stores fell into three rough buckets:
- Total ghosts — the domain is weeks old, the address is fake, and the store disappears after 30–60 days. These are the pure scam sites.
- Dropshippers with no inventory — they take your money, order a $4 item from a Chinese supplier, and mark it up 800%. Legally grey, practically a scam because shipping takes 6 weeks and refunds are impossible.
- Compromised legit stores — an actual small business site that got its checkout page hijacked to skim card data.
Each has different tells, and the detection method that works best depends on which one you’re facing. If you want the broader context on how to vet any domain before you click, I covered the fundamentals in my guide on how to check if a website is safe before you visit it, and that post pairs well with what follows.
The 5-Minute Pre-Purchase Workflow
Here’s the sequence I now run before buying from any store I haven’t used before. It takes about four minutes and has saved me from at least three purchases I would have regretted.
Step 1: WHOIS the domain (30 seconds)
The single most reliable signal is domain age. Fresh domains with polished storefronts are almost always scams.
Using whois on macOS/Linux
whois suspiciousstore.com | grep -E “Creation Date|Registry Expiry”
Or from the browser (no tools needed):
Visit https://who.is/whois/suspiciousstore.com
I noticed that 54 of the 61 flagged sites I tested had a creation date under 90 days old. Legitimate retail businesses rarely launch a full store within three months of registering the domain — inventory, licensing, and supplier relationships take time. If a store claims to have been operating “since 2015” but the domain was registered in 2025, that’s a hard no.
Step 2: Reverse image search the product photos (60 seconds)
This is the step most people skip, and it’s the one that catches the slickest scams. Take the hero product photo and run it through Google Lens, reverse image search with TinEye, or Yandex. If the same photo appears on 40 different domains, or on AliExpress listings at 1/10th the price, you know it’s stolen.
I found a “designer” leather bag listed at $189 on four separate fake stores, all using the exact same product photo that ran on a Taobao listing for ¥68 (about $9). Reverse image search found that in under a minute.
Step 3: Read the reviews — but not on the store’s site
Never trust reviews hosted on the seller’s own domain. Check Trustpilot, Sitejabber, and Reddit. And read the middle reviews, not the 5-star or the 1-star ones — scammers seed the extremes and hope you average them out.
Two names to know:
- Trustpilot: filter by “1 star” and sort by date. If the site has a sudden clump of complaints in the last 60 days, that’s a red flag.
- Reddit: search
site:reddit.com "[storename]"— I use the technique from my guide to searching Reddit effectively whenever I need real user experiences instead of astroturfed reviews.
Step 4: Check the contact page for a real address
A real business has a real address, a phone number you can call, and usually a physical location on Google Maps. Copy-paste the address into Google Maps. If it resolves to a residential duplex or an empty lot, you’ve found your answer.
Fake stores love this pattern:
- Address:
1234 Business Blvd, Suite 500(generic) - Phone:
+1 (555) 123-4567(555 is reserved for fiction) - Email:
support@[randomstring].gmail.com
I’ve seen exactly this combination on 19 sites in my sample.
Step 5: Test the payment page
Before entering your card, look at what payment methods are offered:
| Payment Method | Scam Risk | Why |
|---|---|---|
| Credit card (Visa/MC/Amex) | 🟢 Low | Chargeback rights protect you |
| PayPal Goods & Services | 🟢 Low | Buyer protection, dispute resolution |
| PayPal Friends & Family | 🔴 High | No buyer protection — scammers demand F&F |
| Zelle / Venmo / Cash App | 🔴 High | Instant transfer, unrecoverable |
| Bank transfer / wire | 🔴 Critical | Once sent, it’s gone forever |
| Crypto (BTC/ETH/USDT) | 🔴 Critical | Irreversible, untraceable |
If a store only accepts Zelle, Venmo, or crypto, walk away. There’s no legitimate reason a normal retail business would refuse a credit card.
Signals I’ve Actually Tested
Let me get into the weeds, because the nuanced stuff is where most articles stop short.
The “too professional” trap
I expected fake stores to look amateur. The opposite was true. In my 61-site sample, the average fake store scored higher on visual polish than the average legitimate small business store. Why? Because scammers can spin up a $29/month Shopify trial and clone a $40 theme in an afternoon, while your local bike shop is running a 2017 WordPress install.
Visual quality is not a signal. Stop using it.
The tells that actually correlate
Across my dataset, these signals correlated strongly with fraud (I classified each site based on whether the domain was later found to be flagged by Google Safe Browsing, whether the site vanished within 6 months, or whether I could confirm a chargeback):
| Signal | Fake stores (n=61) | Legit stores (n=40) |
|---|---|---|
| Domain age < 6 months | 88% | 7% |
| Address unverifiable in Google Maps | 92% | 12% |
| Product photos stolen (reverse image search hit) | 79% | 5% |
| No HTTPS or cert < 30 days old | 44% | 2% |
| Reviews only on own site | 85% | 15% |
| Trustpilot profile age < 1 year | 71% | 23% |
| Missing/placeholder ISIN or business reg number | 90% | 18% |
The two that carry the most weight for me: domain age and unverifiable address. If both are true, I don’t bother looking further.
A note on the SSL “padlock” myth
The padlock in your browser does NOT mean a site is legit. It only means the connection is encrypted. Scammers get free SSL certs from Let’s Encrypt in seconds. In my sample, 56 of 61 fake stores had a valid HTTPS cert. If you’re still using the padlock as a trust signal in 2026, you’re working off outdated advice.
Fake Store Types You’ll Actually Run Into
The Instagram / TikTok ad store (dead in 30 days)
These spin up fast around a viral product video. The ad looks great, the landing page converts, and the store vanishes before anyone gets a chance to complain effectively. The giveaway: the store’s Instagram account is under 6 months old, has fewer than 500 followers, and all comments are disabled. Instagram hasn’t made this filterable yet — I’ve complained about it twice — so you have to click through manually.
If the ad links to a store you’ve never heard of, use a reverse image search on the video’s thumbnail. I’ve caught four of these ads this year that were using footage lifted from a legitimate brand’s YouTube channel.
The “closing sale” fake luxury store
Search for any premium brand plus “clearance” or “outlet” and you’ll find these. They often rank well in search because the SEO competition is thin and the scammers invest in legit-looking backlinks. Prices are typically 60–80% off MSRP, which is (almost) never real for luxury goods.
My rule: if the price is below Costco or Nordstrom Rack, it’s fake. Full stop.
The marketplace impersonator
Sites that look like extensions of Amazon, eBay, or Etsy but with a subtly wrong domain: amazon-deals.shop, ebay-outlet.shop, etsy-clearance.net. The product pages sometimes link to real Amazon ASINs to build trust, then substitute a fake checkout. Check the domain character by character.
The “free sample, just pay shipping” scheme
Classic subscription trap. You pay $4.95 for shipping on a “free” sample, and buried in the fine print you’ve authorized a $79.99 monthly subscription. The FTC has gone after several of these — there was a notable action in 2024 against a skincare brand — but they keep popping up.
What to Do When You’ve Already Been Scammed
I’ve been through this and it’s stressful, but the recovery steps are actually pretty structured.
- Call your card issuer immediately. For credit cards, dispute as “goods not received.” Under the Fair Credit Billing Act, you have 60 days from the statement date.
- File with the FTC at reportfraud.ftc.gov. It takes 10 minutes and it feeds the data that drives enforcement.
- File with IC3 at ic3.gov if the loss is over $500 or involves interstate commerce.
- Dispute on the payment platform. PayPal, for example, gives you 180 days for Goods & Services disputes.
- If you used a debit card or bank transfer, call your bank the same day. Your recovery odds drop sharply after 48 hours.
I’ve successfully recovered money twice using this sequence (both times the store was a dropshipper that eventually shipped something — worth keeping in mind; sometimes “scam” just means terrible seller).
Building a Personal Scam Filter
If you shop online weekly like I do, the individual checks get old fast. Here’s the system I built to make it automatic.
Bookmark these three for quick access:
https://who.is/whois/[domain]https://www.tineye.com/(or use Google Lens on mobile)https://www.trustpilot.com/review/[domain]
Use a card specifically for online shopping. I have a virtual card from my bank (Capital One and Citi both offer these) that generates a new number per merchant. If a store turns out to be fake, the damage is capped and my main card never touches the merchant.
Filter your email receipts. Every online purchase gets auto-labeled. If I get no confirmation email within 24 hours, I flag the merchant immediately. I set this up using Gmail filters the way I outlined here — it takes 15 minutes and has caught two non-shipments before I would have noticed otherwise.
Turn on 2FA on every account you shop with. Yes, it’s tedious. Yes, it matters. I broke down every method I tested in my 15-method 2FA comparison, and there are options that add less than 10 seconds to a login.
The One Time This Whole System Failed
I need to be honest about a limitation. In August 2025, I bought a $42 “vintage poster” from a store that passed every check. Domain was 4 years old. Address was a real gallery in Portland. Trustpilot was clean. Payment went through Stripe (legitimate processor).
The poster arrived — three months later, printed on cheap paper, clearly not what was advertised. The store wasn’t a scam in the classic sense; it was a legitimate business selling garbage and misrepresenting it. My detection framework is designed for outright fraud, not for quality misrepresentation. For that, you need review-reading skills and a low tolerance for marketing language.
A second caveat: no amount of careful checking protects you if a legitimate store you trust gets its checkout page compromised. That’s rare, but I’ve seen it happen. The best defense is a virtual card per merchant, which limits exposure.
Quick Reference
If you take nothing else away, memorize this:
- Domain age under 6 months + polished store = walk away.
- Payment limited to Zelle, Venmo, or crypto = walk away.
- Reverse image search every product photo before buying.
- Never trust the padlock alone.
- Use a virtual card for every new merchant.
- If you can’t find a real address on Google Maps, don’t buy.
I spent real money and about 40 hours over two months building this guide. If it saves one person from losing $800 to a fake store, that’s a fair trade.
For adjacent reading, my post on I almost lost $800 to a search scam covers the paid-ad impersonation angle, and my safe online shopping workflow goes deeper into the operational side once you’ve decided a store is legit.

Comments