How to Tell a Real Payment Page From a Fake One (Not by the Padlock)
Most guides to spotting a trustworthy payment page still lead with the padlock. That test no longer works — a phishing page has the same padlock your bank does. These are the checks that survive contact with a modern fake.
Start here
- The padlock proves the connection is encrypted. It proves nothing about who is on the other end.
- FBI/IC3: “Do not trust a website just because it has a lock icon or ‘https’ in the browser address bar.”
- The strongest protection is not a visual check at all — it is the payment method you choose.
- An earlier version of this page recommended looking for the padlock and opening the certificate. We have replaced that advice.
Why the visual checks got weaker
Every check that relies on how a page looks has degraded, because copying appearance is free. Logos, layout, fonts, the padlock, even a plausible-looking certificate — all of it is available to whoever registers a lookalike domain this morning.
CISA makes the related point about the text itself: the old advice to watch for clumsy grammar has expired, because “in the era of artificial intelligence (AI) some emails will now have perfect grammar and spelling”. The same applies to the pages those emails link to.
What has not degraded is the domain name, the route you took to get there, and the payment instrument you use.
The checks that still work
- Verify the domain, not the design. Read the last two labels before the first slash.
paypal.com.account-verify.netisaccount-verify.net. - Navigate there yourself. Type the address or use your own bookmark rather than following a link from an email or message. This is the single most effective habit on this list.
- Prefer a credit card or a payment intermediary. This is the one that actually limits your loss, because it changes who is holding the risk while a dispute is resolved.
- Refuse unusual payment methods outright. The FTC is blunt about this: legitimate businesses do not ask to be paid in gift cards, wire transfers or cryptocurrency. A request for any of these is not a yellow flag, it is the end of the transaction.
- Stop at any certificate warning. Not a prompt to think it over.
What the payment method changes
This is the part most security checklists underplay. The visual checks are probabilistic — you might spot the fake, you might not. The payment method is structural: it decides what happens after you get it wrong.
A credit card charge can be disputed. A wire transfer, a gift card code, and a crypto payment are all effectively final. That is precisely why fraud operators steer people toward them, and why the FTC treats the request itself as the tell.
On buying over public Wi-Fi
The old rule was never shop on public Wi-Fi. That advice was written for an era when much of the web was unencrypted and someone on the same café network could read your traffic.
With HTTPS now near-universal, the eavesdropping risk it was built around is largely handled by the encryption — the same encryption the padlock represents. The realistic public-network risks today are shoulder surfing, a device you left unlocked, and being talked into a fake page, which is a different problem from the network you are on.
Keep your device patched and locked, and apply the domain and payment checks above. Those matter far more than which network you are on.
If a payment has already gone through
Contact your card issuer or bank straight away and ask about a chargeback — speed genuinely affects the outcome. Then report it to the FTC at ReportFraud.ftc.gov.
If you handed over card, bank or Social Security numbers rather than just making a payment, start at IdentityTheft.gov, which walks you through recovery step by step.
Sources: FBI/IC3 PSA I-061019-PSA · FTC: how to recognize and avoid phishing scams · CISA: teach employees to avoid phishing · FTC: ReportFraud.ftc.gov
Reviewed 27 August 2026 by the CyberArtical editorial team against primary guidance from the FBI’s Internet Crime Complaint Center, the FTC and CISA. Security guidance changes; where our earlier version of this page said something different, we say so above rather than editing it out quietly.