A polished design and padlock are not proof that a website is genuine. Check the address, the context and the organisation independently before you trust it.
Use the steps below to slow the situation down, verify the claim through a separate route and protect yourself without giving the suspicious contact more information.
Start with how you reached the site
A site reached from an unexpected text, email, advert or QR code deserves more caution than one you navigated to independently. Criminals can copy logos, colours and layouts, so appearance alone is weak evidence.
Read the real web address carefully
Look at the domain name, not just the page heading. Watch for misspellings, extra words, misleading subdomains and unfamiliar endings. HTTPS protects the connection to a website; it does not prove the operator is trustworthy.
Verify the organisation independently
If the site claims to belong to a bank, retailer, courier or government service, leave the page and find the organisation through its official app, a saved bookmark or a fresh search. The NCSC advises contacting organisations directly rather than using contact details supplied in a suspicious message.
Treat pressure and payment requests as warning signs
Be especially cautious when a page creates an urgent deadline, asks for a small unexpected fee, requests a one-time code, demands unusual payment methods or pushes you to act before checking elsewhere.
If you already entered information
If you entered a password, change it and any reused copies. If you entered bank or card details, contact your bank using a trusted route. Suspicious websites can be reported to the NCSC.
Practical checklist
Quick checklist
- Check how you reached the website
- Read the full domain name carefully
- Do not treat a padlock as proof of legitimacy
- Verify the organisation through a separate trusted route
- Do not enter details while you are uncertain
- Report suspicious sites to the NCSC
Official UK guidance
Scam techniques and reporting routes change. These official sources were checked when this guide was updated: