The padlock in your browser proves the connection is encrypted. It proves nothing whatsoever about who is on the other end. Phishing sites get free certificates in minutes, which means the single check most Indians rely on is the one that offers the least protection.
Here is what to look at instead, including two checks that exist only in India and that almost nobody uses.
What HTTPS Actually Tells You
HTTPS means data travelling between your browser and that server cannot be read in transit. That is genuinely useful, and it is all it means.
Domain-validated certificates — the ordinary kind — are issued automatically and free to anyone who controls a domain name. A fraudster who registers flipkart-bigsale-offer.in this morning will have a valid padlock by lunchtime. The padlock certifies the tunnel, not the person at the far end of it.
So treat the absence of HTTPS as an absolute stop, and its presence as meaning nothing at all.
The Two India-Specific Checks Worth Learning
1. Search the suspect repository before you pay
The National Cyber Crime Reporting Portal runs a Suspect Search facility at cybercrime.gov.in/suspect-search. You can check a mobile number, a UPI ID, a bank account number, an email address or a URL against identifiers that other victims have already reported.
This is the highest-value thirty seconds in this article. If you are about to transfer money to a seller on Instagram, OLX or WhatsApp, run their UPI ID and number through it first. A hit means walk away. No hit does not prove safety — it may simply mean you would have been the first — but a hit is conclusive.
2. Learn the new banking domains
The RBI has introduced exclusive domains for regulated financial institutions: .bank.in for banks and .fin.in for other regulated financial entities, with IDRBT as the sole registrar. Because registration is restricted and verified, a site on one of these cannot be a random impersonator.
Migration is still under way, so many legitimate banks continue to use their older domains and the absence of a .bank.in address does not indicate fraud. Read it the other way round: a .bank.in address is a strong positive signal, and any site claiming to be a bank while using a free or unusual domain deserves suspicion.
Read the Domain, Character by Character
Most Indian scam sites are caught here, by people who slow down for five seconds.
- Check the spelling exactly. arnazon, flipkort, paytrn. Character substitutions are designed for a glance, not a read.
- Look at what comes immediately before the first single slash. That is the real domain. In sbi.secure-login.xyz.com, the site is xyz.com, not SBI.
- Be wary of hyphen stacking. Real brands rarely use brand-offer-sale-india.com.
- Note the extension. Established Indian retailers use .in or .com. A well-known brand on an unusual TLD is a red flag.
Signals on the Page Itself
Look for a CIN or GSTIN and a real registered address. Every legitimate Indian company has both, and they belong in the footer or on the About page. A contact page offering only a WhatsApp number is not a business address.
Read the returns and refund policy. Not for the content — for whether it exists, is specific, and matches the products being sold. Fraud sites paste generic text or skip it.
Check the prices against reality. An iPhone at 70% off is not a deal, it is the entire business model of the site.
Watch for countdown timers and stock-scarcity banners. Legitimate retailers use urgency too, but on a site you have never heard of, manufactured panic is doing a specific job: preventing you from doing the checks in this article.
Never download anything from a payment page. A shopping site asking you to install an app file to complete a purchase is delivering malware. This matters especially on Android, where an installer file can be side-loaded — the risks are set out in our guide to installing APK files safely.
How You Pay Changes How Much You Can Lose
Payment method is a control, not an afterthought.
Credit cards give the strongest dispute rights of the common options. UPI is instant and effectively final, which is exactly why fraudsters prefer it. A direct bank transfer to an account number is the weakest position of all.
Two hard rules. Never pay by transferring to a personal UPI ID or individual account when you believe you are buying from a company. And never share an OTP, or approve a “collect request” — a genuine payment you initiate never requires you to approve a request someone else has sent you. That single confusion drives an enormous share of Indian payment fraud, as covered in our guide to UPI fraud and recovery.
Where the Link Came From Matters More Than the Link
Most payment fraud does not start with a search. It starts with a link — in a WhatsApp forward, an SMS about a pending delivery, an Instagram ad, an email about a KYC update.
The habit that defeats nearly all of it: never transact on a link someone sent you. If the message claims to be from your bank, your electricity provider or a courier, close it and reach the organisation the way you normally would — the app you already have, or a number you look up independently.
You can also report the message itself through the Chakshu module on Sanchar Saathi, which exists for exactly this: reporting a fraud attempt before anyone loses money. Our Sanchar Saathi guide covers where that sits among the other modules.
A Thirty-Second Routine
Before any payment to a site you have not used before: read the domain character by character, confirm HTTPS is present but ignore it as evidence, look for a CIN or GSTIN and a real address, run the UPI ID or account number through NCRP Suspect Search, and search the brand name plus the word “fraud” independently rather than trusting testimonials on the site itself.
If anything on that list fails, the deal was not real. We publish practical, India-specific digital safety guidance at Techleez com.
Frequently Asked Questions
Does the padlock icon mean a website is safe?
No. It means the connection is encrypted. Free certificates are issued to fraudulent sites routinely, so the padlock says nothing about who runs the site.
How can I check if a UPI ID is a known scam?
Use the Suspect Search facility on cybercrime.gov.in to check a UPI ID, mobile number, account number or URL against identifiers reported by other victims.
What are .bank.in and .fin.in domains?
Exclusive RBI-backed domains for regulated financial institutions, registered only through IDRBT. A site using one has been verified; migration is ongoing, so older bank domains are still legitimate.
Which payment method is safest online?
A credit card generally offers the strongest dispute rights. UPI and direct bank transfers are effectively final once sent.
A shopping site asked me to install an app to complete payment. Is that normal?
No. It is malware. No legitimate retailer requires an app installation to finish a browser purchase.
What should I do if I have already paid a fraudulent site?
Call 1930 immediately and file a complaint on cybercrime.gov.in. The first hour is when funds can still be frozen in the receiving account.
