Skip to content

How to Identify Secure Websites

Fake websites are designed to look exactly like real ones. Here’s how to tell the difference before entering any personal information.

Before entering any sensitive information (passwords, card numbers, personal details), verify:

The URL (web address) is your first defense.

Legitimate Examples:

  • https://www.sbi.co.in - State Bank of India
  • https://www.hdfcbank.com - HDFC Bank
  • https://www.irctc.co.in - IRCTC

Fake Examples:

  • https://www.sbi-secure-login.com - FAKE
  • https://www.hdfc-bank-update.in - FAKE
  • https://www.irctc-booking.xyz - FAKE

Red Flags in URLs:

  • Extra words like “secure”, “login”, “update”, “verify”
  • Hyphens where there shouldn’t be (sbi-bank instead of sbi)
  • Wrong domain extension (.xyz, .tk, .ml instead of .co.in, .com)
  • Misspellings (flipkrat.com instead of flipkart.com)
  • HTTPS = Secure connection (look for the s)
  • Padlock icon = Certificate verified
  • Red warning = Do NOT proceed

Important: HTTPS alone doesn’t mean a site is legitimate - scammers can get certificates too. Always verify the URL as well.

Click the padlock to see certificate details:

  1. Click the padlock icon in the address bar
  2. Click “Certificate” or “Connection is secure”
  3. Verify the “Issued to” field matches the company

For banking sites, look for “Extended Validation” (EV) certificates which show the company name in green.

While not foolproof, legitimate sites usually:

  • Have no spelling/grammar errors
  • Load quickly and smoothly
  • Have working links
  • Display proper contact information
  • Show physical address and customer care numbers

When in doubt:

  1. Open a new tab
  2. Search for the company name + “official website”
  3. Look for verified results or Wikipedia links
  4. Navigate from there - don’t click links from messages

Fake sites claiming to be:

  • SBI, HDFC, ICICI, Axis Bank
  • Usually arrive via SMS: “Your account is blocked”

Fake sites impersonating:

  • Amazon, Flipkart, Myntra
  • Often advertise 90% discounts

Fake sites pretending to be:

  • Income Tax department
  • EPFO (PF withdrawal scams)
  • Passport Seva

Fake sites copying:

  • PhonePe, Google Pay, Paytm
  • Usually for “cashback” or “rewards”
BankOfficial Website
SBIhttps://www.onlinesbi.sbi
HDFChttps://www.hdfcbank.com
ICICIhttps://www.icicibank.com
Axishttps://www.axisbank.com
Kotakhttps://www.kotak.com
PNBhttps://www.pnbindia.in

Pro Tip: Bookmark your bank’s official website and always access it from your bookmark - never from links in messages.

What to Do If You Entered Details on a Fake Site

Section titled “What to Do If You Entered Details on a Fake Site”

Act immediately:

  1. Change your password on the real site immediately
  2. Call your bank to report and possibly block your account
  3. Check for unauthorized transactions
  4. Report the fake site to cybercrime.gov.in
  5. Enable 2FA on all accounts if not already done
  6. Monitor your accounts closely for the next few weeks

Chrome:

  1. Settings > Privacy and Security
  2. Enable “Enhanced protection”

Firefox:

  1. Settings > Privacy & Security
  2. Enable all “Deceptive Content and Dangerous Software Protection” options

Safari:

  1. Preferences > Security
  2. Enable “Warn when visiting a fraudulent website”
  1. Always verify the URL - character by character for banking sites
  2. Never click links in SMS/WhatsApp for banking or government sites
  3. Use bookmarks for frequently visited important sites
  4. Enable browser security features
  5. When in doubt, don’t proceed - call the official helpline instead