How to check if a website is fake

You can check if a website is fake by inspecting the URL, the padlock and certificate, the age of the domain, small details on the page, and by cross-checking against the organisation's real website. A single one of these signals is rarely enough — a fake site usually fails two or three at once.

Read the URL character by character

Fake sites use lookalike domains — a hyphen inserted (anz-nz.com instead of anz.co.nz), an extra word (secure-westpac-login.com), or letters swapped (an rn where an m should be, or a 0 where an o should be). Read the domain slowly, right to left, starting at the .nz or .com.

Padlock is not proof of trust

The padlock icon (or "https") only means the connection between you and the site is encrypted. It does not mean the site is legitimate — scammers get free TLS certificates for their fake sites within minutes. Treat the padlock as a floor, not a ceiling.

Check when the domain was registered

Paste the domain into a WHOIS lookup — dnc.org.nz for .nz, whois.com for others. A domain registered in the last few weeks that claims to be a major bank or government agency is almost always fraudulent — real organisations have owned their domains for years.

Look at the details on the page

Fake sites often have low-resolution logos, broken links in the footer, no working "Contact us" page, and language that doesn't quite sit right. Any real business has a physical NZ address, an NZBN (searchable on nzbn.govt.nz), and a working phone number.

Cross-check with the real website

Open a new tab, go to Google, and search for the organisation's name. Compare the URL you were sent against the URL that Google surfaces as the top official result. If they don't match exactly — including the .co.nz, .govt.nz, or .com ending — assume the one you were sent is fake.

Use a URL scanner

Paste the URL into a free scanner like urlscan.io, VirusTotal, or Google Safe Browsing. These tools flag known phishing sites, malware droppers, and lookalike domains within seconds.

If you're still unsure

Don't log in. Don't enter anything. Contact the organisation on a number you already have — a card, a statement, or the number on their real website — and ask if the page you're looking at is theirs. Two minutes on the phone is cheaper than an emptied bank account.

Quick checklist

  • Does the domain match, exactly, the one on the real organisation's website?
  • How old is the domain (WHOIS)?
  • Do the internal links, footer, and contact details work?
  • Does a URL scanner (urlscan / VirusTotal) return anything suspicious?
  • Have you verified via a second, independent channel?

Need help?

If you think you've been targeted or you're not sure what to do next, the Decision1 team can walk you through it. No cost for a first conversation.