How to identify a reliable e-commerce site in 2026

For years the star advice for shopping safely online has been the same: “check if the padlock and HTTPS appear in the URL”. It was good advice in 2015. Today it’s misleading information. TLS certificates are issued free in minutes (Let’s Encrypt has automated the process since 2016) and fraudulent websites have them as standard. According to Google Transparency Report annual data, over 95 % of web traffic uses HTTPS, without distinguishing between legitimate stores and phishing pages.

Identifying a reliable e-commerce site in 2026 requires looking at other indicators: verifiable legal data, domain age, specific return policy, cross-referenced reputation on independent sources, and —when doubt persists— choosing a payment method that protects you if something goes wrong. This guide covers the signals that matter today and the concrete tools to verify a store before entering your card.

Why classic advice is no longer enough

The three usual pieces of advice —HTTPS, professional design and “trust seals”— have become insufficient:

HTTPS only encrypts the connection. It prevents a third party from intercepting data in transit, but says nothing about who’s on the other side. A website recently created by a scammer can have HTTPS just like Amazon.

Professional design is replicable. Shopify, WooCommerce or PrestaShop templates allow assembling a store with impeccable appearance in hours. Fraudulent websites in 2026 rarely look fraudulent at first glance. Many entirely clone a known brand’s website changing only the domain.

Seals can be faked. A “Trusted Shops” or “Confianza Online” seal is only useful if verifiable. Showing the seal image means nothing; the real seal links to the store’s profile on the certifying organisation’s website. If the seal is a simple gif without link, it’s cosmetics.

Signals that do matter in 2026

Complete and verifiable legal data. European regulation obliges any online store to display name or company name, tax ID number, address, registration details and electronic contact. If any of these data is missing, the store operates outside the law and offers no guarantees. The legal notice must be specific to that website, not a generic copied template.

Domain age. A domain registered three weeks ago pretending to be an established store is a strong fraud signal. Age can be checked on any Whois service (whois.com or similar). Domains less than six months old selling with large discounts deserve special scrutiny.

Specific and realistic return policy. In the European Union, the right of withdrawal grants 14 calendar days to return an online purchase without justification. A website offering “30 days return no questions asked” but then hiding conditions, or only allowing store credit, isn’t complying. A very generic returns policy (“there may be charges depending on case”) is usually copied from another website.

Cross-referenced reputation. Search the store name + “reviews”, “scam” or “opinions” outside their own website. Trustpilot, ProductReview and forums like Reddit show patterns the store itself hides. Caution: positive reviews can also be fake and now AI-generated. The most useful signal is usually finding many coincident negative reviews (indefinite delays, duplicate charges, impossibility to contact).

Image consistency. Many fraudulent stores use product photos taken from the manufacturer’s catalogue or other websites. A reverse image search (Google Lens or TinEye) reveals if the same photo appears in dozens of different stores, classic dropshipping or cloned store signal.

Concrete tools to verify a store

Before completing a purchase on an unknown website, five quick checks eliminate most fraud.

1. Domain Whois. Check registration date and registrant. Recently created domains with hidden owner are alert signal.

2. URL analysis with VirusTotal or urlscan.io. Free services that cross-check URL with lists of websites flagged as fraudulent by antivirus and security agencies. Doesn’t cover newly created websites but detects known ones.

3. National cybersecurity agencies. Bodies like INCIBE in Spain, ANSSI in France, or CISA in the US publish lists of known fraudulent websites and offer consultation services.

4. Trustpilot contrast with criterion. Average score isn’t enough; worth reading worst reviews (1 star) and filtering those mentioning specific problems (delays, duplicate charges, impossible contact). Very high scores with few reviews on very recent domains are suspicious.

5. Search for the seller’s name in the commercial registry. If the store declares a company name, it should be registered. In Spain, at Registro Mercantil; in the UK at Companies House; in France at INSEE. If the company name doesn’t exist or doesn’t match the activity, the store isn’t where it claims to be.

Dominant scams in 2024-2026

E-commerce fraud has evolved towards more professional patterns.

Known brand cloning. Domains imitating a real brand’s by changing one letter or adding a suffix (adidas-outletsale.eu, nike-black-friday.com). The website reproduces official design but sends payment to the scammer. Detect: search for the brand’s official domain directly on their main website, not through an ad.

Social media ads leading to fraudulent stores. Meta and TikTok have reinforced their verification but the volume of misleading ads remains high. An ad with a trending product at a price well below market leading to a website with unknown domain is rarely real.

Fake sales on key dates. Black Friday, January sales, Valentine’s Day and Prime Day are the weeks with most launches of fraudulent websites. They promise 70-90 % discounts on premium products. Shipping never arrives or arrives as low-quality imitation.

AI-generated reviews and descriptions. Many 2026 fraudulent websites use AI to generate plausible-looking reviews and detailed product descriptions. Detect: reviews with very similar structure, no style variation, generic details that could apply to any product.

Website impersonation during payment. Purchase initiated on a legitimate store that at payment moment redirects to a fake gateway capturing card details. Detect: check that the payment gateway URL corresponds to a known processor (Stripe, Adyen, Braintree).

Payment method matters as much as the store

Even if the store looks reliable, choosing the wrong payment method can leave you unprotected if something goes wrong. Methods, ordered from highest to lowest real protection:

Credit card. Visa/Mastercard network allows initiating a chargeback for goods not received, not as described or unauthorised charges. Credit card offers additional protection by not deducting the amount until monthly settlement.

PayPal with buyer protection. When the sale meets PayPal requirements (physical product, registered store, complaint within deadline), the system refunds if seller doesn’t respond or product doesn’t arrive.

Prepaid card loaded only with the amount. Not the one with best complaint tools, but limits damage if the website turns out fraudulent: only has the order balance loaded, not all money in a bank account. A Bitsa prepaid card with the exact purchase amount limits exposure if the website is a scam: even if fraud succeeds, the scammer only accesses the loaded balance. It also operates on 3D Secure with app authentication to authorise each online payment.

Debit card direct to bank. Less protection than credit and exposes the current account.

Bank transfer to unknown IBAN. No protection. Once executed, reversal requires voluntary cooperation from the recipient. Scammers empty the account before the claim can proceed.

Cryptocurrency directly to seller. No protection. On-chain transactions are irreversible. Only makes sense for purchases to legitimate merchants with established reputation integrating a known crypto processor (BitPay, NOWPayments), not for payments to individual wallets.

Legal framework and consumer rights

Right of withdrawal (14 days). The consumer can return an online purchase without justification within 14 calendar days from receipt. The store must refund within 14 additional days after receiving the product.

Digital Services Act (DSA). In force since 2024, obliges marketplaces (Amazon, eBay, AliExpress) to verify third-party seller identity and facilitate complaint mechanisms. Platform responsibility against fraudulent products has increased substantially.

National consumer authorities. Formal complaints can be directed to national consumer agencies. These routes work when the store is registered locally; against sellers in third countries the practical route is chargeback on card or PayPal.

What to do if you’ve been scammed

  1. Gather evidence. Save confirmation email, screenshots of the website when making the purchase (scammers often close it afterwards), conversations with seller, card charge statements.
  2. Contact the seller in writing. Even if you know they won’t respond, leave formal record.
  3. Initiate chargeback on the card. Usual deadline is 120 days from transaction (varies by Visa/Mastercard).
  4. Report to police. National cybercrime units investigate these cases.
  5. Report to cybersecurity agency. INCIBE, ANSSI or equivalent record incidents that feed into flagged website lists.
  6. Complaint to platform if applicable. If purchase was made from an ad on Meta, TikTok or Google, report the ad. Under DSA, platforms must facilitate mechanisms to remove fraudulent content.

Frequently asked questions

Are the padlock and HTTPS no longer useful?

They ensure communication with the website is encrypted, preventing a third party on the network from intercepting data. But they say nothing about seller reliability. In 2026 they are a minimum requirement even fraudulent websites meet. Their absence should discard the website, but their presence doesn’t validate it.

How do I verify if a store is real in 5 minutes?

Five checks: (1) find the legal notice and check there’s company name, tax ID, address and contact; (2) do Whois on the domain to see age and owner; (3) search the store name + “reviews” or “scam” on Google; (4) search the company name in the commercial registry; (5) contrast the product price with two or three known stores. If in the five tests there are inconsistencies, don’t buy.

What payment method is safest for shopping online?

Credit card has the best complaint system (broad chargeback). PayPal is convenient and offers buyer protection. A prepaid card loaded only with the purchase amount is useful as additional layer on unknown-reputation websites: if the purchase turns out fraudulent, only the loaded amount is lost, not an entire bank account.

Does using PayPal work for any store?

PayPal protection applies only when the purchase meets its requirements: physical product or contracted service, payment initiated from PayPal (not as friendly transfer), complaint within 180 days. Sending money via PayPal marking it as “friends and family” to pay for an online purchase cancels protection; scammers often request it with excuses.

How to distinguish a real review from a fake one?

Reviews all from the same month after domain launch, with similar style and no specific product details, are suspicious. Reviews with recently created usernames or empty profiles, too. Real reviews usually mention specific details (exact shipping time, particular features, comparison with another brand), even the positive ones.