Knowledge · Check before you click or pay · 8 minutes

How to check if a website is safe: 7 checks before you trust it

A padlock and https do not mean a site is honest. Check the domain, its age, the CERT Polska warning list and company details. Steps for phones and banks too.

Last updated: October 5, 2026

What does a 'safe website' actually mean?

A 'safe website' is really three separate questions. Is the connection encrypted? Is the site run by who it claims to be? Is it a known scam? The padlock only answers the first one.

Nobody outside the company can tell you a site is 100% safe. What you can do is collect, in a few minutes, the signals that separate a normal business from a site set up yesterday for a single campaign. Below is a list of checks you can do yourself with nothing but a browser.

Does a padlock and https mean a website is safe?

No. An https certificate confirms that the connection to a given domain is encrypted and cannot be read along the way. It says nothing about who owns the domain or what they will do with your data. Anyone who registers a domain can get a certificate, scammers included.

Google said this plainly in May 2023: the padlock icon does not indicate that a site is trustworthy, and nearly all phishing sites use https. In Google's 2021 research only 11% of participants correctly understood what the padlock meant. That is why, since Chrome 117 (September 2023) on desktop, the padlock has been replaced by a neutral settings icon.

The takeaway: no https is a reason not to enter any data. Having https proves nothing.

How to check if a website is safe, step by step

1. Read the address from the right. What counts is the domain just before the first slash '/'. In 'bank.pl.login-24.com/pl' the real domain is 'login-24.com', and 'bank.pl' is just decoration at the start.

2. Look for imitations of a brand name. Swapped letters (rn instead of m, 0 instead of o), add-ons like '-support', '-verify', '-refund' or a different ending (.com instead of .pl) are the most common tricks.

3. Check the domain's age. For .pl domains, search the NASK registry WHOIS at dns.pl/whois and look at the 'created' field. For other endings, use ICANN Lookup at lookup.icann.org. A domain registered a few days ago that imitates a known brand is a strong warning sign.

4. Check the CERT Polska warning list at lista.cert.pl. In 2025 almost 245,000 domains were added to it, and blocking stopped about 141.1 million visits to dangerous sites (CERT Polska annual report for 2025). A domain missing from the list is not proof it is clean: new sites only get there after someone reports them and they are analysed.

5. Look for company details. An honest site that sells something or collects data gives a company name, address, tax or registry number, terms of service and a privacy policy. Check that these details exist in an official register, not just in the footer.

6. Think about where the link came from. An ad with a 'deal', a text about an unpaid parcel fee, a message from a stranger on a chat app are typical sources of scam sites. Go to your bank, a government office or a shop from a bookmark or by typing the address yourself.

7. Put it all in one place. You can check for free with arLET'S, in website or domain mode: domain age, the warning list, similarity to known brands, encryption, terms and company details. The result tells you what is known, what is not known and what to do next.

How to check if a website is safe on your phone

On a phone the address is shortened and easy to miss. Tap the address bar to see the full domain and read it from the right, as in step 1.

Do not open a link from a text message or chat app straight away. Press and hold it, choose 'Copy', paste it into your notes and read the address calmly. According to CERT Polska, most visits to phishing pages happen within 15 minutes of receiving the message, and that rush is exactly what scammers count on.

Your mobile network can help too. According to CERT Polska, the Polish operators that joined an agreement with the telecoms regulator and NASK in 2020 use the warning list: Orange, Plus, Play and T-Mobile. If you see a CERT warning page instead of the site, close the tab. Note that the block works on the operator's network and may not work on a different Wi-Fi.

In Poland you can forward a suspicious text message for free to 8080. It goes to CERT Polska for analysis, and a malicious domain may be added to the warning list.

How to check if a bank website is safe

The simplest rule: never reach your bank's login page through a link. Type the address yourself, use a saved bookmark or the bank's app. That almost removes the fake site problem.

If you are already on a page that looks like your bank, check the domain character by character and compare it with the address on your contract, card or app. Stop if the page asks for something unusual: a mobile payment code 'for verification', full card details for a normal login, a text message code to 'cancel' a transfer, or installing an app to 'secure your account'.

If in doubt, call the bank on the number printed on your card or on the official site you typed in yourself. Do not call a number shown on the suspicious page or in the message.

What to do if you entered data on a suspicious website

Act straight away, in this order. Card or banking login details: call your bank and block the card or access. Poland's Central Cybercrime Bureau recommends contacting the bank as the first step, then freezing your national ID number (PESEL) in the mObywatel app or on gov.pl.

Email or service password: change it now, also everywhere you reused it, and turn on two-step login. If you suspect your data is circulating further, read how to check if your data has been leaked.

Report the site to CERT Polska using the form at incydent.cert.pl. If you lost money, report it at any police station and bring the site address, screenshots, messages and transfer confirmations.

What you cannot check from the outside

Looking at a site as a normal visitor, you cannot see how the company stores data, who has access to it or whether its servers are well protected. That needs a full assessment with the owner's permission, not an outside look.

If the site is a shop, go to the separate checklist: how to check if an online shop is legit. If your doubt is about a link in a message, start with how to check if a link is safe. Mobile apps have their own risks, covered in how to check if an app is safe.

In short

  • A padlock and https only mean the connection is encrypted. Scam sites have them too.
  • The most telling signals are the domain read from the right, its age in the registry and whether it is on the CERT Polska warning list.
  • Reach your bank and government services from a bookmark, an app or by typing the address, never from a link in a message.
  • A site missing from the warning list is not proof it is safe: new domains are only added after they are reported.
  • In Poland, forward suspicious texts to 8080, report sites at incydent.cert.pl, and if you entered data, call your bank first.

Have a website, app or email address that looks suspicious?

Frequently asked questions

Is a website with a padlock safe?

Not necessarily. The padlock means an encrypted connection to the domain, not an honest owner. According to Google, nearly all phishing sites use https.

How can I check when a website was created?

Check the domain registration date. For .pl domains use the NASK registry WHOIS at dns.pl/whois (the 'created' field), and for other endings use ICANN Lookup at lookup.icann.org.

How do I check if a site is on the CERT Polska warning list?

Go to lista.cert.pl and search for the domain. A domain stays on the list for 6 months and can be added again, and CERT Polska recommends that blocking systems download the list every 5 minutes.

Where can I report a fake website in Poland?

To CERT Polska via the form at incydent.cert.pl or in the mObywatel app (the 'Safe online' service). Forward a suspicious text message for free to 8080.

Does an arLET'S check guarantee that a site is safe?

No. The free check looks at the site from the outside, like a normal visitor, and tells you what is known, what is not known and what to do. It is not a penetration test or a certificate.

Sources

  1. Chromium Blog: An Update on the Lock Icon (2 May 2023)
  2. CERT Polska: Warning list of dangerous websites
  3. CERT Polska: Annual report on CERT Polska activities in 2025
  4. NASK: WHOIS for .pl domains
  5. ICANN Lookup: domain registration data
  6. CERT Polska: Report an incident
  7. Central Cybercrime Bureau (Polish Police): Report cyber fraud

Accurate as of the article's last update. Laws and vendor terms change, so check the source before you decide.

See also