Checking an unfamiliar website requires separating the address, public safety information and the action it asks you to take. A certificate, polished design or clean tool result does not establish that every transaction or download is trustworthy.

Use several limited checks and verify material claims independently. This guide concerns public assessment of a website, rather than private owner-only Search Console reports.

Read the exact address and claimed identity

Check the relevant domain carefully for altered characters, added words and unexpected spelling. A display label or search advertisement can describe a destination without authenticating it.

Our typo-domain guide explains common identity-confusion patterns. If the site claims to represent a known organisation, locate that organisation’s genuine contact or login route independently.

Review public warnings within their scope

Google provides a Safe Browsing site-status tool. Preserve the queried address, result and date, particularly if a warning is displayed.

Sucuri SiteCheck documents remote public-content scanning and its limitations. A remote scan cannot inspect every private file or server-side component, and absence of a finding is not a complete safety certificate.

Do not override a browser warning merely because another limited tool produced a different result. Investigate the reporting source and exact address involved.

Understand what HTTPS establishes

HTTPS supports encrypted connections and certificate-based connection identity. It does not verify the honesty of the site’s business proposition or prevent all compromised content.

A deceptive site can also use HTTPS. Treat encryption as one technical property, alongside the site’s identity, request and verifiable claims.

Assess the request and supporting information

Check what the site wants: login credentials, payment, a download or private data. Consider whether the request fits a known relationship and whether it can be confirmed through an independent channel.

The NCSC’s phishing guidance covers deceptive sites and communications. Unexpected urgency or changing payment instructions need verification, rather than reassurance from the same unverified page.

Compare invoices or login requests with independent account records. A page reached through an unsolicited renewal notice should not be accepted solely because its name imitates your provider.

Being a third-party seller is not itself proof of spam. Likewise, a pop-up or awkward writing alone cannot decide legitimacy. Record concrete concerns and evaluate them in context.

Keep public and owner evidence separate

If you own the property and have authorised access, additional reports can reveal specific findings. Our website-warning guide explains that process.

Moz Spam Score is a separate SEO research metric, described in our score guide. It cannot certify a download, merchant or login prompt.

Where material uncertainty remains, verify through genuine provider channels before sharing data or paying. A useful check produces supported observations and recognised limits, rather than a universal label that makes every interaction safe.

Categorized in: