# How to Check Whether a Website or Payment Link Is Legitimate

Source: https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection/check-website-payment-link-legitimate

**Answer:** Check two things separately: whether the browser has a protected connection to the domain shown, and whether that domain, business and payment request are genuine. Read the full address, navigate independently, verify unexpected requests through a known channel and confirm the recipient before paying. A lock icon means the connection is encrypted; it does not certify the seller.

Part of [Digital Safety, Privacy & Account Protection](https://urbanx.co.za/knowledge-hub/digital-safety-privacy-account-protection) · 11 min read · by UrbanX Knowledge Hub

**Last reviewed: 26 August 2026 · 11 min read**

### Start with the actual domain

The registered domain is the central identity in a web address. Read carefully around it.

In `accounts.urbanx.co.za`, the registered domain is `urbanx.co.za`. In `urbanx.account-help.example`, the registered domain is `example`; the brand word appears only in a subdomain chosen by someone else.

Look for:

- missing or extra letters;
- substituted numbers or similar-looking characters;
- unexpected hyphens;
- a different domain ending;
- a long prefix before the true domain;
- URL-shortening services; and
- domains that do not match the organisation’s established address.

Do not assume a `.co.za` ending proves a site is South African-owned or legitimate.

### Use a known route instead of the supplied link

For a login, bill or payment:

1. Close the message or advert.
2. Open the official app, saved bookmark or manually typed site.
3. Find the invoice, order or security alert inside the account.
4. Contact the organisation using details from its known website or prior verified document.
5. Ask whether the request and recipient are correct.

This defeats many copied pages because the user does not enter through the attacker’s route.

### Understand the lock icon correctly

HTTPS provides a protected connection to the displayed domain. It helps prevent other parties on the network from reading or altering information in transit.

It does not prove:

- the business will deliver;
- the seller is licensed or registered;
- the bank account belongs to the expected organisation;
- the offer is genuine;
- the site has never been breached; or
- the domain is the one the user intended.

Google advises users to check the site name even when the connection is secure. CISA notes that attackers can obtain certificates for malicious websites.

### Treat browser warnings as a stop signal

Do not proceed when the browser reports an unsafe site, malware, certificate error or insecure connection—especially for a login or payment.

Google’s Safe Browsing status tool can show whether a known URL is currently flagged, but an unflagged result is not proof of legitimacy. New scam pages may not yet be detected.

### Verify the business beyond its own page

Check information the site cannot control easily:

- known company contact details;
- a physical or registered presence where relevant;
- established social profiles linked from a known source;
- independent customer history;
- domain age only as one clue, not a verdict;
- policies that identify the contracting entity;
- consistent contact and banking details; and
- whether the offer appears on the organisation’s official account or app.

Search the business name with terms such as “scam” or “fraud,” but evaluate results carefully. Fake review pages and copied testimonials also exist.

### Payment links and QR codes need extra care

A payment link can point to:

- a genuine merchant checkout;
- a legitimate third-party processor;
- a payment request created by a real person;
- a copied checkout designed to steal card data; or
- a transfer instruction to the wrong recipient.

Before paying:

1. Confirm the order independently.
2. Check the amount, merchant and recipient.
3. Inspect the full destination.
4. Confirm changed banking details verbally through an existing trusted contact.
5. Read banking-app warnings and recipient confirmation.
6. Do not approve a transaction merely to “reverse” or “protect” money.
7. Keep the invoice and proof.

A QR code is only another way to encode a destination. Preview it before opening and look for a sticker placed over an original code.

### Search adverts can be impersonated

The first sponsored result is not automatically the official organisation. Criminals can buy adverts that imitate familiar login or support searches.

For a bank, ISP, government service, password manager or gaming platform, prefer a saved official app or bookmark. Avoid searching for “support phone number” and calling the first advert without checking the domain.

### Marketplace and social-commerce checks

Be cautious when a seller:

- moves the conversation off the marketplace immediately;
- sends a buyer or courier “verification” link;
- asks the seller to pay a release or insurance fee;
- refuses the platform’s protected checkout;
- insists on an irreversible payment method;
- uses stolen product photos; or
- creates urgency around a price far below the market.

Stay within the platform’s official messaging and payment flow where possible. A screenshot claiming payment was made is not the same as funds confirmed in the real banking app.

### If the site collects identity documents

Ask:

- Why is the document required?
- Who is the responsible organisation?
- Is there a privacy notice?
- Can unnecessary fields be redacted under the process?
- How should the file be transmitted?
- Is the request visible in the genuine account?
- What is the retention and deletion process?

Do not send an ID copy, selfie or proof of address through an unverified WhatsApp number because the page looks professional.

### If payment or credentials were submitted

- Contact the bank or card issuer immediately for payment or card exposure.
- Change the affected password from the genuine service.
- Change every reused password.
- End unknown sessions and enable MFA.
- Secure the recovery email.
- Preserve the URL, messages, payment details and timestamps.
- Report the site to the impersonated organisation, browser or hosting/take-down channel.
- Follow current SAPS guidance where fraud or crime occurred.

### Sources

- [Google Chrome: Check If a Site’s Connection Is Secure](https://support.google.com/chrome/answer/95617)
- [Google Safe Browsing Site Status](https://transparencyreport.google.com/safe-browsing)
- [CISA: Shopping Safely Online](https://www.cisa.gov/news-events/news/shopping-safely-online)
- [FTC: How to Recognise and Avoid Phishing Scams](https://consumer.ftc.gov/articles/how-recognize-avoid-phishing-scams)
- [ISPA Public Advisory: Domain Name Fraud](https://ispa.org.za/press-releases/public-advisory-domain-name-fraud/)
- [SABRIC: How to Stay Safe](https://www.sabric.co.za/how-to-stay-safe/)

### Related guides

- [All Digital Safety, Privacy & Account Protection guides](/knowledge-hub/digital-safety-privacy-account-protection)
- [HTTPS Explained: What It Protects and What It Does Not](/knowledge-hub/digital-safety-privacy-account-protection/https-what-it-protects)
- [How to Spot a Phishing Email, SMS or WhatsApp Message](/knowledge-hub/digital-safety-privacy-account-protection/spot-phishing-email-sms-whatsapp)
- [Fake ISP Support Calls and Messages](/knowledge-hub/digital-safety-privacy-account-protection/fake-isp-support-scam-red-flags)

## Frequently Asked Questions

**Does HTTPS prove a payment page is safe?**

It proves a protected connection to the shown domain, not that the merchant or request is honest.

**Is a `.co.za` website automatically local and legitimate?**

No. Domain endings do not guarantee ownership, hosting location or honesty.

**Can Google Safe Browsing prove a site is clean?**

It can warn about detected threats. A site not currently flagged may still be new, compromised or dishonest.

**Should I trust a QR code printed in a shop?**

Confirm the destination and check that another sticker has not covered the original. Verify the recipient before payment.

**What is the safest way to follow an account alert?**

Open the known app or manually typed website and find the alert there instead of using the message link.
