How to Verify a Crypto Website Is Real
The padlock proves nothing. A working checklist for telling a genuine crypto site from a copy, and the habits that make the check automatic.

TL;DR
- The browser padlock means the connection is encrypted, not that the site is genuine. Most phishing sites have one.
- Read the domain right to left: the part before the first single slash is what you are actually visiting.
- Reach crypto sites by bookmark or typed address, never through search ads or links in messages.
- Cross-check a platform against an official regulator register before money moves, and verify social links from the site outwards.
The top search result looked perfect. It was an advert, bought that morning, wearing a real exchange's branding over a domain one letter off, with a login page built to harvest whatever got typed into it. In December 2022 the FBI put out a warning about precisely this trade: criminals buying search adverts to impersonate crypto platforms and outrank the genuine site. Everything about the fakes was professional, including the padlock.
About that padlock. By 2020, the security firm PhishLabs was reporting that four in five phishing sites served their pages over HTTPS, so the lock tells you one thing only: nobody can eavesdrop while a counterfeit steals your money in private. Encryption is not identity, so verification has to happen elsewhere, and here is the check, in the order that catches the most.
Step 1: read the domain, right to left
The only part of a web address that identifies the owner is the registered domain: the last two pieces before the first single slash. In banxa.com/coins, that is banxa.com, and in banxa.com.checkout-secure.net, it is checkout-secure.net, the familiar name at the front is bait. Subdomains are free costume, the right-hand end is the passport.
Then look for substitutions: swapped letters, an extra hyphen, .net for .com, the digit 1 for the letter l. Some attacks go further and register lookalike characters from other alphabets, so the address renders convincingly in the bar. If a domain arrived via a message and you have any doubt, do not squint at it: open a fresh tab and type the address you know.
Step 2: arrive by bookmark, not by search
The advert trade from the opening works because people navigate by searching a brand name and clicking whatever ranks, and the defence costs nothing. The first time you use any crypto platform, verify it once, bookmark it, and arrive by bookmark forever after, with type-and-autocomplete a fine second. Clicking through from search adverts, social posts or chat messages is how nearly every fake-site loss begins.
Step 3: check the company, not just the address
A real platform exists off its own website. Licensed crypto businesses appear on public regulator registers, searchable by legal name, and a fake site impersonating one usually cannot survive that lookup: the register entry points to a different domain, or the entry does not exist. The ten-minute version of that check has its own guide in this library, and you run it before first deposit, not after.
Verify in the right direction: find the platform's X account or support channel from links on the verified website, outwards. Searching social media first and trusting whatever verified-looking account appears is backwards, and support impersonation is a thriving trade.
Step 4: treat the rare, sophisticated attack as survivable
Occasionally the address bar itself lies: in April 2018, attackers hijacked internet routing for MyEtherWallet's DNS and served a fake site at the genuine address, and users who clicked through an unexpected certificate warning lost around 150,000 dollars in hours. The lesson is not that verification is pointless, it is that certificate warnings on a site you know are a stop sign, never a click-through, because they appear precisely when something structural has gone wrong.
Wallet users get one more backstop: a transaction preview. Whatever a page claims, the wallet shows what you are actually signing. An approval request from a site you came to for reading, or an unlimited spending permission where a plain transfer belongs, is the page confessing.
Make it automatic
None of this takes expertise: bookmark the platforms you use, read domains right to left, treat search adverts and messaged links as untrusted by default, check the register once per platform, and stop on certificate warnings. Five habits, a few seconds each, and the entire class of copied-website scams loses its audience.
Frequently Asked Questions
No. It means the connection is encrypted. Most phishing sites use HTTPS and show the padlock. Judge identity by the domain and independent checks, not the lock.
Read the domain right to left. The registered domain, the piece immediately before the first single slash, is what you are visiting. A famous name in the subdomain or path means nothing.
Treat them as untrusted. The FBI warned in 2022 about criminals buying adverts that impersonate crypto brands. Reach platforms by bookmark or typed address instead.
Search the regulator's own public register for the company's legal name and compare the domain the entry lists with the site in front of you. This library's guide to checking a platform's licence walks through it register by register.
Stop. On a site you already know, an unexpected certificate warning can mean the address itself is being intercepted, which is rare but real. Close the tab and try again later rather than clicking through.
