You can tell a shopping site is fake or AI-generated by checking four things before you type in a card number: how old the domain is, whether the reviews and product photos hold up under a close look, whether a real contact and returns page exists, and whether the price is too good to be a coincidence. Fail two of those and close the tab.
The old advice, watch for typos and blurry logos, doesn’t work anymore. The Better Business Bureau has said plainly that AI tools now let scammers build a flawless-looking storefront in minutes, complete with clean copy, a matching logo, and fabricated reviews. Malwarebytes recently mapped a single operation running over 20,000 fake shop domains off shared infrastructure, all generated fast enough to replace each other as they get shut down.
This isn’t a rare event you’ll get lucky avoiding. It’s a volume business. The checklist below is what still catches it, sourced from the researchers and agencies actually tracking these networks.
How we checked this
The red flags here come from the Better Business Bureau’s scam alerts, the FTC’s online shopping guidance, and two Malwarebytes investigations into AI-built storefront networks, plus ScamAdviser’s published checklist for spotting scam sites. Norton’s research on fake fashion e-shops rounds out the pattern. Nothing here is a private test; it’s what these organizations have documented and put their name on.
The checks that still work
| Red flag | What it looks like | How to check it |
|---|---|---|
| Brand-new domain | Site claims to be an established brand | Run a free WHOIS lookup; a domain registered weeks ago is a hard stop |
| Too-perfect reviews | Reviews all sound alike, generic names, stock-photo faces | Search a review sentence in quotes and see if it repeats on other sites |
| AI product photos | Glossy texture, odd fingers, warped background objects | Zoom into hands, fabric weave, and reflections |
| No real contact page | Only a contact form, no address or phone number | Search the business name plus 'scam' or 'reviews' separately |
| Deep, urgent discounts | Countdown timers, "90% off," stock "almost gone" | Compare the price against the same item on a marketplace you trust |
Domain age is the single best tell
Legitimate stores have domains that are years old. Scam operations don’t, because the domain gets abandoned once it’s flagged or the payment processor cuts them off. A WHOIS lookup (whois.domaintools.com, or just search “whois” plus the domain) shows the registration date in seconds, and a site posing as an established retailer that’s three or four weeks old is close to a guaranteed no.
That single check would have flagged most of the network Malwarebytes found. Investigators traced more than 20,000 lookalike storefronts back to just 36 shared IP addresses, almost all registered on the .shop top-level domain, which Cloudflare’s own security data ranks among the domains most associated with spam and fraud. One group runs the servers and templates; smaller operators spin up a new domain and brand name on top whenever an old one gets shut down.
AI tells in photos, copy, and reviews
BBB’s own scam alert is blunt about this: the misspellings and pixelated logos that used to give scams away don’t happen anymore. What still slips through is subtler. Product photos often carry a glossy sheen AI struggles to avoid, and small details, fingers, teeth, fabric weave, come out slightly wrong under a zoom.
Reviews are the easier tell. ScamAdviser flags copy that reads technically correct but strange, phrases like “brings joy to every foot journey with modern performance delight.” Real customers don’t write like that. Neither do real reviews cluster with generic names and stock-photo avatars, or appear all at once on a store with no other footprint anywhere online.
Missing pages and payment red flags
A real retailer has to publish a return policy, a shipping timeline, and a way to reach a human. The FTC’s own online shopping guidance requires sellers to ship within the promised window (30 days if none is stated) and issue a real refund, not store credit, when they don’t. A site that skips all of that, or buries it behind a contact form with no phone number or address, is choosing to avoid accountability.
Payment method matters just as much. A legitimate checkout takes a credit card, which gives you a chargeback if something goes wrong. Any site steering you toward wire transfer, cryptocurrency, or a gift card at checkout is asking for a payment method that can’t be reversed, which is the same tell that shows up in phone and voice scams. Our guide to recognizing an AI-generated scam covers that exact pattern outside the shopping context.
Worth it for
- Checking domain age catches most fake stores before you type in a card number
- AI product photos still struggle with fine detail: fingers, fabric weave, reflections
- A missing or fake contact page takes 30 seconds to check and rarely lies
- Paying by credit card instead of wire or crypto gives you a real chargeback path
Skip it if
- AI-written product copy keeps getting harder to distinguish from a human's
- A convincing storefront can still pass a quick visual glance
- Domain age alone won't catch fraud running on a hijacked legitimate site
- Trust seals and badges can be copied, so verify them on the issuer's own site
Alternatives
- Shop through a marketplace with buyer protection (a known platform’s checkout, not a link from an ad) so a failed delivery has a dispute process behind it.
- Search the exact product plus “scam” or “reviews” before buying anywhere unfamiliar; independent complaints usually surface fast for active fake shops.
- Use a credit card, never a debit card or gift card, for any purchase from a store you haven’t ordered from before.
Verdict
SKIP checkout on any store that fails more than one of these checks: a domain registered in the past few weeks, reviews that read oddly uniform, no real contact information, or a discount that doesn’t add up. None of these checks are foolproof alone, but running all four takes under two minutes and catches the overwhelming majority of AI-generated storefronts before your card number ever leaves your phone.
Common questions
Is Temu legit and safe to order from?
Temu itself is a real, publicly traded company, not a scam storefront. That said, Norton’s own reporting notes real concerns: multiple state attorneys general have sued over data collection practices, and product safety testing has flagged issues with some third-party sellers on the platform. Temu’s checkout uses standard encryption and there’s no confirmed large-scale breach as of mid-2026. The bigger risk on Temu isn’t the platform being fake, it’s individual sellers and product quality, which is a different problem than the AI-storefront scams this article covers.
Is DeepSeek safe to use?
For anything involving personal, financial, or professional data, no. DeepSeek’s own privacy policy discloses that it stores data in China, where authorities can legally request access, and Cisco’s security research found DeepSeek R1 failed to block a single harmful prompt across 50 automated jailbreak attempts, a 100% failure rate compared to 26% for OpenAI’s o1. Italy, Australia, and multiple U.S. federal agencies have restricted or banned it on official devices. It’s a capable tool for low-stakes tasks, but not one to hand sensitive information to.