The useful answer
Stop when identity, policies, or payment instructions do not line up. A dramatic discount is never a reason to skip verification.
Professional design is not proof
A convincing booking page can be assembled quickly from copied photos, logos, and descriptions. Judge the site by verifiable identity and behavior, not polish.
Read the full domain from right to left. Extra words, misspellings, unusual subdomains, or a different top-level domain can signal an imitation.
Cross-check the business identity
Compare the address and telephone number with the hotel group’s directory, a trusted map listing, or another established source. Search the legal business name from the terms or footer rather than relying only on the brand displayed in the header.
Be cautious when every contact method leads back to the same unfamiliar website. Independent confirmation is more useful than three repeated claims.
- Domain ownership and brand relationship make sense
- Address and phone number agree across independent sources
- Terms name a real contracting business
- Support channels work before payment
Treat unusual payment requests as a stop sign
Pressure to pay by bank transfer, gift card, cryptocurrency, or a person-to-person payment app removes protections that cards may provide. A request to move the conversation to a private messenger is another reason to pause.
Never share a one-time authentication code with someone claiming to confirm a reservation. Legitimate payment authentication happens in your bank’s own flow.
Missing or contradictory policies matter
A legitimate seller should explain cancellation, refunds, taxes, payment timing, and who provides the accommodation. Generic text, impossible dates, or a refund policy that contradicts the checkout page are meaningful warning signs.
Take screenshots of the final price and terms. If the site prevents you from reviewing them before payment, choose another channel.
If you already paid and suspect fraud
Contact your card issuer or payment provider promptly using the official number on your card or statement. Preserve confirmations, messages, URLs, and screenshots. Then contact the real hotel through a verified channel to learn whether a reservation exists.
Report the website to the relevant consumer-protection or cybercrime authority in your country. Do not continue engaging with anyone asking for another payment to release a refund.
Quick answers
Frequently asked questions
Does HTTPS mean a booking site is legitimate?
No. HTTPS protects data in transit to that domain; it does not prove that the domain belongs to the hotel or that the seller is trustworthy.
What is the safest way to find a hotel’s website?
Use the hotel group’s official property directory or corroborate the domain across multiple independent, trusted sources before paying.
Have a stay to compare?
Put the guide into practice with CheckElsewhere.