A fake hotel booking website is a convincing copy built to look official. It borrows a real hotel’s photographs, room descriptions and logo, registers a look-alike domain, and often buys the top search result, then asks you to enter card details on a page that belongs to a criminal. Learning how to spot a fake hotel booking website takes about two minutes once you know the eight checks, and every one of them runs before you type a card number.
The awkward part is that these sites are no longer easy to eyeball. Scam copy no longer contains typos because software writes it now, the photography is often the genuine article lifted from the hotel’s own public pages, and the message may arrive inside a real booking platform’s chat window with your correct dates and reservation number. Familiarity is not verification.
What follows is the routine I run before paying any unfamiliar property, whether it came from a search result, a social media advert, an email or a WhatsApp message. It is channel-neutral on purpose, because the same checks work for a standalone site, a listing on a large booking platform and a deal sent to you by a “hotel representative”.
Table of Contents
- What You Need
- Step-by-Step: How to Spot a Fake Hotel Booking Website
- 1. Check the Website Address: How to Spot a Fake Hotel Booking Domain
- 2. Verify the Hotel Exists Independently
- 3. Compare Prices and Availability Without Rushing
- 4. Read Reviews on Separate Websites
- 5. Check Policies, Contact Details and Business Legitimacy
- 6. Investigate the Payment Request
- 7. Test Support Before Sending Money
- 8. Confirm Before You Pay and Keep Evidence
- Common Mistakes
- Frequently Asked Questions
- Can HTTPS prove that a hotel booking website is legitimate?
- What should I do if I already paid a suspected fake hotel booking website?
- Are very cheap hotel rooms always a scam?
- How can I verify a hotel reservation received by WhatsApp or email?
- Which payment methods should I avoid on an unfamiliar hotel website?
- How do I report a fake hotel booking website?
- Start With the Domain, Not the Photos
What You Need

Five minutes and a second device. That is the whole requirement, and the second device matters more than people expect, because checking a suspicious site while still inside it breaks the illusion the scam depends on.
Gather the claim before you judge it. Write down the exact property name, the address, your dates, the room type, the number of guests and the total being asked for. Then keep the reservation request itself: the email, the chat thread, the advert screenshot. Screenshots taken now are evidence later, and they are the only record you will have if the site is taken down within a day.
Have independent sources open in a different browser or on your phone. That means the property’s official website, a mapping app listing, and at least one large booking platform showing the same dates. Never take the phone number from the suspicious message. Find it yourself, from the hotel’s official domain or its verified listing, and that number becomes your verification channel.
Finally, know your payment options before you are asked to choose one. A standard credit card gives you a chargeback route if things go wrong. A virtual card number from your bank gives you a disposable set of digits. A transfer, a gift card or a cryptocurrency request gives you nothing at all.
Step-by-Step: How to Spot a Fake Hotel Booking Website

Run the checks in order. The early ones are fast and rule out most attempts; the later ones only matter if the first ones pass. Stop at the first failure and book through a channel with buyer protection instead.
1. Check the Website Address: How to Spot a Fake Hotel Booking Domain
Read the address character by character, and only the part before the first single slash. Fake sites rely on eyes that skim. Extra hyphens, a swapped letter pair, a doubled character, or a long subdomain that pushes the real brand name into tiny grey text are all common tricks.
Watch for the wrong second-level ending, such as a country suffix sitting where the real domain uses a generic one, or a support address on an unrelated domain. Hover or long-press any link before clicking it so the true destination appears in the preview rather than at the bottom of the screen. Do the same with buttons inside the page, including the one you are about to use to pay.
Then close the tab and search for the property’s name in a fresh window. The official site should appear and should match the address you are about to use. If the site you were sent sits above the hotel’s own domain, or the hotel’s real domain is not in the results at all, stop.
One more thing to check here: the padlock. HTTPS means the connection is encrypted, nothing more. Free certificates are issued in minutes, so a locked padlock proves only that someone has an encrypted connection to whoever controls that site. Several of the sites involved in reported cases show a perfectly valid padlock.
2. Verify the Hotel Exists Independently
Confirm the property exists without using anything the suspicious site told you. Search the name plus the city in a mapping app and read the address, the street view and the number of reviews. A listing that has no photographs, no reviews and no street-level imagery is describing something that may not be there.
Compare the details line by line. Room types, the number of floors, whether there is a pool, whether parking is included, the general layout. Real operators are consistent across their own channels; scammers often assemble a page from descriptions that do not quite agree with each other.
Reverse-search the main photograph. Google Lens and similar tools will show you other properties using the same image, and the result is regularly a completely different hotel or an agency photography library rather than the property you are considering. Genuine professional photography is public, so copying it is trivial, and that is exactly why a photo alone proves nothing.
Finally, take the phone number from the hotel’s official website, not from the message, and ask whether they have a reservation under your name for those dates. Do this before you send any money or documents.
3. Compare Prices and Availability Without Rushing
Check the same dates and room type on the hotel’s official site and on one or two large booking platforms. You are not looking for the cheapest option; you are looking for an explanation if the number is far lower than everything else. A rate well below the market is information, not a bargain.
Look for completeness. Does the site show genuine availability for your dates, or does everything appear to be available? Are taxes and fees included in the headline figure? Watch specifically for charges labelled as resort fees or as tax recovery charges and service fees, which often appear only at the final step. Some reports to the Better Business Bureau describe a quoted rate that grew by more than half once those lines were added at checkout.
Urgency is the pressure mechanism. Language about the last remaining room, a rate held for a short window, or a reservation about to be released is designed to stop you checking. A genuine property will happily answer questions about a rate tomorrow morning.
Be suspicious of the overflow-booking story in particular: the site claims it handles calls the hotel is too busy to take, adds a service charge for the privilege, and then marks the booking non-refundable. That combination removes every reason for you to slow down.
4. Read Reviews on Separate Websites
Reviews sitting on the suspicious site are not evidence. They are content. What matters is what travellers say about this property or this domain on platforms you found yourself, including travel forums and consumer complaint boards.
Search the domain itself as well as the property name. Scam campaigns tend to leave a trail once enough people are caught: repeated reports of paying for a room that did not exist, of being moved to an expensive last-minute alternative, of messages arriving through unusual channels after a “payment failed” notice.
Look for the shape of the complaints rather than single complaints. One angry review is noise. Several independent threads describing the same pattern, from the same dates or the same property name, is a signal. In one long-running thread on the r/travel forum, travellers reported that at least 120 people had lost money to the same listing and had to find expensive rooms at short notice. Other travellers describe receiving the same link through what looked like a genuine in-platform chat.
Reviews help in one more way: genuine guest reviews are specific. They mention the room number layout, the walk to the beach, the breakfast queue. Generic praise with no detail is as useless on a review page as it is on a booking site.
5. Check Policies, Contact Details and Business Legitimacy
A real operator publishes who they are. Look for a legal business name, a registered company number, a physical address and a tax or VAT identifier, usually in the footer or in a terms and conditions page. Check that the contact page lists a phone number, an email address on the company’s own domain and at least one named person.
Note what is missing as much as what is present. Generic greetings such as Dear Customer, a policies page written in a single paragraph, and a contact form with no phone number all point the same way. So does a refusal to answer a direct question about cancellation terms.
Take the business details and look them up on the official company register for the country they claim to operate in. It takes a minute and it is a check almost nobody does.
Read the cancellation policy properly, because it decides how much a dispute is worth. A non-refundable booking made on an unverified site leaves you with very little to argue with. Watch too for rate changes arriving in a confirmation message after you thought the price was settled.
6. Investigate the Payment Request
Look at what is being asked for and through which channel. Card payments on the hotel’s own domain are the normal case. Requests to pay outside the platform, to a personal account, to a new payment link, or to cover a supposed verification or insurance fee are all warning signs.
Refuse any request for a wire transfer, a bank transfer, a prepaid or gift card, or cryptocurrency. Those routes are deliberately untraceable, and no genuine hotel asks for them.
Pay close attention to links that arrive by message with an explanation attached. Reports of this scam often describe a “payment failed” or “card re-verification” notice that opens a page styled like a 3D Secure card authentication screen. Travellers enter full card details believing they are completing a bank security step. They are not; that page exists to capture the card, and the hotel has no record of any charge.
Real hotels rarely ask for full card details, passwords or identity documents by email or chat. If a message requests any of those, treat the conversation as finished.
7. Test Support Before Sending Money
Contact the property through a channel you sourced independently, then ask a question only a real member of staff could answer. Whether the sea-facing rooms have balconies, what the last check-out time is, whether parking is included in the rate, how far the walk to the station is. If the answer is vague, wrong or copied from your own message back to you, that is your answer.
Watch the tone too. Evasive replies, a refusal to give a direct phone number, an insistence that you cannot discuss with the hotel directly, or repeated pressure to pay quickly are all consistent with the same operation.
A genuine property will not mind the call. Front desks answer questions about bookings all day, and a request to confirm a reservation is an ordinary thing to ask. The scammer’s problem is that the hotel they are impersonating has never heard of you.
8. Confirm Before You Pay and Keep Evidence
Before any payment, you should be able to tick seven things: the booking is on the hotel’s own verified domain; you have a written confirmation with a reference number; the total is itemised and includes taxes and fees; the cancellation terms are in writing; the payment route is a secure card page on that same domain; you have spoken to the property through a number you found yourself; and you have saved screenshots of every page and message involved.
If any box is empty, do not pay. Book through a large platform instead and accept a slightly different room or rate, because buyer protection is worth more than a small saving and far more than the whole amount if the property does not exist.
Keep the evidence for at least a year after your stay. Screenshots of the confirmation, the itemised price and the payment page are what make a dispute tractable, and they are much easier to collect now than after the site has disappeared.
Common Mistakes
Most people who get caught were doing something ordinary. Here are the errors I see most often, with the fix for each.
Trusting the design. A polished site with real photography proves nothing, because everything on it can be copied. Replace visual impressions with the phone call to the front desk.
Relying on reviews hosted on the same site. Copy the property name and search for reviews elsewhere before you read a single one on the page.
Accepting urgency. A countdown or a “last room” message is a sales tactic, and it is the scammer’s favourite one. Fix: close the page and come back the next day. If the offer were real it would still be there.
Paying by transfer, gift card or cryptocurrency. You lose your ability to dispute. Fix: use a card, and a virtual card number if your bank offers one.
Answering a message that arrives inside a real platform’s chat window. Hijacked hotel accounts send convincing links from what looks like a legitimate thread. Fix: never follow a payment link from chat. Navigate to the property’s official domain yourself.
Ignoring small inconsistencies. A wrong street number, a room type that does not exist, an address that maps to a car park. Fix: write the details down and compare them side by side rather than skimming.
Treating a padlock as a guarantee. Encryption is table stakes. Fix: pair it with a domain age check, which a free WHOIS lookup makes easy, and a search for the hotel’s real domain.
Skipping the itemised total. Hidden charges are how a fair rate becomes a poor one. Fix: screenshot the full price breakdown, including any resort fees or tax recovery lines, before you confirm.
Two habits cover most of the rest. Book direct or through a platform with clear buyer protection rather than through a link somebody sent you, and turn on transaction alerts so a card used abroad gets flagged quickly. If something does go wrong, speed matters more than anything else you do afterwards.
Frequently Asked Questions
Can HTTPS prove that a hotel booking website is legitimate?
No. HTTPS and the padlock only mean the connection between your browser and the site is encrypted. Anyone, including a fraudster, can obtain a free certificate in minutes, and most fake booking sites display a valid one. Treat the padlock as basic hygiene and check the domain itself instead, including the part before the first slash, plus the domain age and the hotel’s real website.
What should I do if I already paid a suspected fake hotel booking website?
Act within the hour. Contact your card issuer and ask for the transaction to be disputed, then report the site to the platform if it was listed there and to a consumer-protection body such as the BBB Scam Tracker, Action Fraud in the UK or the FTC in the US. Report the card as compromised if you entered full card details on a page you now distrust. Keep every screenshot, because the site will usually vanish within days.
Are very cheap hotel rooms always a scam?
No, but treat a price far below the market as a signal rather than a bargain. Real seasonal discounts and last-minute rates exist. The question is whether you can explain the gap once taxes, resort fees and any service charges are added. If the total is itemised, the property exists at the stated address and the front desk confirms your dates, a low rate is just a low rate.
How can I verify a hotel reservation received by WhatsApp or email?
Do not reply on the same channel and do not use any number or link in the message. Search for the property yourself, open its official domain, and find the contact details there. Call the front desk and ask whether a reservation exists under your name for those dates. A matching reservation number proves nothing, because scammers often hold genuine booking data copied from an earlier message.
Which payment methods should I avoid on an unfamiliar hotel website?
Avoid wire transfers, direct bank transfers, prepaid or gift cards, and cryptocurrency. All four are effectively untraceable once the money moves, which means no chargeback and no dispute. Payment by card on the hotel’s own verified domain keeps a dispute route open, and a virtual card number from your bank limits the damage if the site turns out to be fake.
How do I report a fake hotel booking website?
Report it to the booking platform first if the listing sits there, since they can remove it and warn other guests. Then report it to your national consumer-protection body: the BBB Scam Tracker or the FTC in the US, Action Fraud in the UK, or your local police cybercrime unit. Include screenshots of the address, the payment request and any messages, because the domain is often taken down quickly.
Start With the Domain, Not the Photos
If you do one thing, do this: close the page, search the hotel’s name in a fresh window, find its official domain, and call the front desk on a number from that site. Ask whether they have your name and your dates. That single question catches the large majority of attempts, and it costs you two minutes.
Everything else in this guide is a refinement of the same idea: verify from a source you found yourself, not from the one asking for your money. Photographs, reviews, reservation numbers and padlocks can all be faked or copied. A phone call to the property cannot.


