The coupon space attracts bad actors because the promise of a discount lowers people’s guard. Most fake codes waste your time and nothing more, but a handful of patterns are genuinely dangerous. These are the ones we would tell a family member to watch for.
1. A site asks for card details to "unlock" a code
No legitimate coupon site needs your payment details. A discount code is a string of characters; it does not require a card to reveal. Any site asking for one is either harvesting card numbers or enrolling you in a subscription.
2. You are asked to install a browser extension to see the code
Some extensions are legitimate, but a forced install to reveal a code is a red flag. Extensions can read everything you do in the browser. If the code is real, it can be shown on the page.
3. The discount is implausible
90% off a current-generation phone does not exist. Manufacturers enforce pricing floors on new hardware. Implausible discounts are bait for phishing pages that imitate a retailer’s checkout.
4. The checkout domain does not match the retailer
Before entering any payment details, look at the address bar. Phishing pages copy a retailer’s design exactly but sit on a lookalike domain. If the domain is not the retailer’s own, close the tab.
5. You are pushed to pay by bank transfer or gift card
Legitimate retailers take cards and established payment providers, all of which give you a chargeback route. Requests for bank transfer, cryptocurrency or gift-card payment exist specifically to remove that protection.
6. Countdown timers that never actually expire
A timer that resets when you reload the page is manufactured urgency. It does not mean the site is dangerous, but it tells you something about how much the rest of its content can be trusted.
7. No contact details, no policies, no dates
A site with no company information, no privacy policy and no dates on its listings has nobody accountable for what it publishes. That is a reasonable signal to spend your time elsewhere.
If something has gone wrong
Contact your card issuer immediately and ask about a chargeback. Change any password you reused on the site involved. If you entered details on a page reached from our site, tell us as well so we can investigate the link.