Quick picks
Here are the ten safe online shopping tips, in the order you’d actually use them while browsing and paying:
- Read the full URL letter by letter, not just the padlock
- Confirm a real Sri Lankan phone number, address, and working email
- Prefer a credit card or virtual card over your debit card
- Insist on a 3D Secure OTP at checkout
- Never let a site save your CVV
- Skip “deals” that arrive by DM or WhatsApp — open the site yourself
- Read the return and refund policy before you click Pay
- Use a unique password plus 2FA on every shopping account
- Screenshot the confirmation page the second the order goes through
- Reverse-image-search anything that looks suspiciously cheap
The rest of this post expands each tip with what to check for, and closes with an anonymised case from our support queue at Kapruka.
What are the 10 safe online shopping tips?
1. Read the full URL letter by letter, not just the padlock
The padlock only tells you the connection is encrypted. It does not tell you the site is legitimate. Scam sites buy HTTPS certificates for a few dollars, so a padlock alone means nothing.
Read the domain out loud. kapruka.com is not the same as kapruka-lk.shop or kaprukaa.com. On mobile browsers, tap the address bar to expand the full URL — homograph tricks (an “a” swapped for an “а” from another alphabet) are easier to spot at full width.
2. Confirm a real Sri Lankan phone number, address, and working email
A trustworthy Sri Lankan online shop publishes:
- A local landline or hotline you can actually ring during business hours
- A physical address in Colombo or another named city, not just “Sri Lanka”
- A working support email (send a test question before you buy anything expensive)
If the only contact is a WhatsApp number with a foreign country code and no address, walk away. You can compare against a known-good example — Kapruka customer support publishes a Sri Lankan hotline plus email, which is the pattern to look for.
3. Prefer a credit card or virtual card over your debit card
Debit cards pull money straight from your account. If the transaction is fraudulent, your money is gone while the dispute takes weeks. Credit cards let you file a chargeback while the bank freezes the disputed amount — you’re arguing over money the bank is holding, not money already spent.
Better still, most Sri Lankan banks (Commercial Bank, HNB, Sampath, DFCC) now issue virtual cards you can generate for a single transaction and cancel the moment it clears. Use those for any site you’re using for the first time.
4. Insist on a 3D Secure OTP at checkout
3D Secure is the extra step where your bank texts or app-notifies you a one-time password before the card goes through. If a Sri Lankan checkout takes your card details and completes the payment without ever asking for that OTP, that’s a red flag on both the site and the payment gateway behind it.
Legitimate payment gateways used locally — LankaPay, WebXPay, PayHere, Stripe, and the international schemes — all support 3D Secure. If you don’t see it, cancel and pay a different way.
5. Never let a site save your CVV
The three digits on the back of your card should never be stored. It’s against PCI DSS rules — the payment card industry security standard maintained by the PCI Security Standards Council. If a checkout offers to “remember your CVV for next time,” it is either non-compliant or lying about what it stores. Either way, don’t tick the box.
Saving the card number is fine on reputable sites (they store a token, not the number). Saving the CVV is not.
6. Skip “deals” that arrive by DM or WhatsApp — open the site yourself
A very common pattern I see in support tickets: a shopper gets a Facebook or WhatsApp forward with a “70% off” flash sale link. The link is a lookalike domain. The site is a clone of a real Sri Lankan store, hosted for a week, pulled down after collecting a few dozen card numbers.
Rule of thumb: if a promotion is real, it’s on the real site. Open a fresh tab, type the store’s domain yourself, and check the promotions section. If the “deal” isn’t there, it isn’t real.
7. Read the return and refund policy before you click Pay
Every legitimate Sri Lankan online store publishes a return, refund, and cancellation policy in plain language. It should tell you:
- How many days you have to raise a return
- Which categories are non-returnable (perishables, personalised items, sealed hygiene products)
- Whether refunds go back to card or as store credit
- How long refunds take to reflect (typically 5–14 working days on card refunds locally)
If the policy page is missing, or reads like machine-translated boilerplate with no company name, treat it as no policy at all.
8. Use a unique password plus 2FA on every shopping account
The single biggest cause of “someone hacked my account” tickets I’ve reviewed isn’t the shop being breached — it’s password reuse. A shopper used the same password on a forum that leaked in 2019, and attackers tried the same combo on their shopping account.
Use a password manager (Bitwarden and 1Password both have free tiers) so every site gets its own password, and turn on two-factor authentication wherever it’s offered. On email especially — because whoever controls your email controls every password reset.
9. Screenshot the confirmation page the second the order goes through
Not the confirmation email. The confirmation page. Emails can be delayed, spam-filtered, or lost.
Capture the order number, date, delivery address, and total shown on screen. If a dispute comes up later — wrong item, missing delivery, double charge — that screenshot is the strongest piece of evidence you have. On electronics in Sri Lanka especially, where invoice values are higher, this habit has saved customers hours of back-and-forth.
10. Reverse-image-search anything that looks suspiciously cheap
If an iPhone, PlayStation, or branded perfume is listed at a fraction of the going rate on a site you’ve never used, drag the product image into Google Images or TinEye. Scam listings often reuse a single stock photo across dozens of fake stores.
If the same image shows up on ten unrelated “sale” sites and no manufacturer page, the listing is bait. Real inventory has real photos.
Which tips matter most if you only do three?
If you’re rushed and only running three of the ten, do these:
| Priority | Tip | Why it’s the biggest lever |
|---|---|---|
| 1 | Read the full URL (Tip 1) | Blocks the most common scam vector — lookalike domains |
| 2 | Insist on 3D Secure OTP (Tip 4) | Blocks card-not-present fraud even if the site is compromised |
| 3 | Use a credit or virtual card (Tip 3) | Limits your loss and preserves chargeback rights if something does go wrong |
The other seven still matter — they just have smaller individual impact than these three.
What does a real Sri Lankan online shopping scam look like?
A customer messaging our support last year had received a “Kapruka clearance sale” link on WhatsApp — 60% off flowers for a birthday. The link went to a domain with two extra letters in the middle. She noticed at the payment step because the checkout skipped the OTP entirely and asked her to “enter CVV twice for verification” — two red flags at once (Tip 4 and Tip 5).
She closed the tab, came to the real site, and ordered birthday gift ideas through the normal checkout. The clone site was reported and taken down about a week later, but by then it had already collected card details from other shoppers who hadn’t noticed the missing OTP.
Two tips — read the URL, and expect a 3D Secure prompt — would have stopped every one of those losses. No online shopping is 100% scam-proof, but running through this ten-point list closes off the majority of routes attackers actually use in Sri Lanka today. That is what makes these safe online shopping tips worth memorising.
Frequently asked questions
How can I tell if a Sri Lankan online store is legitimate?
Check three things fast: the full URL matches the brand exactly, there’s a Sri Lankan phone number and physical address on the contact page, and checkout triggers a 3D Secure OTP. A store missing any of these is not one to trust with card details.
What should I do if I paid a scam site with my card?
Call your bank’s card hotline and ask them to block the card and open a dispute. The faster you report it, the higher the chance of a chargeback. Also file a complaint with the Sri Lanka Consumer Affairs Authority so the site can be flagged.
Is it safe to save my card on a shopping website?
Saving the card number itself is generally safe on reputable Sri Lankan sites because they store a bank-issued token, not the raw number. Saving the CVV is never safe and is against PCI DSS rules — no legitimate site should offer that option.
Why does my bank keep asking for an OTP at checkout?
That is 3D Secure working as intended. Your bank sends the one-time password so the transaction cannot complete on your card without a second factor you control. If a checkout skips this step, treat it as a warning sign, not a convenience.
Can I shop safely from a public WiFi network?
Public WiFi is fine for browsing but not for entering card details. Use mobile data or a trusted network when you reach the payment step. If you must use public WiFi, use a reputable VPN so your session traffic is not readable on the local network.
Related reading on Kapruka
About the author
Akthar is the Digital Marketing Manager at Kapruka Holdings PLC.
He has spent over four years at Kapruka working across marketing analytics, customer experience, and operations — with direct involvement in diaspora gifting logistics, payment integrations, and customer support workflows. The perspectives in his writing come from running these systems day to day, not from theory.
You can reach Akthar by email or connect with him on LinkedIn.