Serious Discussion Norton Safe Web Is Failing to Properly Identify Phishing and Fraudulent Websites.

nickstar1

Level 19
Thread author
Verified
Top Poster
Well-known
Dec 10, 2022
930
4,561
1,768
It is extremely concerning and unacceptable for a well-known security product like Norton Safe Web to classify websites as “Safe” when those same websites are already identified as phishing or fraudulent by other security providers.The website in question is fraudulent, yet Norton’s product is telling consumers that it is safe to visit. This creates a serious security risk because users may reasonably trust Norton’s rating and proceed to a website that could potentially steal their personal information, credentials, or financial data.If Norton has not yet tested or determined the reputation of a website, it would be far more responsible to classify it as “Unknown,” “Not Tested,” or “Unrated” rather than incorrectly labeling it as “Safe.” There is a significant difference between not knowing whether a website is dangerous and confirming that a website is safe. Norton should not give consumers a false sense of security.

This is an issue that Norton needs to address, particularly if the Safe Web extension is not being maintained with the same level of attention and up-to-date threat intelligence that users expect from a major security company. If Norton cannot reliably maintain the extension and its threat feeds, continuing to present potentially fraudulent websites as “Safe” puts users at unnecessary risk.There was a time when Symantec operated Safe Web and its threat intelligence was more closely integrated with its security infrastructure. At that time, the service appeared to be much more effective at keeping website reputation information current and accurately identifying threats. Norton should seriously review how Safe Web determines website reputation, how frequently its threat intelligence is updated, and how it handles websites that have already been identified as malicious by other reputable security providers.

A security product should err on the side of protecting its users not reassuring them that a potentially fraudulent website is safe when it has not been adequately evaluated Thoughts on this?

Screenshot 2026-09-09 070516.pngScreenshot 2026-09-09 070550.png
 
It is extremely concerning and unacceptable for a well-known security product like Norton Safe Web to classify websites as “Safe” when those same websites are already identified as phishing or fraudulent by other security providers.The website in question is fraudulent, yet Norton’s product is telling consumers that it is safe to visit. This creates a serious security risk because users may reasonably trust Norton’s rating and proceed to a website that could potentially steal their personal information, credentials, or financial data.If Norton has not yet tested or determined the reputation of a website, it would be far more responsible to classify it as “Unknown,” “Not Tested,” or “Unrated” rather than incorrectly labeling it as “Safe.” There is a significant difference between not knowing whether a website is dangerous and confirming that a website is safe. Norton should not give consumers a false sense of security.

This is an issue that Norton needs to address, particularly if the Safe Web extension is not being maintained with the same level of attention and up-to-date threat intelligence that users expect from a major security company. If Norton cannot reliably maintain the extension and its threat feeds, continuing to present potentially fraudulent websites as “Safe” puts users at unnecessary risk.There was a time when Symantec operated Safe Web and its threat intelligence was more closely integrated with its security infrastructure. At that time, the service appeared to be much more effective at keeping website reputation information current and […]


Hi nickstar1, your central criticism is justified: displaying “Safe” is too definitive when Norton has not detected a threat, because users naturally read it as an affirmative assessment of the site’s trustworthiness. A more accurate label would be “No known threats detected”—but the screenshots alone do not prove that the site is fraudulent or establish why Norton and the other services disagree.

What the screenshots actually show​

Norton Safe Web gives the specific URL a green Safe rating. ScamAdviser displays several risk indicators and reports that IPQS flagged it for phishing, while also showing that DNSFilter considers it safe.

So this is not quite “Norton versus all other providers.” It is a split verdict, and several listed negatives—private WHOIS, low traffic, recent registration, use of a registrar associated with abuse—are risk signals rather than proof of fraud. Even a phishing classification from one provider can be a false positive and should ideally be confirmed using the provider’s underlying result and other independent detections.

The sales page itself certainly deserves caution: extraordinary health claims, urgency messaging, and a form requesting substantial personal information are reasons not to trust it merely because an extension shows a green tick. But judging the business practices, product claims and checkout terms is a different task from detecting malware or credential-phishing content.

Why “Safe” is the wrong wording​

Reputation systems generally work from blocklists, automated analysis, telemetry and prior observations. Not being on a product’s threat list is not evidence that a merchant is honest, nor does it validate medical claims, refund practices or payment handling.

That makes the user-interface problem important even if Norton’s database is functioning as designed:

  • Safe implies the site has been positively vetted.
  • No known threats detected describes the narrower technical result.
  • Unknown/Unrated is appropriate when there is too little reputation data.
  • A green rating should not be presented as an endorsement of the merchant.

No reputation service catches every newly created or rapidly changing page. The green badge is a detection verdict, not a certificate of good character—although the wording rather carelessly encourages users to treat it as one.

Useful next steps​

  1. Report the exact URL to Norton Safe Web for review, including the full path and query-free landing URL if possible. Reputation can differ between a domain, subdomain and individual page.
  2. Include the IPQS finding and screenshots, but describe them as conflicting classifications rather than conclusive proof. That gives Norton something specific to investigate.
  3. Avoid entering personal or payment information while the merchant’s legitimacy remains unresolved. Check the named business, physical contact details, billing terms, refund policy and product claims independently—not through links supplied by the sales page.
  4. If anyone already submitted only contact details, expect possible spam and targeted sales messages. If payment-card details or account credentials were entered, contact the card issuer or secure the affected account as appropriate.

The screenshots support a strong complaint about misleading certainty in Norton’s label. They do not yet establish whether this particular rating resulted from stale intelligence, different classification criteria or a detection failure; Norton’s review and the underlying URL-level results would be needed to distinguish those possibilities.
 
I’m aware that I can do that. However, that’s not the point. Norton should not be flagging a site like this as “Safe.” Based on the nature of the site and the potential risks involved, it should be displaying a gray or red warning instead. The issue is that Norton’s current classification gives users a false sense of security. This is exactly the kind of situation where the web protection system needs to be more accurate and appropriately cautious.
 
Norton Safe Web's "Safe" rating only means their automated systems didn't detect technical threats — specifically malware, known phishing kits, or malicious code on the page. It is not a consumer protection or business ethics rating.View attachment 299872
Correct. However, a normal user isn’t going to understand the difference. They’re likely to assume that the page is safe simply because the security product indicated that it was. Here at MalwareTips, we’re probably part of the 10% who actually understand the difference. The average user isn’t going to know that distinction, which makes it a much bigger concern especially in an age where technology is advancing and becoming more complex at an incredible pace. But that’s probably a discussion for another day.