Forum Moderators: open
When you check the certificate, you should be online, that way it's possible to verify that it has not been revoked - that's the theory anyway. You could also check the valid-from date and the signature date. If it's more than a few weeks old then you might reasonably conclude that it would have been reported if it was dodgy.
Naturally, you should also have anti-virus software, etc. installed. I would also check the whois domain data. If it's Europe or North America I would be more comfortable. You could also do some research on Google.
Kaled.