Before you trust a website with money, credentials, or personal data, a few minutes of open-source checking can expose a scam. This method reads a site's registration, infrastructure, and reputation to separate a legitimate business from a fraudulent one.
What you'll need
- The website's URL (do not enter any personal data yet)
- Domain tools from the Domain Names & Usernames category
- Reputation and threat sources from the Threat Intelligence category
Steps
- Check the domain's age. Look up WHOIS registration details. A domain registered days or weeks ago, especially for a "established" brand, is a strong scam signal.
- Inspect the infrastructure. Review DNS, hosting, and the TLS certificate. Cheap throwaway hosting, a mismatched or missing certificate, or a domain impersonating a known brand with slight misspellings are red flags.
- Check reputation and blocklists. Search the domain against threat-intelligence and reputation services to see whether it has already been reported for phishing, malware, or fraud.
- Read the site critically. Look for a real physical address and contact details, working policy pages, consistent branding, and reviews off-site. Scam sites often copy content, hide ownership, and pressure you to act fast.
- Verify the business exists elsewhere. A legitimate company has a footprint — social accounts with history, independent reviews, business-registry records. A brand-new site with no independent trace is suspect.
- Compare against the real brand. If the site claims to be a known company, compare its exact domain, design, and certificate against the genuine one; impersonation sites rarely match on every detail.
Common pitfalls
- Trusting the padlock alone. HTTPS only means the connection is encrypted, not that the site is honest — scam sites use certificates too.
- Entering data to "test" it. Never submit credentials or payment details to check a site; assess it from the outside.
- Judging on looks. Professional-looking sites are cheap to clone; weigh registration, reputation, and independent traces over appearance.
Verify your result
You have assessed the site when you can point to concrete signals — domain age, infrastructure, reputation, independent footprint, and brand consistency — that together support "legitimate" or "avoid". When the signals conflict or the site is brand-new with no trace, treat it as untrusted and do not share anything sensitive.