Fraudox FRAUDOX

Six checks that tell you a website is fake

The strongest check is the registrable domain: one label plus the public suffix. Then domain age in WHOIS, lifted content, payment method, and where the form posts.

Fraudox Team 4 min read

Everything on a web page can be copied except the domain it is served from. Logos, layout, reviews and a padlock all clone in minutes, so checking whether a site is real means checking what a copy cannot carry with it: which domain owns the page, how old it is, whether its content came from somewhere else, and where its forms send your data. Six checks, most under a minute, and a fake site usually fails more than one.

The six checks, in order

  1. Read the domain right to left. The real owner of a page is its registrable domain: one label plus the public suffix at the end of the hostname. In paypal.com.secure-login.xyz that is secure-login.xyz, and the paypal.com in front is subdomain text anyone holding the domain can invent. A few suffixes run to two labels, so in login.example.co.uk the owner is example.co.uk. Then read the spelling of what is left, because a swapped or doubled character and a Cyrillic letter that renders like a Latin one both survive a glance.

  2. Check how old the domain is. A WHOIS lookup, or the RDAP query that has replaced it at most gTLD registries, returns the creation date and the sponsoring registrar, and that date usually stays public even where the registrant's contact details are redacted for privacy. A domain registered days ago while presenting itself as an established bank or courier is the strongest single signal a non-expert has. The free domain scan pulls that record if you would rather not read raw registry output.

  3. Do not read the padlock as identity. A domain validated certificate, the free and automatic kind, attests to one thing: whoever requested it proved control of the domain at the moment of issue, by DNS record, by a file on the web server, or by mail to an address on that domain. It says nothing about the company named on the page.

  4. Look for lifted content. Clones are assembled by scraping. Reverse image search the hero image: if it sits on the real site, this page did not produce it. Paste a sentence from the about page into a search engine and count the sites carrying it word for word. Dead internal links and a footer still naming a different company mark a page built in a hurry to impersonate.

  5. Read the payment and contact details, not the design. Payment only by bank transfer, cryptocurrency or gift card removes your chargeback route, which is the reason it is asked for. A legitimate seller names a legal entity you can look up in a company register. A shop that moves you to WhatsApp or Telegram after one message is moving the sale where nothing is recorded.

  6. Check where the form posts. Read the form's action attribute in the page source, then watch the network tab in developer tools as you submit junk text. Many forms submit by script and carry no action, so the network tab is the reliable read. A login form for your bank should post to the bank's own domain. If the request goes to an unrelated host, a bare IP address, or a script on a third domain, that is a collection endpoint. Never type real credentials to test it.

The padlock tells you the connection is private. It does not tell you who is on the other end of it.

Signals ranked by weight

Nothing here is proof on its own; weight tracks how hard a signal is to fake.

Signal Weight Why
Registrable domain is not the brand's Strong The genuine one is already registered
Domain created days or weeks ago Strong The registration date is a matter of record
Form posts to an unrelated host Strong It shows where the data actually goes
Text and images lifted from the real site Moderate Fast to clone, fast to verify
Payment only by transfer, crypto or gift card Moderate Removes recourse by design
No checkable company identity Moderate Legitimate sellers rarely hide one
HTTPS and a padlock None Free, automatic and near universal
Polished design, logos and reviews None Copying a look costs nothing, proves nothing

Age cuts one way only: a domain registered last week is a warning, but an old one proves nothing, because expired domains with history get bought and repurposed.

Checking protects you and nobody else, because the site stays online either way. If the fake is wearing your brand, those six answers are the start of a case file: the registrable domain, the creation date, the images and text it lifted from you and the endpoint behind the form are what a host or a registrar wants in front of it before acting on a phishing takedown. Ten minutes turns a suspicion into something a provider can act on.

Seeing this threat against your brand?

Fraudox removes phishing sites, impersonation accounts, fake apps, and scam domains. You only pay for successful takedowns.