Loading report for

How we check a website

A domain report is our current view of a website, built from every scan we have run against it. It updates as evidence arrives, and records when a verdict changes.

Every scan opens the site in a real browser and records what it does: the redirects it follows, the resources it loads, where its forms send what you type, its certificate, its hosting and its domain age. We compare the page against the sign-in screens and icons of the brands most often impersonated, and we check it against public threat-intelligence sources.

No single check decides a verdict. Each one contributes a bounded amount, so a result always rests on several independent signals agreeing — and every signal that moved the score is listed on the report, in plain language.

If a site blocks automated checks and we cannot see its real content, we say so and withhold a verdict rather than calling it safe. An absence of findings is not the same as a clean result, and we do not present it as one.

What a scan cannot tell you

An automated check inspects how a website is built, not how the people behind it behave. A shop that takes payment and never ships looks technically flawless to us: valid certificate, clean reputation, no phishing markers. So do advance-fee frauds, fake investment schemes and most romance scams, which move to messaging apps before any money changes hands. For those, first-hand accounts from people who were targeted are the only real evidence, which is why reports from the public sit alongside our own findings and are reviewed before they are published.

A verdict here describes what we observed at the time shown, and it can change. If you run this site and believe a finding is wrong, you can prove control of the domain and publish a response alongside the report. If you were targeted through a link, reporting it to the hosting provider and registrar listed under “Report it” is usually the fastest route to getting it taken down.