Domain and destination
Look at the actual domain, not only the logo or visible link text. Misspellings, extra words, strange subdomains, shortened links, and lookalike characters deserve independent verification.
Free first check
Spot pressure, money, identity, and access signals in a redacted example.
Paid early access · USD 19 reference
Turn one redacted situation into a one-page decision brief, official routes, and 15-minute / 24-hour actions.
Clear boundary
No guaranteed verdict or recovery promise. Scope and timing come before payment.
A polished design, padlock, or familiar logo is not proof. Use a layered first check before you sign in, buy, download, call, or share personal information.
Check site status with Google Safe Browsing →No single signal proves that a website is legitimate. Several pressure or identity mismatches together are a reason to stop.
Look at the actual domain, not only the logo or visible link text. Misspellings, extra words, strange subdomains, shortened links, and lookalike characters deserve independent verification.
Countdowns, “account closed” warnings, limited-time prices, forced chat, and urgent payment requests are designed to remove your time to verify.
Never enter a password, verification code, bank login, card number, or remote-access approval just because a page asks for it. Open the known official app or site yourself.
Compare the company name, address, support route, return policy, and contact details with independent sources. A contact page alone is not proof.
Unusually low prices, guaranteed returns, crypto-only payments, gift cards, overpayment stories, or a request to move off-platform are strong warning signs.
Search for the domain and company name separately. Read criticism carefully and remember that reviews, badges, and social profiles can be copied or manipulated.
If the address arrived by text, email, DM, or an unexpected ad, do not use that link. Find the service through a bookmark, the official app, or a domain you already know.
Use Google Safe Browsing site status as one signal. A clean result is not a guarantee, and a warning means you should not proceed.
Contact the bank, store, platform, employer, or person through information you found independently. Never use the phone number or support link supplied by the suspicious page.
If a suspicious text or email led you there, remove private data and use the global message checker guide for a first-pass review.
Do not test a site by making a small payment or creating an account. If the identity, request, or payment route is still uncertain, treat that uncertainty as a stop signal.
New scam domains may not be listed yet, and legitimate sites can be compromised later. Re-check important claims through the official organization.
Encryption protects the connection; it does not prove the operator is honest, the store will deliver, or the payment request is legitimate.
Copied testimonials, fake badges, followers, and sponsored search results can make a site look established. Look for independent evidence and a known contact route.
For phishing warning signs and account protection, see the FTC phishing guidance.
Stop interacting with the suspicious site. From a trusted device, change exposed passwords through the official service, contact your bank or payment provider, preserve evidence, and use the official reporting route.
Follow the post-click recovery checklist → Find official reporting routes →
Send this public checklist to someone who is about to buy, sign in, or pay. Do not forward passwords, payment details, codes, or private screenshots.
Use a redacted message first check, then verify through the official source before you click, pay, or sign in.
Open the global first-check guide →