Private digital intelligence bureau Lawful OSINT — Cyber monitoring — Due diligence
Researcher reconstructing the ownership and public history of a suspicious website

Web fraud guide · 11 min

Check a suspicious website without clicking through everything or mistaking polish for legitimacy.

A padlock, professional design or high search position does not establish trust. Start with the exact address, claimed entity and observable history.

Published 15 September 2026Reviewed by IIS editorial team

At a glance

Four rules for a useful review.

  • Read the address character by character.
  • Do not submit data as a test.
  • Compare identity, domain and history.
  • Preserve redirects and observed pages.

Step-by-step method

A reproducible path from question to conclusion.

  1. 1

    Isolate the exact address

    Copy the URL without opening it where possible. Identify subdomains, subtle misspellings, lookalike characters, shorteners and tracking parameters.

  2. 2

    Verify the claimed identity

    Compare legal name, address, contacts, required notices and payment details with appropriate official sources.

  3. 3

    Reconstruct public history

    Review accessible registration traces, certificates, archives and content changes. A recent domain is not proof of fraud, but it changes confidence.

  4. 4

    Observe public relationships

    Look for related domains, redirects, official profiles, advertising and warnings from identifiable sources.

  5. 5

    Assess the requested journey

    Consider whether the site asks for credentials, payment, software, documents or urgent action. More sensitive requests require more independent verification.

  6. 6

    Decide without further interaction

    Classify the site as coherent within the observed scope, doubtful, avoid or undetermined. Continue a legitimate task only from an independently found official site.

A domain is an identifier, not decoration

The meaningful part of a URL can be hidden behind a long subdomain or reassuring phrase. Verify the registered domain and extension, then restart from a known official source.

HTTPS protects data in transit to the visited site; it does not certify the business, offer or intention.

Look for overall coherence

A site can copy text, logos and reviews. Compare contacts, history, legal pages, official channels, payment methods and independent presence.

One anomaly deserves checking; several independent inconsistencies combined with urgency or a sensitive request justify stopping.

Research without unnecessary exposure

Do not install a file, allow notifications, enter data or call the supplied number before legitimacy is established.

Professional review should use an appropriate environment and clear mandate. This guide remains limited to defensive public observation.

Common pitfalls

Four shortcuts that weaken the result.

Trusting the padlock

HTTPS encrypts the connection but does not guarantee legitimacy.

Testing with false details

Interaction may confirm that your address or device is active.

Believing embedded reviews

They can be selected, copied or fabricated. Find the source and date.

Making an unsupported accusation

Preserve observable facts and use proportionate language.

Practical questions

Frequently asked questions.

Is a new domain fraudulent?

No. It is a contextual signal to compare with identity, journey, content and other sources.

Does HTTPS prevent phishing?

It protects transport to the domain visited, including a domain controlled by a fraudster.

How can I check without clicking?

Inspect the address, research the organisation separately and use suitable public tools without submitting data to the site.

Editorial scope

Written and reviewed by Internet Intelligence Service on 15 September 2026. This educational guide describes a lawful, defensive method. It is not legal advice, an emergency service or authority instruction.