1. Check the full domain
Read left-to-right starting from the last dot. A site at 'support.brand-secure.com' is on 'brand-secure.com', not on 'brand.com'. The bit immediately before the TLD (.com / .co.uk) is the real owner.
Help · Spot fake sites
A few quick checks separate most fraudulent sites from the real thing — before you enter a password or card number.
Read left-to-right starting from the last dot. A site at 'support.brand-secure.com' is on 'brand-secure.com', not on 'brand.com'. The bit immediately before the TLD (.com / .co.uk) is the real owner.
Cyrillic and Greek letters can imitate Latin ones. If a domain looks right but the browser address bar shows it as 'xn--' something, it's a homoglyph. Hover over the address bar to see the raw form.
'Your account will be closed in 24 hours' is a fraud signal, not a service notice. Real businesses don't operate that way for security-sensitive actions, and never gate account access behind countdown timers.
Requests to pay in gift cards, crypto, or via personal bank transfer for what should be a standard merchant purchase are almost always fraudulent. Legitimate retailers accept card payments through PCI-compliant processors.
If you're unsure, navigate to the brand's site by typing the URL or using a bookmark — never via a link from the suspicious message. For banks, call the number on the back of your card; never call a number provided in the message.
A brand-new domain (registered within days) with a free SSL certificate, claiming to represent a 50-year-old company, is suspect. Tools like who.is and crt.sh show registration and certificate history.
Search the domain plus 'scam' or 'review' — fraud victims often post about active scams quickly on Reddit, Trustpilot, and forum sites. Absence of any results for a 'global brand' is itself a red flag.
Low-resolution logos, mismatched fonts, broken stock photos, and grammatical errors in product copy are all reliable indicators. Modern scams are slicker than they used to be, but the long-tail still cuts corners.
On a suspected phishing page, enter a deliberately wrong password. A real login form will reject it. A phishing page often accepts anything and proceeds to the next step.
Submit the URL to FraudRadar and to the impersonated brand. A single early report often prevents many later victims, and feeds the pattern detection that surfaces the next wave of clones.