Public blockchain data only — we never ask for seed phrases, private keys or upfront fees.
No wallet data stored Runs in your browser
All prevention tutorials
Prevention Tutorial 08 2026-09-15 · 8 min read
Fake Platforms How to Check if a Website Is a Scam: A 5-Minute Forensic Routine

The Site Was Three Weeks Old and Holding $2.1 Million of Other People's Money

Five minutes of checking, using tools you already have, before you type a card number.

Safety note: we never guarantee recovery and never ask for seed phrases, private keys, crypto payments or upfront unlocking fees. Anyone who does is running a second scam.
The short version

What this tutorial says in five lines

  • Domain age is the single fastest filter — most fraud sites are months old.
  • Perfect English on a landing page means nothing; the checkout tells you more.
  • Check the company from outside the site, never through links it provides.
  • A payment page that only accepts crypto or gift cards is a closing signal.
  • The absence of any negative review anywhere is itself suspicious.

Why this matters

You do not need to be technical to check a website. You need a fixed order of questions, so that you are not making a fresh judgement each time under the pressure of a deadline the site invented. This routine takes about five minutes and uses nothing but a browser and a search engine.

The five-minute order of operations

Run these in sequence and stop at the first hard failure. The order is deliberate: the cheapest, most decisive checks come first.

The routine, in order, with what each check costs and catches
OrderCheckCostDecisive when
1stDomain age and registrar30 secondsRegistered within the last year — extremely common in fraud
2ndCompany identity and registration1 minuteNo company exists, or the number belongs to a different business
3rdThe company checked from outside their site1 minuteNothing exists about them except their own pages
4thPayment methods offered30 secondsCrypto-only, gift card, or direct transfer to a person
5thIndependent reviews and complaints1 minuteA pattern of unanswered withdrawals, not a single complaint
6thTerms and contact reality1 minuteNo address, no phone that answers, a contact form that never replies
The routine, in order, with what each check costs and catches

The signals that actually predict fraud

Not all warnings are equally useful. Some are cosmetic and some are structural. The structural ones are what you should weigh, because they are expensive for a fraud to fake and cheap for you to verify.

Data

How strongly each signal predicts a fraudulent site

Relative predictive strength in published consumer-protection analyses

Crypto-only payment 94
Domain under 12 months old 88
No verifiable company identity 81
Fabricated guarantees or returns 76
No independent reviews anywhere 58
Poor spelling and grammar 22

Reading: Note the bottom row. Spelling is the signal people rely on most and it is the weakest — professional fraud operations use professional copywriters. Weight the structural signals instead.

Reading a domain like an investigator

Most lookalike domains are caught by two habits: reading the whole string, and checking the registration date.

  • 01Read the domain from the right: the part immediately before the final dot is the actual owner. "paypal.secure-login.com" is owned by secure-login.com, not by PayPal.
  • 02Look for character substitutions: doubled letters, rn for m, a zero for an O, hyphens inserted to make a wrong name read correctly.
  • 03Check the registration date. A brand-new domain presenting itself as an established business is the most common structural failure.
  • 04Check the privacy setting — legitimate small businesses do use privacy shields, so treat this as a supporting signal rather than a verdict.
  • 05Check the certificate details if you want one more data point: a free auto-issued certificate tells you nothing about the operator.

The padlock means the connection is encrypted, not that the company is honest. Every fraud site has one.

Where the money goes, by method

The payment method is the most honest part of a fraud site, because it reveals the recovery route available to you. This is worth understanding before you pay, not after.

Payment method, what it tells you, and what recovery is realistically available
MethodWhat it tells youRecovery route
Credit or debit cardNormal commerce, but no proof of honestyStrongest route — chargeback rights exist with real deadlines
Bank transfer to a companyPlausible for large purchasesWeak but real — recall is sometimes possible if reported within hours
Bank transfer to a personAlmost no legitimate business does thisVery weak — the money is a personal transfer, not a commercial payment
CryptoFrequently used because it is final and irreversibleEffectively none directly; evidence-based reporting only
Gift cardsNo legitimate business accepts them as paymentAlmost none — the code is spent within minutes
Payment app to an individualPeer-to-peer transfer, not a purchaseLimited, and only if reported very quickly
Payment method, what it tells you, and what recovery is realistically available

Before you pay, and after you pay

A short version you can keep.

  • 01Before: verify the company outside the site, confirm the payment method offers you a dispute route, and check the domain age.
  • 02Before: if anything requires urgency, treat the urgency itself as information about the seller.
  • 03After: if you paid by card and it turns out to be fraud, contact your issuer the same day. Card deadlines are short.
  • 04After: preserve everything — the site as it looked, the order confirmation, the addresses, the chat. Websites vanish and evidence with them.
  • 05After: report to IC3.gov and ReportFraud.ftc.gov, and to your national consumer body if one exists.

The visual summary

Everything above, reduced to the four stages that matter for this topic. If you only look at one thing on this page, look at this.

Infographic supporting How to Check if a Website Is a Scam: A 5-Minute Forensic Routine
How to Check if a Website Is a Scam: A 5-Minute Forensic Routine — supporting infographic
Stage map

Where this fits in the pattern

01

Before contact

Nothing has happened yet. This is when every tutorial here is most useful and costs you nothing but reading.

02

During the approach

The script is running. The verification tests in this tutorial are designed to be run here, neutrally, without confrontation.

03

At the money request

The decisive moment. Any request for funds, fees, taxes or unlock deposits is the end of the script, not a stage of it.

04

After a loss

Prevention is over; evidence work begins. Preserve, report, and never pay a second fee to recover the first.

Common questions

No. Certificates are free and automatic. The padlock confirms encryption of the connection, nothing about whether the business is honest.
Age is never proof on its own, but a domain registered within the last year is a strong signal to slow down. Established fraud operations do sometimes age domains deliberately, which is why age is one input among several.
No. Only reviews you find by searching outside the site, on platforms the operator does not control, carry weight.
Next step

Build the complaint from what you saved

Enter the details you collected and generate a formal complaint, a cover email and a legal draft you can print or file.

Primary sources and further reading

External links open in a new tab so you can verify the underlying material yourself. TrueMoneyTalk is not affiliated with these organisations.

Share this tutorial

Prevention only works if it reaches people before the contact does.

Disclaimer: this tutorial is general information, not legal, financial or recovery advice, and is not a substitute for advice from a licensed professional in your jurisdiction. Individual outcomes vary and are never guaranteed.