How to identify a scam website
Scam websites usually combine several warning signs: a domain registered days or weeks ago, a name that imitates a known brand, pressure to pay quickly, payment only by bank transfer or crypto, and contact details that cannot be verified. No single sign is conclusive. Look for the combination, and always reach the real organisation through an address you already trust.
Why newly registered domains deserve caution
Fraudsters register fresh domains for each campaign because blocked domains are quickly reported. A domain created in the last few weeks is therefore a common feature of phishing and fake shops. Many legitimate businesses also launch new domains, so domain age raises caution but never proves fraud on its own. Read the domain age guide
How DNS and hosting analysis helps investigations
DNS shows where a domain points: its web servers, nameservers and mail servers. Network registration records identify the organisation that controls each IP address. Together they help investigators link sites run on the same infrastructure, find the hosting provider to send abuse reports to, and spot broken or suspended configurations. Cloud, CDN, shared or foreign hosting is normal and is not scored as risk.
Can HTTPS websites still be scams?
Yes. The padlock means the connection is encrypted, not that the owner is honest. Certificates are free and issued automatically within minutes, and most phishing sites today use HTTPS. A missing or broken certificate is a warning sign, but a valid one is not a sign of trust.
How URLForensics calculates website risk
Six independent modules run on our servers: domain registration, DNS health, hosting, email security, HTTPS and redirects, and threat intelligence. Each finding carries a fixed number of points, each category is capped (registration 15, DNS 10, hosting 15, email 10, website 20, threat intelligence 30), and the total is limited to 100. A confirmed listing of the exact URL by a threat provider sets the score to at least 85. Email configuration gaps such as missing DMARC are shown as security findings and do not count as fraud on their own. If too few checks complete, the result is Insufficient Data instead of a misleading low score.
Why a low-risk result cannot guarantee safety
The checker can only report what public records and configured threat sources show at the moment of the scan. Established domains can be hacked, new scams may not yet be listed anywhere, and the page content itself is not judged. Treat a low score as the absence of known warning signs, not as approval. For evidence in a dispute or investigation, run a full sealed domain investigation.
