Suspicious websites and URLs
A link can look official while pointing somewhere else. Use these checks before you enter payment details — and submit the URL to Assayer if you want an evidence report on what you can see.
Hostname and visible-brand mismatch
Compare the brand shown on the page with the hostname in the address bar. A page that says “Northline Outlet” but loads from northline-deals-shop.example deserves extra scrutiny. Assayer may flag when visible brand text does not align with the registered domain.
Next step: Find the brand’s official site through a search you start yourself — not through a link in the suspicious page — and compare contact details and return policies.
Lookalike characters and misleading subdomains
Scammers register domains that resemble trusted names: swapping 0 for o, 1 for l, or doubling letters. They also use subdomains such as paypal.secure-pay.example so “paypal” appears before the real domain.
Read the full hostname right-to-left: the registrable domain is what matters, not the leftmost word.
Next step: Type the official domain manually or use a saved bookmark instead of following ad or message links.
HTTPS protects transport, not trust
A padlock means your connection to that server is encrypted. It does not mean the operator is honest, the products are real, or refunds will be honored. Assayer treats HTTPS as one observable fact — not proof of legitimacy.
Next step: Judge the business evidence: contact paths, refund policy, seller identity, and whether payment goes to the entity you expect.
Redirects
Short links and redirect chains hide the final destination. A legitimate marketing link can still land on an impersonation page if an account was compromised.
Next step: Before paying, expand shortened links where possible, note each hop, and stop if the final hostname does not match the seller you intended.
Contact, refund, and business-information checks
Look for concrete business signals before checkout:
- Physical address and working phone line reachable from the site itself
- Refund, return, and shipping terms that match the brand you think you are buying from
- Consistent naming across the footer, invoice preview, and payment screen
- Support email on the same domain as the store — not only a web form with no reply path
Missing or copied policy text is a reason to pause — not automatic proof of fraud, but a gap Assayer may list as missing information.
Pressure to pay through irreversible methods
Pages that push gift cards, cryptocurrency, wire transfers, or peer-to-peer apps with no purchase protection are high-risk regardless of how professional the design looks. Assayer commonly flags these payment patterns in visible text.
Next step: Prefer payment methods with dispute options for online purchases. If only irreversible methods are accepted, treat that as a stop sign until you verify independently.
Safe independent verification
- Open the seller or brand site from your own search — not from the suspicious link.
- Call or email using contact details listed on the official site.
- Compare prices and SKU details; extreme discounts alone are not proof of fraud, but they raise questions when paired with other gaps.
- Submit the URL plus any checkout screenshot to Assayer before sending money.
What a Google Web Risk no-match does and does not mean
When Assayer includes a URL, it may run Google Web Risk Lookup. If no threat is listed, Assayer adds a limitation: that only means no known threat was on Google’s lists at check time.
- Does not mean: the business is real, the product will ship, or the page will stay benign later.
- Does mean: Assayer found no listed malware, phishing, or related threat entry for that URL at that moment — one input among many.
A threat-list match is serious warning evidence. Absence of a match is not validating evidence by itself.