Most advice about fake websites tells you to look at the page: check the spelling, look for the padlock, watch for pressure tactics. That advice is sound, but it has a weakness. Modern scam sites are copied pixel for pixel from the real thing, and a free certificate gives any fraudster the same padlock your bank has. The page itself has stopped being reliable evidence.
The domain behind the page is far harder to fake. Every registered domain carries a public record of when it was created, who registered it, and which name servers it uses. That record is where a convincing fake usually falls apart.
The single most useful signal: age. A genuine retailer, bank, or courier has held its domain for years, often decades. Scam domains are disposable. They are registered in bulk, used for a few weeks until they are blocklisted, and abandoned. If a site asking for your card details was registered eleven days ago, nothing else about it matters. You can check this yourself with our WHOIS Lookup tool: paste the domain and read the creation date.
What else the record tells you:
- Registrant details: Privacy services are common and legitimate, so redacted contact details are not proof of anything on their own. But a large, established company hiding behind a privacy shield on its main commercial domain is unusual.
- Expiry date: Serious businesses register domains years in advance. A domain set to expire twelve months after registration suggests nobody expects to still be using it.
- Registrar and country: A supposed national postal service registered through a budget offshore registrar is worth a second look.
- Name servers: If a site claiming to be a major brand resolves through free hosting, the brand almost certainly has nothing to do with it.
A worked example. You receive a message about a held parcel pointing to a site that looks exactly like your courier. Rather than clicking, copy the domain out of the link without opening it, and look it up. If the real courier has held its domain since 2003 and the one in your message was created last Tuesday, you have your answer in under a minute, without ever visiting the page.
Watch for look-alike domains. Scammers register names that read correctly at a glance: an extra hyphen, a swapped letter, a plausible subdomain, or a familiar brand placed where it looks like the main domain but is actually part of a longer address. Read a web address from the right: the real domain is the part immediately before the first single slash. Everything to the left of it can be anything the scammer wants.
What a lookup will not tell you. Domain age is a strong signal, not a verdict. Criminals do buy aged domains, and legitimate new businesses do exist. A recently created domain is a reason to stop and verify through a channel you already trust, not proof of fraud by itself. Used alongside the usual checks, though, it catches a large share of throwaway scam sites before they get anywhere near your details.
If you want to see what your own connection reveals while you are investigating, our Privacy & Leak Check and Browser & Connection Info tools show exactly what a website learns about you the moment you arrive.