Fake online shops have become an industrial product. Kits are sold that clone a real store's layout, fill a catalogue with stolen product photographs, and wire up a payment form that either takes your card details or collects money for goods that never ship. The site will look fine. That is the entire investment.
What the operators cannot cheaply fake is history. A domain registered eleven days ago is eleven days old no matter how polished the homepage is. This checker reads the evidence that sits underneath the design.
The single most useful signal: domain age
Scam shops are disposable. They are registered, run hard through a burst of social media advertising, and abandoned once the chargebacks and complaints arrive, usually within one to three months. A genuine retailer, even a small one, has been on its domain for years.
Scanify reads the registration date from the domain's registry record and shows you exactly how old it is. Treat the result roughly like this:
- Under 30 days. Extremely high risk for anything that takes payment. There is almost no legitimate reason for an established-looking shop to sit on a brand-new domain.
- One to six months. High risk. Possible for a genuine new business, but you should find independent evidence before paying.
- Six months to two years. Worth a second look. Check the other signals and look for reviews that predate the site.
- Over two years. Not proof of honesty, but it rules out the disposable-storefront model that drives most shopping fraud.
What else the checker looks at
Google Safe Browsing
If Google has already classified the site as deceptive or as hosting malware, the result says so immediately. A listing here is close to conclusive.
Certificate and encryption
Scanify reads the TLS certificate: whether it is valid, who issued it and whether it matches the hostname. Be clear about what this proves. A padlock means the connection is encrypted, not that the business is honest; free certificates are trivial to obtain, and nearly every scam site has one. A certificate that does not match the hostname, or a checkout served over plain HTTP, is a serious warning.
Lookalike and impersonating names
Many fake shops trade on a real brand's name through a near-miss domain: an extra word, a hyphen, a digit standing in for a letter, or an unusual ending attached to a famous name. Scanify detects brand names sitting in the wrong part of a hostname and digit substitutions designed to read as letters at a glance.
Redirects
If the address you were given quietly forwards somewhere else, you will see the full chain. Advertising links that bounce through several unrelated domains before landing on a storefront are worth understanding before you spend money.
The manual checks a scanner cannot do for you
- Compare the price to reality. A current-season item at seventy percent below everywhere else is the oldest signal there is. If the deal only exists on this one site, the deal is the bait.
- Look for a real address and company number. Legitimate retailers publish a registered company name, a number and a physical address. Search that company name separately. A missing or unsearchable identity is damning.
- Test the contact route. A contact page with only a web form, a Gmail address or a phone number nobody answers is a deliberate choice.
- Read the policies for copy-paste text. Scam sites paste generic returns and privacy policies. Mismatched currencies, another shop's name left in the text or impossible terms all give it away.
- Check how they want to be paid. This is close to decisive. Bank transfer, cryptocurrency, gift cards or a "friends and family" payment all remove your ability to reverse the transaction. That is why they are requested.
- Search for reviews off-site. Look for the shop's name plus the word scam on a search engine and on discussion forums. Reviews hosted on the shop's own pages are worth nothing.
- Reverse-search a product photo. Stolen imagery is standard. If the same photograph appears on dozens of unrelated stores, the catalogue is not real.
If you have already paid
- Contact your card provider today and ask about a chargeback. Card payments carry protections that transfers do not.
- Do not send anything further. A common follow-up is a request for an extra customs or delivery fee to release goods that do not exist.
- Change any password you reused on that checkout. Credentials entered on scam sites are tried elsewhere within hours.
- Watch the card closely and consider replacing it. Details are frequently sold on rather than used immediately.
- Report it. In the United States, reportfraud.ftc.gov. In the United Kingdom, Action Fraud. Reports feed the blocklists that protect the next person.
Why a clean result is not a guarantee
These checks catch the disposable storefront, which is the dominant pattern in shopping fraud. They cannot detect a business that is real but bad at shipping, a legitimate site that has been compromised in the last few hours, or a fraud running on an aged domain bought specifically to defeat age checks. Use the verdict as one strong input, not as permission to stop thinking.