URL check

Before you pay on a site you don't know, see what public data says about it.

You enter an address; from publicly available data we pull the signals that commonly appear on fraudulent sites — and show them to you right away. It works for any address: someone else's shop you are checking before you buy, or your own site. We guarantee nothing — the check shows what stands out, never that a site is safe.

What we check

All from publicly available data — we only read the page, we touch nothing.

The check is external and passive: we open the page in a real browser, just like your customer, and ask public registries about the domain. That way we also see what loads via JavaScript — so we don't flag an honest shop as suspicious just because its content is drawn in the browser. We probe nothing actively and change nothing. Every single finding is a fact you can verify yourself.

Domain age and term

The strongest single signal. Scam shops typically live for weeks. We check when the domain was registered, for how long it is paid, and who the registrar is.

Company ID and trader identity (for .hr)

Croatian law requires a trader to publish its company name, address and OIB. For .hr sites we check whether an OIB is listed at all and whether it is mathematically valid. We cannot check foreign traders this way, but we look at the other signals.

Payment method

When the only option offered is bank transfer or crypto, with no recognisable card processor, there is none of the protection a card gives (chargeback) — a common pattern in fraud.

Who is behind it, and how to reach them

Whether the trader's details are published — address, company, phone, e-mail on its own domain — or the contact is just a form with no details at all. We also check whether the domain can receive mail (MX) and whether the shop has its mandatory pages (terms, returns/complaints).

Imitating well-known names

A domain that mimics a well-known brand with a small change (a hyphen, a swapped letter, a different suffix, punycode) to look like the official site.

Certificate and first appearance

When the TLS certificate was issued and when the site was first archived on the Wayback Machine — an independent confirmation of age, resistant to a forged WHOIS.

Limits of this check

What the check does not claim.

It does not say a site is safe

The best possible result is “nothing obvious stands out” — never “safe to buy from”. A properly registered company can still defraud, and a new shop can be honest. We give no green light.

It does not say a site is a scam

We state the facts we verified and what they usually mean, and leave the judgement to you. “The domain is 11 days old, has no company ID, takes payment by transfer only” — those are facts, not a verdict.

It works on others' sites and your own

We ask you to prove nothing and to sign in to nothing — the check only looks at what is public. So it works for a site you are checking before buying, and for your own.

It only sees what is public

An external check cannot see everything. An honest trader whose site looks suspicious here is usually missing the trust signals buyers and regulations expect — and that can be fixed.

Not sure about a site? Check it before you pay.

Enter an address and get a finding from public data in a few seconds. No sign-up.

Run the check