RepublicCyberIntel

Trusted site or trap? A 90-second inspection anyone can run

20 September 2026

Magnifier inspecting a suspicious lookalike domain

Why "looks professional" means nothing

Scam kits now ship pixel-perfect clones of banks, marketplaces, and government portals in minutes. Design is no longer evidence. These five checks take ninety seconds and catch most traps.

The 90-second inspection

  1. Read the domain backwards. The registrable core sits just left of the public ending: sbi.**co.in** real vs sbi-kyc.**xyz** trap. Hyphens + urgency words (verify, suspend, offer) + odd endings (.xyz, .top, .sbs) = walk away.
  2. Check the age. Real businesses are rarely days old. Our free domain check shows registrar and creation date via public RDAP records — a "bank" born last Tuesday is not a bank.
  3. Check certificate history. crt.sh lists every public certificate for a domain. Established sites have history; throwaway scam domains have none.
  4. Look for humans. Real businesses have verifiable addresses, working phone numbers answered in their name, and GSTIN/company records you can cross-check. Scam sites have forms that go nowhere and chat widgets staffed by urgency.
  5. Feel the pressure. Countdown timers, "only 2 left", advance-payment-only, no-COD-ever: pressure is the payment method of fraud. Legitimate sellers survive your delay; scammers cannot afford it.

Worked example

http://sbi-kyc-verify-urgent.xyz/login?session=8491 — fails all five: http (not encrypted), hyphens + urgency words, .xyz ending, days-old domain, pressure framing. Paste anything like it into the scam-link scanner and watch it light up.

The whitelist habit

Bookmark the five sites you bank, pay tax, and shop on — and always arrive via bookmarks or the official app, never via SMS, email, or search ads (scammers buy ads on their own brand-names-plus-typo). Trust is a route, not a feeling.

Trusted vs Suspicious Websites: 90-Second Safety Check — Republic CyberIntel — Republic CyberIntel