Website Scam Checker
Worried about a website or link? See how Tracidar will check it — and what you can look for right now.
Live website checking is not yet available. Nothing entered here is analyzed, transmitted or saved.
Check a website or link
What you type stays in this page — nothing is sent anywhere or saved.
Evidence model
The website evidence map
One website, several kinds of evidence, one assessment. Tracidar is designed to combine these sources — the live checks aren't available yet.
- One website or link
Domain & address
Registration & ownership
When the domain was registered and what's on record.
URL patterns
Look-alike spellings and odd subdomains deserve a closer look.
Connection & behavior
HTTPS & connection
Encryption and certificate details — planned as a weak positive, never proof of trust.
Redirect behavior
Where links actually lead, considered before you ever click.
Reputation & page
Threat & reputation
Known threat lists and reputation sources — a match is strong; no match means unknown.
Page & form signals
Credential and payment forms, contact details and page claims.
Identity & brand match
Whether a page claiming a known brand sits on that brand's official domain.
Unknown / missing evidence
What couldn't be verified — reported as unknown, part of the assessment.
- Evidence combinedAssessment
One of five risk bands — with the evidence behind it.
Read the actual domain
The part that matters most sits just before the first slash. Everything else is easy to decorate.
Reading the results
How to read a Tracidar assessment
Tracidar's result model uses five classifications. Each one comes with the evidence behind it — not just a word.
Low Risk — No strong risk signals were observed.
Low Risk means fewer concerning signals were found within the evidence available. It is not a promise that a website is safe — evidence can change, and some risks are hard to see from outside.
Caution — Some signals deserve attention.
One or more signals suggest slowing down and checking further — for example, a very new domain combined with limited reputation history.
Suspicious — Several concerning signals.
Multiple signals point the same way — enough to treat the website or link with real care until you can verify it through other channels.
High Risk — Strong concerning signals.
Strong evidence of harmful behavior — such as a confirmed threat-list match or clear impersonation. This is the strongest warning Tracidar's model is designed to give.
Insufficient Evidence — Not enough evidence to assess.
A legitimate outcome, not an error: there isn't enough reliable information to support a meaningful assessment. The honest answer is to stay cautious and verify yourself until more is known.
Tracidar won't produce a percentage or a “confidence meter.” Results are a band plus the evidence behind it — so you can judge the reasoning, not just the verdict.
Misread signals
Three things that don't prove a site is safe
Each of these is useful in context — and each gets oversold every day. Here's what they really tell you.
HTTPS is not proof of trust
A padlock means the connection is encrypted — it doesn't prove the owner is trustworthy, the business is real, or the site isn't a scam. Many scam sites have valid certificates. HTTPS still matters for connection security, so don't ignore it — just don't read it as a character reference.
A new domain is not proof of a scam
A very new domain can deserve extra caution — but new businesses start with new websites. And an old domain isn't proof of safety either: domains change ownership, get compromised or get repurposed. Age is context, not a verdict.
No bad reports doesn't mean safe
No reports, no records, little history — that generally means UNKNOWN, not SAFE. Absence of reputation information is not proof either way, and a real result will say so plainly instead of inventing a verdict.
Weighing the evidence
Evidence strength
Not every signal means the same thing. A future assessment is designed to weigh stronger evidence more heavily — and never let one weak signal become a verdict.
Stronger evidence
A known malicious or phishing reputation · Confirmed harmful behavior · Strong impersonation evidence
Contextual evidence
A very new domain · Brand-and-domain mismatch · Unusual redirects · Credential or payment requests
Weak, context-only evidence
Private registration details · Low traffic · Shared hosting · An ordinary HTTPS certificate · Certain TLDs · Grammar and style
The core principle: one weak signal should not automatically make a website a scam. Several independent signals pointing the same way can matter more.
Warning signs
Common suspicious website patterns
These scenarios deserve a closer look, especially when several appear together. None of them proves a scam on its own — they're reasons to slow down and check further.
Look-alike domains
The page looks like Example Bank — the domain doesn't. Read the actual domain, not just the logo or the page design.
Unexpected redirects
A link that lands somewhere other than where it appeared to lead deserves a second look.
Urgent credential requests
Urgency plus an unexpected request for your credentials deserves caution.
Unusual payment requests
Unexpected or hard-to-reverse payment methods can deserve caution — slow down.
Brand and domain mismatch
The visible business identity and the actual domain don't align. Find the official domain independently and compare.
Pressure and too-good offers
Countdowns and extreme discounts are designed to stop you thinking. Pressure is a reason to slow down — not proof of a scam.
Do it yourself
Website checks you can do right now
A minute of checking, in three stages — no scanner needed, and it works in any browser.
Before you visit
Inspect the domain closely — swapped letters and extra words hide in plain sight.
Preview where links actually lead before you click.
Find the official domain independently, then compare.
While you're on the site
Question unexpected login or payment requests.
Verify contact details through a channel you trust — not the page itself.
Notice redirects and identity mismatches.
Before you pay or sign in
Question unusual payment methods — gift cards, crypto, direct transfer.
Search for independent information about the seller.
Slow down when you're being pressured.
Pause before entering credentials or card details.
Example / Demonstration
What a real website result is designed to explain
This is a demonstration using fictional data. No website was analyzed. The preview shows the shape of a future assessment, not a result for anything you enter.
Caution
Some signals deserve attention.
Concern — registered a few days ago. Very new domains are common in short-lived storefronts. Newness alone isn't proof of a scam — it's a reason to slow down.
Positive — a valid HTTPS certificate. The connection is encrypted. HTTPS doesn't make a site trustworthy, but it's better than nothing.
Unknown — no reputation history. No record was found for this domain. That's uncertainty, not proof of anything.
Recommended next action: Don't enter payment details yet. Verify the store through a channel you trust independently — or wait until more is known.
Fictional demonstration — not a real check. No website was analyzed.
A real result is designed to explain:
Classification — one of the five risk bands
Why it was reached — the concerns behind the band
Concerns — signals that deserve attention
Positive signals — what looks reassuring, never oversold
Unknowns — what couldn't be verified yet
Evidence strength — where each signal came from and its weight
Recommended next action — one calm, practical step
The live checker isn't available yet, so this page can't produce a result for anything you enter. The preview is the concept.
Common questions
Frequently asked questions
Short, honest answers.
How can I tell if a website is legit?
Start with the evidence you can check yourself: look closely at the domain, compare it with the organization's official website, preview where links really lead, and be cautious about unexpected requests to log in or pay. Tracidar is designed to gather more of this evidence automatically — but the live checker isn't available yet.
Does HTTPS mean a website is safe?
No. HTTPS encrypts the connection, which is valuable — but it says nothing about who runs the site or whether the business is legitimate. Many scam sites use HTTPS too.
Does a new domain mean a website is a scam?
No. New businesses start with new websites, and old domains can change hands or be compromised. Age is one signal, never a verdict.
What does Insufficient Evidence mean?
It means there isn't enough reliable information to support a meaningful assessment. Insufficient Evidence is a legitimate result, not an error — it's a prompt to stay cautious and verify things yourself until more is known.
Does a Low Risk result guarantee a website is safe?
No. Low Risk means fewer concerning signals were found within the evidence available. It never means “safe” — evidence can change, and some risks are hard to see from outside.
Is Tracidar's live website checker available yet?
Not yet. The checker on this page accepts input so you can experience the flow, but it does not analyze anything. This page will say so clearly when live checking arrives.
Does Tracidar save the website I enter?
No. In this pre-launch stage, what you type stays in your browser — nothing is sent anywhere, analyzed or saved.
Return to the checker
The live checker isn't available yet. The form below shows how checking will work — without pretending to analyze anything.
What you type stays in this page — nothing is sent anywhere or saved.
Every Tracidar result will show its evidence. If we can't be sure, we'll say so.