Home / Scam safety / Three checks on official channels
Fake support, fake apps, fake sites: three checks
The least reliable way to spot an impersonation is by looking carefully at it. What follows are three fixed actions that still work when you are tired, rushed, or being pushed.
- Only enter through something you saved yourselfA bookmark, or the official app store. Not a search advertisement, not a link in a chat.
- Read the domain you are standing on, right to leftLook at the full address bar, particularly the last segment.
- Check who spoke firstOfficial channels never message you. Support conversations always start from you, inside the site.
That is the entire article. Everything below explains how each step works in practice, and why the order cannot be swapped.
Step one: the entry point
Most fake sites never need to be "spotted", because you would never have found them yourself. They were delivered to you.
Delivery happens three ways: a link in a conversation, a paid slot at the top of search results, or an app in a store with a very similar name. All three share one property — you did not go and find it.
What to do
- The first time you visit a platform, confirm the address through an official channel (the bio on an official social account, the About page inside the official app), then bookmark it immediately.
- After that, only ever enter through the bookmark. On a phone, add the page to the home screen, or use only an app installed from the official store.
- Skip the results marked "Ad" or "Sponsored". This is not a claim that advertisements are fake; it is that there is no reason to take the risk here.
Step two: read the domain right to left
Every guide mentions this and most people do it wrong.
The part of a domain that determines ownership is on the right. If an address reads binance.com.security-check.xyz, your eye is drawn to the familiar part at the front, but the site actually belongs to security-check.xyz, which has nothing to do with anything before it.
So the correct reading is: find the last two segments before the first slash. That is the identity of the site.
Three common disguises
| Technique | What it looks like | How to beat it |
|---|---|---|
| Subdomain disguise | The real brand name placed in the subdomain position | Read right to left; only the last two segments count |
| Lookalike characters | l swapped for I, rn arranged to read as m, characters borrowed from other alphabets | Do not compare by eye — compare against your bookmark |
| Different suffix | Brand name identical, only the ending changed | Know which suffix the official site uses |
Being honest: distinguishing lookalike characters by eye is not reliable. A well-made impersonation survives being stared at. The real defence is the bookmark habit in step one. Step two is a backstop, not the main line.
The search results problem, on its own
For many people the first visit starts with a search, and that is exactly the risky entrance.
Two issues. Advertisement slots at the top are bought, and impersonators buy brand keywords to sit above the official site. And results that look close enough — aggregators and directory sites styled to resemble an official entry point.
- Skip every ad slot. Scroll to organic results.
- Read the link, not the title. Titles can say anything; the domain is the identity. Most engines show the full address under the result.
- Bookmark it the moment you find it. Then you only ever have to search correctly once.
- When unsure, go around: find the address from an official social profile, or from the About page of the app you already have.
One situation people forget: logging in on somebody else's device. There may be extensions installed, and bookmarks in the history may have been tampered with. If you must, use a private window, and afterwards change your password on your own device and sign that device out.
Step three: who spoke first
The simplest and the most effective.
Fix the rule: anything "official" that contacts you first is not official. Regardless of verification badges, avatar quality or how professional they sound.
Why does that hold? Because a platform has no reason to privately message an individual user. It has announcements, in-app messages and email templates — all one-directional and all verifiable inside the official interface. A private message that needs your reply and your action is structurally implausible.
Verification codes, account passwords, seed phrases. No genuine support process requires any of them. The moment someone asks, the conversation can end.
Checking apps
Apps are harder than websites because there is no address bar. What is available:
- Install only from the system app store, and check the developer name rather than the app name — names are easy to imitate, developer accounts less so.
- Look at install counts and the age distribution of reviews. A genuinely large platform has years of accumulated reviews; impersonations appeared in the last month or two.
- If any channel asks you to bypass the store, or to trust a configuration profile or certificate, stop there.
Checking email and messages
Email is the easiest thing to imitate and the easiest to overlook, because the sender name is free text.
- Read the full address, not the display name"Binance Official" as a display name means nothing. Expand it and look at the real domain after the @.
- Look at what it asks you to doPure notifications (login alert, withdrawal completed) require no action and are normal. Anything asking you to log in, verify or resubmit documents is suspect by default.
- Do not click the link — go in through your bookmarkIf something genuinely happened, there will be a matching notice inside your account. If there is not, there was nothing.
The same applies to text messages, only more so — sender IDs can be forged to display identically to a legitimate channel, which is not technically difficult. Treat links in messages as never clickable.
Anti-phishing codes, an underused feature
Major exchanges offer a setting called an anti-phishing code: you choose a string, and from then on every genuine email from the platform includes it. A fake email does not know the string, so the difference is immediate.
It is one of the highest-value security settings I know of — two minutes, once, and every email afterwards carries its own proof. How to enable it is in the three things to set up on day one.
Checking social accounts
Exchanges maintain official accounts on every platform, and so do the impersonators.
Verification badges are a hint, not an answer
Verification mechanisms have changed a lot in recent years and on some platforms the badge can be purchased. Treat it as one input, not a conclusion.
The reliable approach is to verify in reverse: do not go from the social platform to the website — go from the website to the social account. Official sites list their accounts in the footer or on an About page. Anything you reach from there is genuine.
The direction matters. Searching a social platform for a site can put you on a fake from the first move; starting from the site and following its links means that if the site is right, everything downstream is right.
Groups and channels
- Official groups are usually read-only. An announcement channel does not let members post. A group where anyone can talk and where new members get private messages is usually not official.
- Were you added, or did you find it? Treat groups you were added to as suspect.
- Does anyone message you privately? Close to decisive on its own.
- Where did the invite come from? Only use the link published on the official site.
You ask a question in a group and within five minutes three private messages arrive, all offering help. You do not need to work out which one is genuine — they are all fake. Real support does not arrive as a private message. That single rule beats any amount of detail comparison.
Phone calls and video
Everything above concerns text and web pages. There is another category that is becoming more common: someone calls you, or starts a video call.
It does more damage, because voice and video carry trust automatically, and a live conversation leaves you no time to check anything.
Calls
Caller ID can be spoofed; this is not technically hard. So "the number looked official" is not evidence of anything.
There is exactly one way to handle it: whatever they say, hang up, then contact the platform yourself through official channels. If something real is happening, you can deal with it just as well by initiating contact. If it is fake, you have simply stepped out of the way.
Do not perform actions on a call, do not read out numbers, do not tap what you are told to tap. No exceptions, and no need to feel rude — a real institution does not object to you verifying who they are.
Video
Video calls are no longer proof of identity either. Face and voice synthesis good enough to convince an ordinary viewer in real time is not difficult now.
Which means "we video called, it was really him" has stopped working as a reason. Where money is concerned, judgement has to fall back on things that cannot be forged: did you enter through an official channel yourself, and did you initiate this action.
Any live interaction — phone, video, voice — is a bad setting for an important decision, because none of them leave you time to verify. Hang up, go offline, check it yourself. That is always available and always correct.
Third-party tools
Beyond exchanges you will use other things: market sites, block explorers, wallets, dashboards. There is no "official" version of those, so how do you judge?
- Does it want money or keys? A read-only tool that never asks you to connect a wallet is low risk. The moment it wants a connection and a signature, the standard goes up.
- How long has it existed? Reputation in this category accrues slowly. Something two months old with heavy promotion deserves more observation.
- Is the address stable? A project that changes domains often, for whatever reason, increases your exposure to impersonation.
- Disconnect when done. If you connected a wallet, disconnect afterwards and review approvals periodically — see section four of the playbooks piece.
My own approach is conservative: read-only tools freely; anything wanting a wallet connection gets tried first with a wallet holding almost nothing. It has never cost me anything and it has saved me a few times.
Turning it into a ten-second reflex
Knowledge is forgettable; actions are not. Make these three automatic:
- About to log inClose the page, re-enter through the bookmark, then log in.
- About to install somethingClose the link, search the app store, check the developer name.
- Someone claims to be officialDo not reply. Open the official app and look for a matching notification. If there is none, there is none.
Under ten seconds combined, and they replace judgement with procedure. Judgement fails when you are tired, rushed or being pushed. Procedure does not.
We turned this into a tickable list: the channel checklist. The fuller catalogue of scam types is in the playbooks piece.
What this does not cover
Stating the boundary matters more than overselling the method.
These three steps stop impersonation. They do not stop two other things: platforms you sought out yourself that were never legitimate, and relationship-built fraud — where nobody impersonates anyone, the person simply is "your friend" and the platform came from them. That one is recognised differently; see the long con.
And a third layer: even if you never visit a fake site, reused passwords, a device in the wrong hands, or an intercepted code will still cost you. That layer is covered in the three things to set up on day one.