Most scam websites are built to be temporary. A fake store takes orders for a few weeks, stops answering emails, and reappears under a new name with the same product photos. That churn is exactly what makes fraud hard to catch with technology alone: by the time a domain lands on a blacklist, it has usually already done its damage. The earliest warning, almost every time, comes from a person.

That is why community reports sit at the centre of how SiteScano reviews websites. They are one of three ways a scam gets caught here, and the only one powered by people. To understand what your report actually does, it helps to see the machinery it lands in.

How we find scams in the first place

Every domain we review goes through the same machinery, and the first pass is entirely automated. It runs in seconds, live, and deliberately queries independent sources side by side, because any single blacklist has both false positives and blind spots. This pass answers one question: is this domain dangerous or unusual right now?

What we checkWhat it tells usRefreshed
90+ security enginesWhether the domain sits on malware, phishing or spam blacklists, and how many independent providers agree.Every check
Registration recordsDomain age, the single most useful number in fraud detection, plus registrar and status flags.Weekly
HostingWhose network the site sits on, and whether it shares infrastructure with previously flagged domains.Weekly
The pages themselvesA first-party crawl looking for injected scripts, hidden redirects, and missing ownership or policy pages.Monthly
Link reputationWhich sites link in, how reputable they are, and whether the pattern looks organic or bought.Monthly
Public discussionReviews and complaint threads elsewhere on the web, read for recurring themes.Monthly

The second pass is a person. Where the automated answer is unconvincing, an analyst opens the site and actually reads it, asking a harder question: would a careful person trust this site with something that matters? Authorship, originality, transparency, intent. The things a scanner reads as an empty field rather than a problem.

And here is the honest limit of the machines. Automated checks are excellent at catching domains already known to be bad, and domains that are conspicuously new. They are poor at the carefully ordinary fake. A three-week-old domain belonging to a legitimate new business and a three-week-old domain built for a fake shop produce almost identical automated signals. Very often, the only thing that separates them is someone like you saying: I ordered, I paid, nothing came.

What a report actually is

A scam report is a first-hand account tied to one specific domain: what the site promised, what actually happened, and what you can show. It is not a star rating, and it is not the place for slow-shipping complaints. It exists for deception. Filing one takes about two minutes and needs no account. Every field on the form is required, including one piece of evidence, and your email is never published; it exists so we can send your reference number and ask follow-up questions.

It also has a scope: a report belongs here when a website was the instrument. If the contact happened only by phone or in person, your national cybercrime portal is the better route. These are the patterns we act on.

Fake shops

Order placed, money taken, nothing delivered. Or a counterfeit arrived and the returns address does not exist.

Phishing & impersonation

A login page copying a bank, a courier or an employer, usually reached from an SMS or email link.

Investment & crypto fraud

Guaranteed returns, a dashboard of profits you cannot withdraw, or a tax demanded before payout.

Job & task scams

Paid tasks that require a deposit, a registration fee or your identity documents before any work exists.

Subscription traps

A free trial that quietly bills monthly, with cancellation hidden behind a form that never completes.

Malware & forced downloads

Fake update prompts, browser lockers, or a download that installed something you did not ask for.

The report form as it looks today. Every field is required, and the form also asks how you reached the site, because the route (an SMS link, an ad, a search result) tells us how the operation finds its victims.

From the moment it is submitted, every report follows the same path.

1.  Submitted. You describe what happened and attach one piece of evidence. The form asks for the exact web address, so the right domain gets the scrutiny.

2. Acknowledged within 24 hours. You get a reference number by email. Quoting it later is the fastest way to add evidence or ask where your report has reached.

3. Read by a moderator. A person checks that the report describes a real experience, that the domain matches, and that nothing in it identifies a private individual. Reports written to attack a competitor are rejected here, and repeat submissions from one source are traceable.

4. Tested by an analyst. Verified reports move the domain into the manual review queue. An analyst opens the site, tests the claims that can be tested, and weighs them against domain age, hosting and other reports describing the same pattern.

5. Published in the review. Your account appears in its own section of the public report, clearly separate from our findings, so readers can tell which is which. The site operator gets a right of reply through the correction process.

Inside the analysis

Verification is not a gut call. A manual review follows a fixed sequence, so that two analysts looking at the same site arrive at comparable findings, and every review records who did it, when, what triggered it, and what the automated score said at intake. In practice, each type of claim has a matching test.

What you tell usHow we test it
“I paid, nothing arrived”The checkout flow is opened live, the business named at payment is traced through registration records, and the domain's age is set against how established the store claims to be.
“It is a clone of a real brand”Page structure, images and certificates are compared against the genuine domain, and we check which of the two was registered first.
“The site vanished after I paid”Cached snapshots and archived crawls let an analyst see the site as you saw it, even after it is gone. This is also why screenshots in reports matter so much.
“Support went silent”We look for the signature behind the silence: a young domain, hidden ownership, no reachable contact, and other reports describing the same pattern.

Evidence beats adjectives

The single biggest factor in whether a report can be verified is what comes attached to it. “This site is a scam” is a claim. A screenshot of the checkout page sitting next to a payment confirmation is a case. The form takes one file, a PNG, JPG or PDF up to 8 MB, so if you have several screenshots, combine them into a single PDF. And write what happened as a sequence of events rather than a verdict: “I paid on 3 March and the tracking number was never valid” carries far more weight than “this site is a fraud”.

EvidenceWhat it provesOne tip
ScreenshotsPreserves pages scammers delete once payments clear.Capture the full window, address bar included.
Payment recordsConfirms money actually moved, when, and how.Blank out card numbers; keep the amounts and dates.
The exact URLSeparates the scam page from lookalike or innocent domains.Copy it from the address bar rather than retyping it.
Emails & messagesShows the tactics: urgency, fake support, impersonation.Screenshot the thread with dates visible.
Operator identifiersUPI IDs, wallet addresses, phone numbers and the name on the invoice link one domain to the next, turning one complaint into a mapped network.Even a single identifier helps; operations reuse them.

Before you attach anything: cover your card number, CVV, OTPs and full account numbers. We do not need them, and we do not want to hold them. And report websites, not people: never include a private individual's name, address or documents.

How verified reports move a score

Reports are weighted, not counted. One account on its own does not decide anything; a corroborated pattern decides a great deal. Here is how the same domain is treated as the evidence builds.

One thing worth being precise about: first-hand reports feed one of the five weighted signal groups in the score, alongside security scanning, content and authorship, domain history and link reputation. Their larger effect is human. Verified reports move a domain into the manual queue, an analyst's finding can shift a score by up to 15 points, and a confirmed active threat caps it in the Danger band no matter what else looks clean.

The scale every score lands on. Verified community reports are one of the forces that move a domain down it, and a confirmed active scam pins it to the bottom band.

What we are seeingWhat happens
One report, no evidenceLogged on the domain's file. The score does not move on a single unsupported account.
Several reports, same patternThe domain is queued for analyst review, whatever its automated score currently says.
Verified report + technical red flagsScore adjusted, by up to 15 points. The finding is written into the public review and signed by the analyst who verified it.
A confirmed active scamScore capped. No amount of good signals elsewhere can lift it while the threat is live.

One report rarely moves a score. A verified pattern always does.

What a report can and cannot do

Being straight about the limits saves you from expecting the wrong outcome. We publish what public signals and first-hand accounts show about a website; we are not a regulator, a court or an investigating agency.

A report achieves

✓  Moves the domain into the queue for analyst review

✓  Adds your account to the public report, in its own section

✓  Feeds the signals that lower a fraudulent domain's score

✓  Connects operators when the same identifiers appear across many domains

A report cannot

×  Recover your money or reverse a payment

×  Take a website offline; only registrars, hosts and courts can

×  Serve as a police complaint or any kind of legal filing

×  Guarantee publication, because every report is moderated first

If you have lost money, these three moves actually work

1. Go to the payment provider first. Card payments can be charged back for goods not received, and UPI or wallet disputes must be raised in the app quickly. Those windows close long before the seller stops replying.

2. Save the evidence before the site changes. Screenshot the product page, the checkout confirmation and every support message. A page that disappears next week cannot be verified next week.

3. Report where it can be acted on. In India that is the National Cyber Crime Reporting Portal at cybercrime.gov.in, or the 1930 helpline. Then tell us, so the next person searching the domain finds your account first.

There is a full walkthrough in our guide to getting money back after an online scam.

Fair to the accused, too

A system where anyone could drag a score down would just be a different kind of scam: one aimed at honest businesses instead of shoppers. So the same weighting that stops a fraudster hiding behind a clean scan also stops a competitor, or one furious customer, from sinking a legitimate site. Malicious and mistaken reports are filtered out at review, and they do not leave a mark.

Site owners are part of the process, not spectators to it. Anyone can flag a factual error in a review and have it corrected, and no one, reporter or owner, can pay SiteScano to create, change or bury a report. Corrections run on published timelines: a complaint is acknowledged within 2 working days, confirmed factual errors are fixed within 5, and a full re-review, where one is warranted, completes within 15. All of it is free, and the analyst reviewing a domain cannot see whether its owner is a paying customer. The scoring method itself is published in full, so a score can always be traced back to the evidence behind it.

Why it is worth two minutes

Every review on SiteScano stays public. That is the quiet power of a single report: the person you are really protecting is the stranger who checks the same domain tomorrow, card in hand, one search away from the same mistake. Scam operations rely on each victim staying silent. Reporting is how the silence breaks.

Seen something? Say something.

If a website took your money, cloned a brand, or asked for details it had no business asking for, tell us. Two minutes, no account, and your email is never published.

Report a scam

Read how we review websites