How we work
The 13-point investigation protocol
Every case file runs the same thirteen checks, in order, before a verdict is printed. No site is convicted on vibes; no site is cleared on charm.
- 01
Domain age via RDAP/WHOIS
We pull the registration record directly. A 'trusted exchange since 2018' registered eleven weeks ago is not a discrepancy — it is the story.
- 02
SSL certificate validity
We verify the certificate chain, issuer and expiry. A padlock proves encryption, not honesty — but a broken or self-signed chain on a 'bank-grade' platform tells its own tale.
- 03
DNS records
MX, NS, A and TXT records reveal the real infrastructure: where mail actually goes, which name servers host the operation, and what else lives on the same address.
- 04
Blacklist status
We check major security and anti-phishing blocklists. Prior listings are logged with dates; a clean record is noted, not assumed.
- 05
Company registration
Every claimed corporate entity is checked against the official register of the jurisdiction it claims. 'Incorporated in St. Vincent' is verified, not transcribed.
- 06
On-site claims audit
Guaranteed returns, fake team photos, invented awards, regulator logos. Each claim on the site is catalogued and tested against verifiable fact.
- 07
Contact and address verification
We test the phone numbers, email addresses and physical addresses the site publishes. Virtual offices and disconnected lines are recorded as findings.
- 08
Payment-method analysis
How a platform takes money tells you who it is. Crypto-only deposits, pressure toward irreversible transfers and evasive withdrawal rails all carry weight.
- 09
Withdrawal-complaint scan
We scan public complaint channels for the signature pattern: deposits instant, withdrawals 'pending review'. Volume and consistency of complaints are logged.
- 10
Review-network scan
Five-star reviews posted in bursts by accounts with no history are themselves evidence. We map the review ecosystem around the site, including astroturfing patterns.
- 11
Linked-domain analysis
Scam operations rarely run one site. Shared analytics IDs, cloned templates, common name servers and redirect chains expose the wider network.
- 12
Screenshot evidence archive
Every page we cite is captured and archived at review time, so the record stands even after the site edits itself — or disappears.
- 13
Regulatory-register cross-check
Claims of licensing are checked against the actual registers of financial regulators — SEC, FCA, ASIC, CySEC and their peers. A license number that belongs to someone else ends the discussion.
The protocol ends in a verdict — scam, highly suspicious, caution or verified — and a trust score from 0 to 100. Both are editorial judgments, and both carry the evidence they rest on. If new facts emerge, the case file is updated openly through our corrections process.