Skip to content
BeginnerLearn the steps

How to verify that a site is the official one

Author
CRYPTO PORT Editorial
Published
Updated
Reading time
5 min

In short

Reach an official site from your own bookmark of the correct URL, not from the top of a search page or from an advert. Fake sites bought as search adverts is a tactic that keeps recurring. Read the domain name character by character, install apps only from the official app stores, and make checking the URL before logging in a habit.

Key points

  • Bookmark the correct URL and open the site only from there afterwards
  • Fake sites are routinely placed in the advert slots of search results
  • Read the domain character by character — watch for near-identical spellings and different top-level domains
  • The padlock (HTTPS) shows the connection is encrypted; it does not prove who is running the site

Definition

The practice of confirming, from the URL and the distribution source, that a site or app really belongs to the service you intend to use. It is the first line of defence against phishing.

Start with the tactic itself. A search results page has advert slots and organic results, and the advert slots go to whoever pays. Attackers buy adverts under a real exchange's name and send people to a near-perfect copy of its site. From the user's side, nothing looks wrong: they searched for the exchange and clicked the top result. Understand that arriving via search is itself the weak point.

The core defence is to fix your entry point. Once you have reached the genuine URL with certainty, bookmark it and open the site only from that bookmark afterwards. To establish the genuine URL, you can use a link inside the official app, the URL in the email the operator sent when you opened the account, or the details listed in the FSA's published register. Avoid starting from a link on a third-party round-up page.

When you read a URL, go through the domain character by character. The common tricks are a one-character spelling difference, an added hyphen, or the real service name appearing only as a subdomain or inside the path while the actual domain is something else. The test is to find the registered domain — the part immediately left of the final dot-separated segment. If that is right, the rest of the path belongs to the same operator.

The HTTPS padlock is widely misread. It shows the connection is encrypted, not that the operator is genuine; fake sites obtain certificates too. Do not treat a padlock as safety. For the same reason, a convincing design and fluent Japanese prove nothing either.

Apps need the same discipline. Install only from the official app stores, and there check the developer name, the number and content of reviews, and the publication date. Following the link from the exchange's own website to the store is the most reliable route. Never touch an install link sent by message or social media, or an installer distributed outside the stores. 'Preventing phishing' and 'Fake support scams' cover the related tactics.

Watch out for

  • · Fake sites appear in the advert slots of search results. Searching the exchange's name and opening the top hit is a dangerous habit
  • · The HTTPS padlock does not prove who runs a site; fake sites display it too
  • · However perfect a copy looks, the moment it asks for a seed phrase or private key it is definitively fake. A genuine exchange never asks

Frequently asked questions

  • I entered my login details on a fake site.

    Go to the genuine site via your bookmark immediately, change the password and reset two-factor authentication. Change it anywhere else you reused that password too. Then check your withdrawal history and registered withdrawal addresses, and contact the official support channel.

Read next

Crypto quizzes

Answer a few questions and get your result instantly.

Start