How we score a shop
Every check runs the same set of controls, with fixed weights, published here in full. We surface risk signals, never verdicts — an automated check can be incomplete or wrong, and a score is not a judgement about any business. If you operate a site we flagged, appeal it — a human reviews every appeal.
The score, in one paragraph
Every scan runs 150+ individual deterministic checks — you watch each one stream live during the check, and every verdict lists all of them. They roll up into a risk score from 0 to 100: deterministic infrastructure and page signals add points (capped at 75 combined), an AI review of the rendered page contributes at half weight (up to ~43 points), and deterministic trust indicators — evidence the operator pays for legitimate services — subtract points (capped at −12, deliberately less than one verdict band, so faked trust signals can never move a verdict a full level). If an authoritative source flags the site (Google Safe Browsing, a public threat blocklist, a urlscan.io "malicious" verdict, or the page itself displaying a phishing block), the score is floored at 85 regardless of anything else — trust indicators can never buy that down.
Domain & infrastructure controls
Deterministic lookups against public records — no AI involved. This group is capped at 70 points.
| Control | Data source | Points |
|---|---|---|
| Domain less than 7 days old | Registry records (RDAP), else first-seen proxies | +45 |
| Domain 7–13 days old | as above | +38 |
| Domain 14–29 days old | as above | +30 |
| Domain 30–89 days old | as above | +15 |
| Listed on a public threat blocklist | URLhaus, OpenPhish, PhishTank | +40 † |
| Flagged by Google Safe Browsing | Google Safe Browsing Lookup API | +45 † |
| urlscan.io classifies as malicious / suspicious | urlscan.io community verdicts | +30 / +15 † |
| No mail (MX) records configured | DNS | +5 |
| SSL certificate under 30 days old, on a domain under ~6 months old | Live TLS handshake | +5 |
| TLD commonly used for throwaway shops (.shop, .top, .icu, .xyz, …) | Domain name | +10 |
† Also triggers the authoritative floor: the final score cannot fall below 85 (urlscan "suspicious" adds points but does not trigger the floor).
How we determine domain age
Where the registry publishes a creation date (most global TLDs, via RDAP) we use it directly. Some registries — including Australia's .au — publish no creation date at all. For those we fall back to the domain's earliest observable footprint: its first TLS certificate in public Certificate Transparency logs, then its earliest Internet Archive snapshot. These proxies only prove the domain existed by that date — public certificate logs only reach back to around 2013–2015 — so we always report proxy-based ages as "at least this old", and a long-established domain may be far older than the floor we can prove.
Page-content controls
Deterministic pattern matches against the rendered page's visible text. This group is capped at 60 points; combined with the infrastructure group above, the deterministic total is capped at 75.
| Control | Points |
|---|---|
| Page currently displays a phishing / deceptive-site block | +45 † |
| Mentions high-risk payment methods (bank transfer only, crypto, gift cards, wire services) | +20 |
| Pushes extreme discounts ("80% off", "closing down", "hot sale") | +12 |
| Artificial urgency (countdowns, "only a few left", "ends tonight") | +8 |
These are deliberately mild individually — a legitimate store running a sale is not condemned; they matter when they stack with other signals.
AI forensic review
A language model reviews the rendered page for storefront-scam patterns we cannot express as fixed rules: brand impersonation on a lookalike domain, heritage claims ("since 1932") that contradict the measured domain age, and deep sitewide discounts on branded goods on a very new domain. Its assessment contributes at half weight:
| AI assessment | Contribution (points) |
|---|---|
| Low risk | +2.5 |
| Unclear — could not verify (genuine uncertainty is not evidence of risk) | +7.5 |
| Elevated risk | +30 |
| High risk (e.g. confident brand impersonation) | +42.5 |
The AI can only raise or lower within these bounds — it cannot flag a site on its own past the "elevated" band without deterministic signals alongside it, and its findings are always shown as hedged observations.
Trust indicators — evidence of a real business
Throwaway scam storefronts almost never pay for business services or pass identity checks. Each indicator below is deterministic — DNS records, certificate fields, or the real SDK URLs embedded in the page (never logo images or text, which are trivially faked) — and subtracts points. The combined credit is capped at −15, and can never override the authoritative floor.
| Indicator | Why it matters | Points |
|---|---|---|
| Paid business email service on the domain's MX (Google Workspace, Microsoft 365, Zoho, Fastmail, …) | A billing relationship and admin setup effort | −6 |
| DMARC email authentication published | The operator protects its own name from spoofing | −4 |
| SPF record (without DMARC) | Basic email hygiene | −2 |
| Organisation-validated (OV/EV) TLS certificate | A paid certificate issued only after identity verification | −6 |
| Real payment SDKs requiring merchant identity checks (Stripe, PayPal, Afterpay, Klarna, Zip, Shop Pay) | Mainstream processors KYC their merchants | −3 each, cap −6 |
| Commercial subscription services on the page (Klaviyo, Zendesk, Trustpilot widget, Yotpo, …) | Ongoing paid vendor relationships | −2 each, cap −6 |
| Hosted commerce platform with enforced seller policies (Shopify, BigCommerce, …) | A platform that can and does remove bad actors | −2 |
| DKIM email-signing keys published | A configured, verified sending platform | −3 |
| DNSSEC-signed zone | Deliberate, maintained DNS security | −2 |
| Advanced records: CAA, BIMI, MTA-STS, TLS-RPT | Mature security operations | −1 each, cap −3 |
| 3+ browser security headers set | An actively maintained deployment | −3 |
| 4+ customer-policy pages linked (privacy, returns, shipping, contact, …) | Consumer-law obligations honoured | −4 |
| Checksum-valid ABN/ACN published | A verifiable Australian business identity | −3 |
| 3+ real social-media profiles linked | A public, followable presence | −2 |
| robots.txt + sitemap + favicon all present | Search-engine hygiene of a real operation | −2 |
Free trackers (Google Analytics, Meta Pixel, …) are shown for context but earn no credit — they cost nothing to add, so they say nothing about legitimacy. Combined credit is capped at −12 — less than one verdict band.
Scam-tell controls
Deterministic patterns that fake storefronts exhibit and legitimate ones don't. Each is individually small; the group is capped at +35 so no single lane can condemn a site alone.
| Control | Points |
|---|---|
| Claims heritage ("since 1998") but the domain is brand-new | +15 |
| Punycode/homoglyph domain trickery | +12 |
| Displayed ABN/ACN fails the official checksum | +12 |
| A form on the page submits to an unrelated domain | +12 |
| "Powered by Shopify" claim on a non-Shopify host (cloned theme) | +10 |
| Unfinished template placeholder text; name servers on a parking service; redirects down to unencrypted HTTP | +10 each |
| Only a free-webmail contact address | +8 |
| Multiple-hyphen lookalike domain names | +6 |
| Milder tells (+3 to +5 each): AliExpress/Taobao imagery, chat-app-only contact, fake payment logos, static review stars, leftover Chinese-language code, dropshipping tooling, geo-currency switchers, countdown timers, decorative trust badges, mixed content, bait words, default template titles, foreign-currency pricing, deep subdomains, broken SPF, crowded/overlong certificates, storefronts with zero analytics | +3–5 |
The full list of every check, with its live determination, is shown during each scan and on every verdict.
Honest limitations
- Checks are automated and point-in-time. Sites change; data sources can be stale, incomplete or wrong.
- A low score is not a guarantee of safety, and an elevated score is not an accusation — it means several signals we associate with unsafe storefronts are present.
- Some sites block automated inspection; when we cannot load a page we say so rather than guessing.
- Sophisticated fraud can imitate some trust indicators; that is why credits are small, capped, and keyed on things that cost money or identity verification.
- Wrongly flagged? Appeal — a human reviews every case, and corrections update the published verdict.