ShopSafe

How we score a shop

Every check runs the same set of controls, with fixed weights, published here in full. We surface risk signals, never verdicts — an automated check can be incomplete or wrong, and a score is not a judgement about any business. If you operate a site we flagged, appeal it — a human reviews every appeal.

The score, in one paragraph

Every scan runs 150+ individual deterministic checks — you watch each one stream live during the check, and every verdict lists all of them. They roll up into a risk score from 0 to 100: deterministic infrastructure and page signals add points (capped at 75 combined), an AI review of the rendered page contributes at half weight (up to ~43 points), and deterministic trust indicators — evidence the operator pays for legitimate services — subtract points (capped at −12, deliberately less than one verdict band, so faked trust signals can never move a verdict a full level). If an authoritative source flags the site (Google Safe Browsing, a public threat blocklist, a urlscan.io "malicious" verdict, or the page itself displaying a phishing block), the score is floored at 85 regardless of anything else — trust indicators can never buy that down.

0–24Low risk signals
25–49Unable to verify
50–74Elevated risk signals
75–100High risk signals

Domain & infrastructure controls

Deterministic lookups against public records — no AI involved. This group is capped at 70 points.

ControlData sourcePoints
Domain less than 7 days oldRegistry records (RDAP), else first-seen proxies+45
Domain 7–13 days oldas above+38
Domain 14–29 days oldas above+30
Domain 30–89 days oldas above+15
Listed on a public threat blocklistURLhaus, OpenPhish, PhishTank+40
Flagged by Google Safe BrowsingGoogle Safe Browsing Lookup API+45
urlscan.io classifies as malicious / suspiciousurlscan.io community verdicts+30 / +15
No mail (MX) records configuredDNS+5
SSL certificate under 30 days old, on a domain under ~6 months oldLive TLS handshake+5
TLD commonly used for throwaway shops (.shop, .top, .icu, .xyz, …)Domain name+10

Also triggers the authoritative floor: the final score cannot fall below 85 (urlscan "suspicious" adds points but does not trigger the floor).

How we determine domain age

Where the registry publishes a creation date (most global TLDs, via RDAP) we use it directly. Some registries — including Australia's .au — publish no creation date at all. For those we fall back to the domain's earliest observable footprint: its first TLS certificate in public Certificate Transparency logs, then its earliest Internet Archive snapshot. These proxies only prove the domain existed by that date — public certificate logs only reach back to around 2013–2015 — so we always report proxy-based ages as "at least this old", and a long-established domain may be far older than the floor we can prove.

Page-content controls

Deterministic pattern matches against the rendered page's visible text. This group is capped at 60 points; combined with the infrastructure group above, the deterministic total is capped at 75.

ControlPoints
Page currently displays a phishing / deceptive-site block+45
Mentions high-risk payment methods (bank transfer only, crypto, gift cards, wire services)+20
Pushes extreme discounts ("80% off", "closing down", "hot sale")+12
Artificial urgency (countdowns, "only a few left", "ends tonight")+8

These are deliberately mild individually — a legitimate store running a sale is not condemned; they matter when they stack with other signals.

AI forensic review

A language model reviews the rendered page for storefront-scam patterns we cannot express as fixed rules: brand impersonation on a lookalike domain, heritage claims ("since 1932") that contradict the measured domain age, and deep sitewide discounts on branded goods on a very new domain. Its assessment contributes at half weight:

AI assessmentContribution (points)
Low risk+2.5
Unclear — could not verify (genuine uncertainty is not evidence of risk)+7.5
Elevated risk+30
High risk (e.g. confident brand impersonation)+42.5

The AI can only raise or lower within these bounds — it cannot flag a site on its own past the "elevated" band without deterministic signals alongside it, and its findings are always shown as hedged observations.

Trust indicators — evidence of a real business

Throwaway scam storefronts almost never pay for business services or pass identity checks. Each indicator below is deterministic — DNS records, certificate fields, or the real SDK URLs embedded in the page (never logo images or text, which are trivially faked) — and subtracts points. The combined credit is capped at −15, and can never override the authoritative floor.

IndicatorWhy it mattersPoints
Paid business email service on the domain's MX (Google Workspace, Microsoft 365, Zoho, Fastmail, …)A billing relationship and admin setup effort−6
DMARC email authentication publishedThe operator protects its own name from spoofing−4
SPF record (without DMARC)Basic email hygiene−2
Organisation-validated (OV/EV) TLS certificateA paid certificate issued only after identity verification−6
Real payment SDKs requiring merchant identity checks (Stripe, PayPal, Afterpay, Klarna, Zip, Shop Pay)Mainstream processors KYC their merchants−3 each, cap −6
Commercial subscription services on the page (Klaviyo, Zendesk, Trustpilot widget, Yotpo, …)Ongoing paid vendor relationships−2 each, cap −6
Hosted commerce platform with enforced seller policies (Shopify, BigCommerce, …)A platform that can and does remove bad actors−2
DKIM email-signing keys publishedA configured, verified sending platform−3
DNSSEC-signed zoneDeliberate, maintained DNS security−2
Advanced records: CAA, BIMI, MTA-STS, TLS-RPTMature security operations−1 each, cap −3
3+ browser security headers setAn actively maintained deployment−3
4+ customer-policy pages linked (privacy, returns, shipping, contact, …)Consumer-law obligations honoured−4
Checksum-valid ABN/ACN publishedA verifiable Australian business identity−3
3+ real social-media profiles linkedA public, followable presence−2
robots.txt + sitemap + favicon all presentSearch-engine hygiene of a real operation−2

Free trackers (Google Analytics, Meta Pixel, …) are shown for context but earn no credit — they cost nothing to add, so they say nothing about legitimacy. Combined credit is capped at −12 — less than one verdict band.

Scam-tell controls

Deterministic patterns that fake storefronts exhibit and legitimate ones don't. Each is individually small; the group is capped at +35 so no single lane can condemn a site alone.

ControlPoints
Claims heritage ("since 1998") but the domain is brand-new+15
Punycode/homoglyph domain trickery+12
Displayed ABN/ACN fails the official checksum+12
A form on the page submits to an unrelated domain+12
"Powered by Shopify" claim on a non-Shopify host (cloned theme)+10
Unfinished template placeholder text; name servers on a parking service; redirects down to unencrypted HTTP+10 each
Only a free-webmail contact address+8
Multiple-hyphen lookalike domain names+6
Milder tells (+3 to +5 each): AliExpress/Taobao imagery, chat-app-only contact, fake payment logos, static review stars, leftover Chinese-language code, dropshipping tooling, geo-currency switchers, countdown timers, decorative trust badges, mixed content, bait words, default template titles, foreign-currency pricing, deep subdomains, broken SPF, crowded/overlong certificates, storefronts with zero analytics+3–5

The full list of every check, with its live determination, is shown during each scan and on every verdict.

Honest limitations

  • Checks are automated and point-in-time. Sites change; data sources can be stale, incomplete or wrong.
  • A low score is not a guarantee of safety, and an elevated score is not an accusation — it means several signals we associate with unsafe storefronts are present.
  • Some sites block automated inspection; when we cannot load a page we say so rather than guessing.
  • Sophisticated fraud can imitate some trust indicators; that is why credits are small, capped, and keyed on things that cost money or identity verification.
  • Wrongly flagged? Appeal — a human reviews every case, and corrections update the published verdict.