How to recognize a fake site impersonating your brand
Updated on August 5, 2026 · LegalBrandGuard · 3 min read
Quick answer
Six signals distinguish a fake store from a legitimate reseller: domain age, the absence of verifiable legal notices, implausible discounts, content copied word for word, hidden hosting, and limited payment methods. None is sufficient on its own — it is their accumulation that settles the question.
The six signals, from most to least reliable
| Signal | What to check | Reliability |
|---|---|---|
| Domain age | Registration date at the registry | High — hard to falsify |
| Legal notices | Real registration number, an address that exists | High — verifiable in a public database |
| Copied content | Text and photographs taken from the official site | High if the copy is literal |
| Discounts | Price consistency with the market | Medium |
| Hosting | Server hidden behind a CDN | Weak alone — very common |
| Payment methods | Absence of solutions offering buyer recourse | Medium |
1. Domain age, the strongest signal
An established store has a domain name registered for years. A fake store rarely has one older than a few months: the model relies on disposable domains, replaced as soon as they are reported.
This information is public and free. It is held at the registry, accessible via RDAP or WHOIS, and it is far harder to fake than a legal notice or an “about” page.
A necessary nuance: a recent domain is not guilty by itself. Any business that just launched has one. The signal only becomes strong when combined with the reuse of an existing brand.
2. Legal notices that cannot be verified
Fake stores almost always display legal notices — a total absence would be too obvious. What gives them away is that the notices cannot be verified.
- No business registration number, or one that matches nothing
- A postal address that does not exist, or belongs to another company
- A contact form as the only way to reach the seller
- Terms and conditions copied verbatim, sometimes with another brand's name still in them
In France, the registration number can be checked for free in seconds on public business databases.
3. Content copied word for word
These sites are generated from the catalog of the brand being copied. Product descriptions, photographs, sometimes even the text of the “our story” page, are reused verbatim.
The simplest test: copy a sentence from the suspect site and search for it in quotation marks on a search engine. If it appears word for word on the official site, the case is made.
A clue that gives away mass production
These stores are deployed automatically, and the production process sometimes leaves visible traces: an internal identifier left in the page title, an “under construction” notice, a template name that was never replaced.
4. What the HTTPS padlock does not prove
This is the most common misconception, and it is worth pausing on because it reassures people wrongly.
A free TLS certificate can be obtained in minutes, with no identity check. Every fake store has one. The padlock attests that the connection is encrypted — that no one is intercepting your data in transit. It says nothing about what the recipient does with it.
5. Hidden hosting
Nearly all of these sites sit behind a reverse proxy service that hides the real server address. That is an obstacle to tracing the host, but a weak signal on its own: millions of perfectly legitimate sites use the same services.
What is revealing, on the other hand, is repetition: these stores are not set up one by one but deployed in bulk on the same infrastructure. That is what the anatomy of the BogusBazaar network shows, with roughly two hundred stores sharing a single server.
6. The payment methods offered
A fraudulent seller avoids payment methods that give the buyer recourse. It favors what is hard to dispute: bank transfer, prepaid cards, sometimes cryptocurrency.
The absence of the usual online payment options, from a merchant claiming to be an established brand, is inconsistent.
Key takeaways
- Domain age can be checked for free via RDAP or WHOIS; a recent domain is not guilty on its own, but becomes a strong signal when combined with the reuse of an existing brand.
- Fake stores almost always display legal notices — it is their unverifiability that gives them away, not their absence; in France, a business registration number can be checked for free in seconds.
- Content (descriptions, photos, sometimes the “our story” page) is copied verbatim from the official site; a leftover internal identifier in the page title or an “under construction” notice betrays mass production — we found exactly that on a domain registered just six weeks earlier.
- A free TLS certificate takes minutes to obtain with no identity check: the HTTPS padlock only attests that the connection is encrypted, never that the seller is honest.
- Hosting hidden behind a CDN is a weak signal on its own — millions of legitimate sites do the same — but its repetition across the same infrastructure, like the roughly two hundred stores in the BogusBazaar network, becomes revealing.
- A fraudulent seller favors payment methods that are hard to dispute (bank transfer, prepaid cards, cryptocurrency) and avoids those that give the buyer recourse.
Frequently asked questions
Does an HTTPS certificate guarantee that a site is legitimate?+
What is the most reliable signal?+
Is a recently registered domain necessarily fraudulent?+
Do fake sites always carry the brand name in their domain?+
Check your own brand
Our analysis tests hundreds of variants of your brand, checks which ones are active, and distinguishes clear-cut impersonation from legitimate homonyms.
Scan my site for freeSources
- BogusBazaar: a criminal network of webshop fraudsters — Security Research Labs
- French business registry — verifying a SIREN number — French Republic
Once the fake site is identified: the step-by-step takedown procedure.