Brand-copycat stores
The site copies a fashion, footwear, beauty or electronics brand and adds words such as India, official, sale or outlet to a lookalike domain.
Loading RakshaAI...
A fake online store can copy a real brand logo, product catalogue and checkout. You pay, but nothing arrives, a worthless substitute appears, or your payment details are exposed. Check the domain and business before you buy.
A checker result is a risk signal, not a guarantee of legitimacy.

red flags to check before paying
independent website checks to combine
immediate cyber-financial fraud helpline
National Consumer Helpline
Padlock warning: HTTPS protects the connection; it does not verify the store owner, product or refund promise.
Logos and catalogue images are easy to copy. Professional themes, HTTPS certificates, order emails and familiar payment screens can all exist on a fraudulent store. The useful question is not whether the page looks polished; it is whether the exact domain, operator, offer and payment destination can be independently verified.
A standalone copycat website has its own product pages and checkout. The operator may take payment, send junk or never deliver.
A fraudulent third-party seller operates inside a real marketplace. Start the dispute through that platform because its buyer-protection terms may apply.
A product arrives, but it is an imitation, unsafe or materially different from the genuine branded item advertised.
The site copies a fashion, footwear, beauty or electronics brand and adds words such as India, official, sale or outlet to a lookalike domain.
High-demand phones, consoles, sneakers or luxury goods are advertised far below normal retail price. Nothing arrives, or a low-value substitute is shipped.
The page uses countdown timers, limited-stock claims and familiar sale language around Diwali, New Year or marketplace sale periods to rush checkout.
A sponsored social post, search ad, influencer impersonation or WhatsApp forward promises an unusually steep discount.
Stolen logos, product photos, testimonials and a normal-looking HTTPS checkout make the store appear established.
The checkout collects a card payment or redirects to UPI, sometimes showing a personal or unrelated beneficiary name.
The order is never shipped, fake tracking appears, junk arrives, support vanishes or the website goes offline.
One warning can have an innocent explanation. Several together mean stop and verify independently.
Compare the exact model on the brand website and trusted retailers. A huge price gap combined with urgency is a strong warning, not proof by itself.
Watch for misspellings, extra hyphens, added words such as outlet or sale, and a different ending from the brand domain.
A recent creation date is useful context when a site claims a long business history. Older domains can also be compromised, so never use age alone.
The legal name, address, phone, email and grievance contact are absent, inconsistent or copied. A GSTIN can support verification where applicable, but its absence alone does not prove fraud.
Return text names another company, contact links fail, product descriptions conflict or reverse-image search traces photos to unrelated stores.
Checkout redirects to a personal UPI ID, unrelated name or direct bank transfer. Stop if the displayed beneficiary is not the seller you intended to pay.
A timer, last-item warning or WhatsApp-only deal pressures you to pay before checking the URL, seller and refund terms.
A seller or support agent asks for your OTP, card PIN, UPI PIN, screen share or remote-access app. Genuine refunds do not require these secrets.
Combine all five checks. Domain age, HTTPS and automated scanners are useful context, but none is a standalone safety certificate.
Open the brand from a saved bookmark, official app or manually typed address. Compare every character before entering personal or payment information.
Paste the store URL into the Website Safety Checker for a fast risk review. Treat the result as one signal, not a guarantee.
Open Website Safety CheckerReview available creation dates, registrar and status information. Some registrant details are legitimately redacted, and domain age alone cannot establish trust.
Open ICANN LookupLook for a current unsafe-site warning. A clean result only means no warning is shown at that moment; a new scam site may not yet be detected.
Open Google Safe BrowsingCheck the legal name, contact details, authorised-retailer list, return terms and payment beneficiary using independent sources.
Check the exact website before you enter your address, card or UPI details.
Check Website FreeAct promptly and use parallel reporting routes. A report can improve the chance of intervention, but no recovery percentage or fixed refund outcome is guaranteed.
Capture the URL, product page, checkout, order confirmation, payment reference, beneficiary details, emails, chats and courier label. Keep packaging and record the item received.
Call 1930 for cyber-financial fraud and notify your bank, card issuer, UPI app or wallet. Ask about the correct fraud report or goods-not-received dispute; deadlines vary by provider and payment method.
Submit the fake store URL, payment trail and screenshots to the National Cyber Crime Reporting Portal. Keep the acknowledgement number and complete any required follow-up.
Send a cybersecurity incident report to CERT-In when appropriate and report the page to its registrar, hosting provider, payment gateway and Google Safe Browsing. Reporting does not guarantee a fixed takedown time.
If an identifiable seller or e-commerce entity is involved, call NCH 1915 or lodge a grievance online. NCH is a pre-litigation mechanism and does not guarantee recovery.
Use the bank grievance process, the appropriate ombudsman or consumer commission where applicable, and contact local cyber police for deliberate fraud or identity theft.
Do not discard the parcel, invoice, courier label or item. Photograph every side, preserve a continuous opening video if you have one, compare the received item with the listing, and start the seller and payment dispute the same day. Do not return evidence to an unverified address before your provider confirms the process.
Overview of fake stores, COD fraud, marketplace scams and shopping recovery routes.
Use this when the platform is real but the third-party seller, tracking or package is fraudulent.
Use this when an imitation or unsafe branded product arrives instead of the genuine item.
Use this when the seller asks for UPI, token money or bank transfer outside protected checkout.
Use this when a shopping ad or seller operates through Instagram, WhatsApp, Facebook or YouTube.
Check the exact domain, compare the price with the official brand site, review ICANN registration data, run Google Safe Browsing and RakshaAI checks, verify the legal identity and contact details independently, and confirm that the payment beneficiary matches the seller. No single check proves a site is safe.
No. HTTPS encrypts the connection between your browser and the website. It does not prove that the operator, products or refund promise are genuine.
No. A recent registration date is a risk signal when combined with copied branding, implausible discounts or unverifiable business details. Legitimate new businesses exist, and older domains can be compromised.
Preserve screenshots and payment details, call 1930 for cyber-financial fraud, contact your bank or payment provider, and file at cybercrime.gov.in. Speed helps, but no channel can promise that the money will be recovered.
Ask your card issuer immediately about a merchant dispute or chargeback for goods not received or not as described. Eligibility, evidence and deadlines depend on the issuer, card network and transaction, so do not rely on a universal 120-day rule.
CERT-In accepts cybersecurity incident reports, including phishing and attacks involving e-commerce applications. You can report the URL and evidence, but CERT-In does not promise a fixed takedown or suspension time for an individual report.
Google Safe Browsing can show whether a URL is currently identified as dangerous. A warning is a strong reason to stop. A clean result is not a guarantee because a new or unreported fake site may not yet be flagged.
Not every missing GST number proves fraud because registration obligations depend on the business and applicable tax rules. Treat legal-name, address or tax-detail inconsistencies as warning signs and verify any GSTIN shown on the official GST portal.
The rules require covered e-commerce entities to provide specified business and grievance information. The grievance officer must acknowledge a consumer complaint within 48 hours and redress it within one month. Those rules do not make NCH or a complaint an automatic refund guarantee.
A fake shopping website is a standalone store outside the real marketplace. A fake marketplace seller operates inside Amazon, Flipkart, Meesho or another platform, so the platform dispute and buyer-protection process may be available.
Pause before checkout. Read the complete domain, compare the price, verify the operator and check the payment beneficiary. If the seller creates urgency or asks for an OTP, UPI PIN or remote access, close the page.