Read the complete domain character by character
Look for substituted letters, extra hyphens, unexpected numbers and unfamiliar domain endings. A padlock only means the connection is encrypted; it does not prove the operator is genuine.
A polished design is not proof of trust. Use these 12 checks before entering credentials, sharing personal information or sending money.
Look for substituted letters, extra hyphens, unexpected numbers and unfamiliar domain endings. A padlock only means the connection is encrypted; it does not prove the operator is genuine.
Avoid signing in through a forwarded message or unknown advertisement. Type a previously verified address or use a trusted bookmark. CERT-In advises checking URL integrity before entering credentials.
Look for a consistent business identity, contact route, terms and privacy information. A logo, brand-like name or copied “About” paragraph is not proof.
Claims such as “official,” “licensed” or “years of experience” need evidence from an authoritative source. Do not treat a badge image as verification.
A username can identify an account. Passwords, PINs, recovery codes and OTPs authenticate access and must remain private. Support should not ask you to read out an OTP.
Pressure to deposit immediately, keep the conversation secret or act before an offer expires is a warning sign. A legitimate process should leave time to check.
No account identifier can guarantee winnings, returns, deposits, withdrawals or uninterrupted access. Promises of risk-free results are not reliable evidence.
Check whether the recipient identity, payment route and published terms are consistent. Be cautious when payment is repeatedly redirected to unrelated personal accounts.
Ask clear questions about the operator, privacy, eligibility, fees and dispute handling. Evasive or contradictory answers deserve a pause.
India’s National Cyber Crime Reporting Portal provides facilities to check or report suspect website URLs, phone numbers, email addresses and social handles.
Keep software updated and do not install unknown apps, browser extensions or remote-access tools at a stranger’s request.
Save the URL, messages, phone number, timestamps and transaction references. Evidence can help a bank, platform or law-enforcement report.
CERT-In’s phishing guidance recommends expanding and verifying shortened URLs, using unique passwords and never sharing sensitive details such as passwords or PINs through email or text.
Use the National Cyber Crime Reporting Portal to report cybercrime. Its “Report Suspect” facility accepts suspicious website URLs, WhatsApp or Telegram handles, phone numbers, email addresses and related identifiers. For immediate cyber financial fraud reporting, the official helpline is 1930.
For broader phishing safety practices, see the CERT-In Digital Safety Compass Handbook.
Learn the difference between a Cricket ID, password and OTP, read our online Cricket ID security guide, or use the Cricket ID FAQ.