Most scam links arrive in a moment of distraction — a DM, an email, a "delivery" SMS. The 30-second routine below catches the majority.
The 30-second check
- Hover, don't click. On desktop, hover over the link to see the real URL. On mobile, long-press to preview.
- Look at the root domain. Strip everything after the third "/". Is it actually the brand it claims to be? Watch for "support-binance.com" vs "binance.com".
- Paste into GACS Safe Scanner. Free, 4-second verdict including blacklist match, WHOIS age, certificate issuer, and red-flag patterns.
- Check the cert. Browser padlock → "Connection is secure" → "Certificate is valid". An EV / Org cert is a positive signal. A 2-month-old free Let's Encrypt cert on a financial domain is a yellow flag.
- Check /is/<domain> on GACS. Every domain in our database has a public report page at
gacs.app/is/<domain>.
Common impersonation patterns
- Hyphen-extended brand names: "binance-secure.com", "metamask-support.net".
- TLD swaps: "paypal.app", "amazon.support", "apple.id".
- Punycode lookalikes: "xn--pypal-4ve.com" renders as "paypaI.com" with a capital i.
- Subdomain tricks: "binance.com.login-secure.io" — the real domain is "login-secure.io".
If the GACS Safe Scanner flags anything, do not log in, do not download, and report the link. Even attempted phishing reports help — they feed the auto-learning fraud rules that protect the next person.
