Who we are, and how we verify a fake store
You have probably arrived here from a page asking you for money, having just given money to a website that turned out not to be what it looked like. Fair enough. This page is the answer to “who are you, and why would I believe you” — what we check, how we check it, what we refuse to claim, what is in the $19 pack and when it arrives, and the address a person reads.
60 documented hostnames across 56 brands, each published free with the date we checked it — read the whole index before you spend anything.
Who we are
Scam Detective is an independent scam-research service. We check websites that appear to be impersonating a real brand, we publish what we found and the date we found it, and we sell one-time reports built from that same research. There is no subscription, no account and no login — you pay once, for one thing, and it is delivered straight away.
The research is the part you can inspect before spending anything. 60 hostnames across 56 brands are published free on this site, each one naming the brand it reproduces, the class of evidence, every artefact we recorded and the date we ran the check. The oldest entries come from a teardown of a mass-produced clone kit we published on 27 July 2026; later ones come from sweeps we run against real store domains, most recently in August 2026. Nobody pays us to add a hostname to that list, and nobody pays us to keep one off it.
What we are not, stated plainly: we are not your bank, not a law firm and not a fund-recovery service. No money passes through us, we never contact a website's operator on your behalf, and nothing on this site is legal advice.
Four things are for sale, all one-time. A $2 instant check on a single URL. The $19 Dispute Evidence Pack described further down, for someone who has already paid one of the storefronts we documented. And two for a brand being copied: a $49 Evidence Report, where we assemble the evidence and draft a filing for every desk and you send them, and a $890 Takedown Engagement, where we submit those filings ourselves as your authorized agent under a written authorization you sign first. Submitting an abuse complaint is an administrative act — it is not legal representation, it creates no attorney-client relationship, and no outcome or timeline is ever promised.
Exactly how a copy is verified
This is the whole method, in the order it runs. Two of the steps exist to discard evidence that would read convincingly and prove nothing — those are the ones worth reading if you are deciding whether to trust the rest.
1We fetch the page ourselves, with the cache bypassed, and write down the date
Nothing on this site rests on a screenshot somebody sent us or on a list scraped from elsewhere. We request the address ourselves, with caching bypassed so we are reading what it served at that moment rather than a stored copy, and we record the HTTP status it returned. If it does not resolve, that is what we record — a dead or dormant address is reported as dead, never quietly counted as a live one.
2We read where the images come from — the image-origin, or own-CDN, check
On a suspected copy, right-click an image, copy its address, and read the hostname: everything between https:// and the first single slash. If that hostname is the real brand's own domain or CDN, the copy is not hosting the picture at all — it is loading the genuine brand's own file on every page view. That is file-level copying rather than an imitated look, it is the strongest class of evidence we hold, and anyone can reproduce it in a couple of clicks without tools or an account.
3The worked example, dated: foursigtics.com, 17 August 2026
On 17 August 2026 we fetched foursigtics.com with cache bypassed; it returned HTTP 200 and served a storefront reproducing the mushroom-coffee brand Four Sigmatic. Four images on its homepage loaded from us.foursigmatic.com — the genuine store's own domain — while its product photographs loaded from its own server. That last detail is the reason we check five or six images and start with the decorative ones: had we right-clicked a coffee bag and stopped, we would have concluded there was nothing there.
4Reused filenames count for images only — never for platform files
Where a copy reuses the genuine brand's image filenames, catalogue handles or product codes, we record it as an artefact. Where two sites merely share the same JavaScript or stylesheet filenames, we record nothing: two unrelated stores on the same shop platform ship identical script files because the platform ships them, and calling that copying would be an inference rather than an observation.
5A brand name in the page title only counts when something else corroborates it
A title carrying a real brand's name is a candidate, not a finding. It counts only when the page also reproduces at least two distinctive words from the genuine store's own title, or five from its description. A title that is nothing but the hostname is a default holding page and is not evidence of anything. The uncorroborated version of this rule matched an unrelated app listing, an adult site and a pet blog, which is why the bar is where it is.
6A shared template signature identifies a template, not an intent
Many of the storefronts in our first teardown share a generated social-image signature. We do not treat that as proof of impersonation and neither should you: two sites we checked that copy nobody at all return the same signature, and one of them exposes the underlying build as a commercially sold starter template. What we treat as probative is the combination — a real brand's name, plus a copy of that brand's catalogue, plus fabricated reviews, plus 65–70% discounts, together.
7Anything blocked at our end is a fact about us, not about the domain
If a site challenges or rate-limits our request, we record that we could not read it. We do not retry our way into a finding, and we never write up a page we did not successfully fetch as though we had. In the same spirit, a check that finds nothing ships as a check that found nothing: “no live lookalike answered today, on the variants we checked” is a complete and honest result, and inventing one to avoid it is the single failure this service could not survive.
The image-origin check is written up in full, with the screenshots-worth of detail and the mistake most people make when running it, in the ten-second own-CDN check. The clone kit behind the earliest entries is taken apart in our 27 July 2026 teardown.
What a published record contains
- The hostname, exactly as it was served to us.
- The real brand whose name and catalogue it reproduces.
- The class of evidence — whether the copy served the genuine brand's own hosted files, reused its filenames, handles or product codes, or matched its title and description in a corroborated way.
- Every artefact we observed, written out in full, so you can check each one yourself rather than take our word for it.
- The date we ran the check and the HTTP status it returned.
- Any later re-check, added as its own dated entry. We never edit or delete an earlier finding to make it read as current — both dates stay on the page.
Every one of those records is on this site free, at /is-<hostname>-legit, and indexed together in the documented fake-store index. Nothing in a paid product contradicts a free page: the paid documents are built from the same records.
What we deliberately do not assert
This list is longer than the one above, on purpose. What a research page declines to say is the part you cannot check for yourself, so it belongs in writing:
- Who registered a domain, why they did it, or that anyone committed a crime. We describe what a page served. We make no assertion about any registrant's identity, intent or criminality.
- That a domain shares hosting with anything, sits on an IP with other sites, was registered in bulk, or belongs to a network. We do not have the visibility to substantiate any of that, so we never say it — and our own generator is prevented in code from saying it either, after it did once and we retracted it in writing.
- That any goods are counterfeit. We have not examined goods. We document websites, not merchandise.
- That a domain is live today. Every finding is a point-in-time record of a named date. We do not monitor domains, there is no feed and no alerting, and a website's status can change any day.
- The registrar, hosting provider, name servers or IP addresses behind a documented domain. That attribution is deliberately withheld from the free pages — it is the research the paid brand-owner reports are priced on, and it is not needed to attach a dated record to a payment dispute.
What the $19 Dispute Evidence Pack is, and when it arrives
It is one document about one web address, for someone who has already paid that address and is taking it to their bank or card issuer. Four parts:
- The dated record for that one web address: the hostname, the brand it reproduces, the date we checked it and what it returned — the same words published free on its own page.
- An evidence index: one numbered exhibit per artefact we recorded for that hostname, each with the date it was observed and one line saying which assertion it supports.
- A written statement addressed to a bank or card-issuer dispute team, setting out what was documented at that address and on what date, with bracketed space for your own transaction details and your own description of what happened.
- A plain disclaimer, in the document itself, stating what it is: an automated dated record of publicly observable information, not legal advice, and not a representation about the outcome of any dispute.
When it arrives, and in what form: the moment your payment goes through, the pack appears on your own order page — a web page you can read, copy from, print or save from your browser, with the written statement in a copy-to-clipboard block so it can be pasted straight into an online dispute form. Nothing is researched or generated first; the evidence is already on file. We email you the link as well, so you can open it again from your phone when your issuer asks for it.
There is no waiting because there is nothing to run. Every other report on this site researches a domain when you buy it; this one does not. The evidence is already on file and already published, and the pack is assembled from it word for word — no model writes any part of it. A document that is going to be read by a dispute team is the last place we would let anything invent a sentence.
The pack is only offered for a web address we already hold a dated record for. If a hostname is not in our published index, there is no buy button for it anywhere on this site and there is no way to pay us for one — charging for evidence that does not exist is the one thing this product could not come back from.
What we do not promise: we cannot say whether your bank or card issuer will refund the payment, how long they take, or whether they will accept a claim at all — that decision is theirs alone. This pack is a dated factual record, not legal advice, and no money passes through us.
You do not have to take the description on trust either: every refund page shows a real, redacted sample of the pack for that hostname — for instance the one for thewinfieldcollectionco.shop — generated by the same builder the paid order uses, with only the body of the written statement held back.
What we do not promise, and do not do
- We do not recover funds. No money passes through us, and nobody here contacts a website, its operator or your bank on your behalf.
- We make no promise about a payment dispute — not the outcome, not the timing, not whether an issuer will accept a claim at all. That decision belongs to your bank or card issuer, and anyone who tells you otherwise is guessing.
- We give no legal advice and do not interpret your bank's or card network's rules. Their process, their deadlines and their decision are theirs to state, so ask them directly and ask early.
- We do not monitor anything on a one-time purchase. Every report and every published record is a point-in-time assessment, not a watch on a domain.
- We do not file abuse complaints for a shopper. Filing happens only on a Takedown Engagement, bought by the brand being copied, and only under a written authorization signed before payment.
How to reach a person
Write to scam-detective8@mail.acoco.ai. It is a real, monitored inbox — the same address every email from us is sent from, and the same one a reply reaches. There is no phone number and no chat widget, and we will never call you or ask you for card details, a password or remote access to your device.
If something we published about a web address is wrong, or you own a domain we have described and believe we have it wrong, write to that same address with what you observed. We re-check it and record what the re-check found, alongside the original entry rather than in place of it.
The short version
- Who is Scam Detective?
- An independent scam-research service. We check websites that appear to impersonate a real brand, publish what we find with the date we found it — 60 hostnames across 56 brands, free to read — and sell one-time reports built from the same research. We are not a bank, not a law firm and not a fund-recovery service, and nothing we publish is legal advice.
- How do you verify that a site is a copy?
- We fetch the page ourselves with caching bypassed and record the date and the HTTP status it returned. Then we look at where its images come from: if they load from the real brand's own domain or CDN, the copy is serving the genuine brand's own files, which is file-level copying rather than an imitated look. Reused image filenames, catalogue handles and product codes count as artefacts; shared platform scripts do not, and a brand name in a page title counts only when other distinctive wording from the genuine store corroborates it. We record what a check returned on a named date, and we do not claim a domain is live today.
- What is in the $19 Dispute Evidence Pack, and how quickly does it arrive?
- The dated record for one web address, a numbered evidence index of every artefact we published for it, and a written statement addressed to a bank or card-issuer dispute team with space for your own transaction details. It is assembled from evidence already on file — nothing is researched or generated when you buy — so it appears on your order page as soon as your payment goes through, and we email you the link as well. What we do not promise: we cannot say whether your bank or card issuer will refund the payment, how long they take, or whether they will accept a claim at all — that decision is theirs alone. This pack is a dated factual record, not legal advice, and no money passes through us.
- What do you deliberately not say about a documented domain?
- Anything we cannot observe directly. We make no assertion about who registered a domain, why, or whether anyone committed a crime; we never claim a domain shares hosting, an IP address or a network with anything; we do not call goods counterfeit, because we have not examined goods; and we do not claim a domain is live today, because every finding is a dated point-in-time record and we do not monitor domains. The registrar and hosting attribution is deliberately withheld from the free pages.
- How do I contact a person?
- Write to scam-detective8@mail.acoco.ai. It is a real, monitored inbox — the same address every email from us is sent from, and the same one a reply reaches. There is no phone number and no chat widget, and we will never call you or ask you for card details, a password or remote access to your device. If something we published about a web address is wrong, or you own a domain we have described and believe we have it wrong, write to that same address with what you observed. We re-check it and record what the re-check found, alongside the original entry rather than in place of it.
Scam Detective — pay-per-use scam intelligence. One-off checks, no subscription, no account.
Everything on this site is an assessment of publicly available information at the time of the check, and is not legal advice. We do not recover funds, do not monitor domains on any one-time purchase, and make no promise about the outcome or timing of anything decided by a bank, a registrar, a hosting provider or a platform.
Questions? scam-detective8@mail.acoco.ai