The ten-second check: is that copy of your store serving images from your own CDN?
If someone has cloned your store, the fastest proof you can get — no tools, no account, no expertise — is sitting in your browser's right-click menu. Here's the check, an example we verified live, and the thing most owners get wrong about it.
Published 17 August 2026 by Scam Detective · foursigtics.com resolved and returned HTTP 200 on 17 August 2026 with cache bypassed. A domain's state can change any day — re-check before relying on it.
The check
On the suspected copy, right-click an image → ‘Copy image address’ (Chrome/Edge), ‘Copy Image Link’ (Firefox), or ‘Copy Image Address’ (Safari). Paste it somewhere you can read it. Then look at one thing only: the hostname — everything between https:// and the first single slash.
Three outcomes, and they mean different things:
- The hostname is your own domain or your own CDN. The copy is not hosting that picture at all — it is loading it from your server, on every single page view. This is the strongest and most self-evident class of evidence there is, because the file was taken rather than the look imitated, and because you can demonstrate it to anyone in one click.
- The hostname is the suspect's own domain. They downloaded and re-uploaded your files. Still copying — but you now have to prove the file is yours, which is a comparison rather than a one-click demonstration.
- The hostname is a generic stock or marketplace domain. It may not be your image at all. Check another one before you conclude anything.
The mistake almost everyone makes
Do not check one image and stop. A copied storefront is usually a mix: some assets pulled from the real brand, some re-uploaded locally, some generic. If you right-click the first product photo you see, land on outcome 2, and conclude there's nothing here, you will miss the evidence.
Check five or six images, and deliberately include the ones nobody thinks about:
- background and lifestyle images, and decorative flourishes
- the favicon (the little icon in the browser tab)
- logos, badges and ‘as seen in’ press strips
- section backgrounds behind text
Those are the ones that get left pointing at the original, because they are the ones whoever built the page never bothered to re-host. Product photos are the most likely to have been re-uploaded and the least likely to give you outcome 1. Start with the decoration, not the products.
What it looked like when we ran it
On 17 August 2026 we checked foursigtics.com, a lookalike of the mushroom-coffee brand Four Sigmatic. It resolved and returned HTTP 200 — it was serving a live storefront when we looked. (If you searched ‘is foursigtics.com legit’ and landed here, that is what we observed on that date.)
Four images on its homepage load from us.foursigmatic.com— which is the genuine Four Sigmatic store's own domain:
Note the ?v= cache-busting parameter and the /cdn/shop/files/path. That is a Shopify asset path, and it is the real brand's — the version stamps are the ones the genuine store generated.
And here is the nuance from the section above, in the wild: on that same page the product photographs load from foursigtics.com/wp-content/uploads/2026/02/...— the suspect's own server. Had we right-clicked a coffee bag and stopped, we'd have seen outcome 2 and moved on. The four images that pointed back at the real brand were decorative — background artwork in one marketing section.
The dated record for this domain is on its full report.
Three other things on that page you can check without any tools
- The real brand's name, reproduced.Its footer reads ‘Copyright © 2026 Four Sigmatic’.
- Discounts in the 65–70% band. Ground coffee marked $20 down to $6, and protein marked $50 down to $15 — both exactly 70% off.
- A product the brand does not sell.A mushroom-coffee storefront carrying a slide for ‘JBuds Open Wireless Open-Ear Headphones’. Generic template stock poured into a brand nobody involved understood — the same self-refuting tell we documented across a dozen storefronts in our clone-kit teardown.
Also worth knowing before you act: the support address published on that page is support@ its owndomain. Writing to the contact address you find on a suspected copy reaches whoever runs it — not the brand being copied. Get your contact details from the real brand's own site.
Different build, same tell
This matters more than one domain. In July we published a teardown of roughly 90 fake .shop storefrontsthat were all one Next.js build, and one of the artefacts we found was exactly this: storefronts serving artwork from the real brand's own CDN. foursigtics.com is a completely different build — WordPress and WooCommerce, not that kit, and not a .shop domain.
Every hostname from both pieces of research is listed together, under the brand it copies, in the documented fake-store index.
So the own-CDN tell is not a quirk of one kit. It appears to be what happens whenever someone rebuilds a storefront quickly from a real one, in whatever technology. That is why it is worth teaching as a general check rather than as a fact about one operation.
What the check does and doesn't get you
Being able to point at your own hostname in someone else's page is genuinely strong evidence, and it costs you ten seconds. It is not, by itself, a filing.
An abuse desk needs the specific URL of the infringing material, your own claim to the asset stated plainly, the request addressed to the party that actually controls the domain or the server, and a specific action asked for. Most complaints fail on that last part rather than on the merits — they arrive at the wrong provider, or ask for something that provider cannot do. The registrar abuse desk, the hosting abuse desk and a marketplace report form each want a different shape, and one written for the wrong desk is routinely bounced.
Run it on your own brand, free
Our free Exposure Preview takes one field — the domain you own. It runs a live lookup while you wait and shows you the real lookalike and typosquat candidates it finds for your brand, each with what we observed on it, plus an exposure score and a plain-English verdict. No email, no card, no account. If your brand genuinely has no live lookalike today, that is what it says.
If you want the whole picture rather than one image check, the $29 Brand Impersonation Auditsweeps every lookalike and typosquat name generated from your own domain, resolves them, fetches what answers with cache bypassed and grades it against your own page — then names each confirmed-resolving hostname with the dated readings behind it, the copying evidence where we found it, a risk rating derived in code, and a takedown request drafted with your details in square brackets. One-time payment; you send the request, we don't file for you, and no outcome or timeline is guaranteed. We publish one complete audit in full so you can read the document before you buy one.
Scam Detective — pay-per-use scam intelligence. One-off checks, no subscription, no account.
Every finding here is an assessment of publicly available information at the time of the check, and is not legal advice. We produce the evidence and the correctly addressed request; on a Takedown Engagement we submit it to the abuse desks as the customer’s authorized agent, which is an administrative act and not legal representation. We do not monitor continuously and never contact the registrant on a customer’s behalf, and no outcome or timeline is guaranteed. Confirm your own trademark position before sending anything adversarial. The domain state described on this page was captured on 17 August 2026 and may have changed since.
Questions, or want the underlying capture? scam-detective8@mail.acoco.ai