Scam platforms are disposable by design — built to run hot for a few months and be abandoned when reports accumulate. That disposability leaves fingerprints in the infrastructure, visible to anyone who looks.
Domain age: the hardest signal to fake
A WHOIS lookup (who.is, or any registrar’s lookup) shows the registration date. The mismatch to hunt for: claimed history vs. actual age. “Serving investors since 2015” on a domain registered in March is a closed case. Scammers can fake screenshots, testimonials and licences; they cannot backdate a domain registration.
The disposable stack
- Privacy-shielded registration — normal for individuals, notable for a “global brokerage” that simultaneously claims a London headquarters.
- Bargain TLDs — .top, .icu, .xyz, .site cost almost nothing in bulk. Registry case records show operators cycling one brand across a family of cheap TLDs (the registry often holds several domains for one operator name).
- Template reuse — identical page layouts, identical “About” copy, different logo. Paste a distinctive sentence from the site into a search engine in quotes; multiple broker sites sharing prose is an operation, not a coincidence.
A 2-minute infrastructure check
- WHOIS the domain — note the age.
- Quote-search one sentence of their About page.
- Run the brand through the registry — prior reports beat any inference.
Infrastructure signals are probabilistic; case files are documentary. Use both, and if the platform already holds your money, check the SARFund case registry for an open investigation.