Skip to content
18+ Adults only Independent information website Information status Review details appear on each guide
RAJABETSINDIA GUIDEIndependent Information Website Home
Account safety · local address-format check

Account safety

Read the Address Before Entering Account Details

A familiar design says nothing about who controls an address. Read the hostname, subdomains and unusual characters first, then consider password, OTP, shared-device and recovery risks.

URL anatomy separated into scheme, subdomain, domain, top-level domain, path and query
Address structure can be inspected locally but does not prove ownership or safety.

Local URL format check

Checks visible URL structure only. It never opens the address.

This local format check does not verify ownership, authorisation or safety.

Your local summary will appear here.

URL anatomy begins at the hostname

In https://sub.example.com/path, the hostname is sub.example.com. Read it from right to left to identify the registrable domain and any preceding subdomains.

Reserved URL examples showing subdomains, punycode, IP addresses and at symbols
Structure examples only; they do not verify ownership, authorisation or safety.

These examples illustrate URL structure only. They do not verify ownership, authorisation or safety.

Threat cards: pause before entering information

A copied page can look polished. Textual and behavioural signals provide a more useful reason to stop.

Unexpected subdomain

A familiar brand word placed before an unrelated domain does not control the domain.

Look-alike text

Punycode or substituted characters can make a hostname appear familiar at a glance.

Short link

A redirect service hides the final destination until followed.

Password reuse

One leaked password can expose every account where the same value is used.

Payment-proof request

A fake helper may ask for full records, OTPs or remote screen access.

Shared device

Saved sessions, downloads and browser autofill can remain after the tab is closed.

OTP, recovery code and remote-access boundaries

An OTP or recovery code is an authentication secret, not evidence for a support ticket. Remote-access software gives another person control of the device and should not be installed at the request of an unsolicited contact.

  1. Use a unique password stored in a reputable password manager.
  2. Do not send an OTP, recovery code, PIN or password.
  3. Do not grant accessibility or screen-control permission to a stranger.
  4. Mask transaction destinations and crop unrelated balances.
  5. Sign out and clear saved data on a shared device.
  6. Review active sessions through a trusted account route when available.

Account recovery order after a suspected incident

Disconnect from the suspicious conversation first. Preserve the address and time without revisiting the link, then secure the email or phone channel used for recovery.

Change reused passwords from a clean device, review active sessions and contact the relevant financial provider through its independently verified channel if a payment secret was exposed. For access troubleshooting, follow Login Help. For device-source checks, use the App Guide. Build a redacted report with the Support Guide, and never include secrets in that report.

Read a hostname from the right

In accounts.brand.example.com, the ending “example.com” controls the subdomains placed before it. A brand word on the left does not make the address brand-owned.

Punctuation matters. An @ symbol can make text before it look like a hostname even though the browser navigates elsewhere. An unusual port after a colon changes the network endpoint. An IP address replaces a readable domain with numbers. Punycode beginning “xn--” can represent internationalised characters, and look-alike letters can be difficult to notice.

The safest comparison is with a hostname obtained independently, not with a link displayed on the suspicious page itself. Do not search only for a familiar word and click the first advertisement. The local checker never opens a URL; its output is a reason to inspect further, not a certificate.

Payment-proof scams exploit real-looking records

A genuine transaction screenshot can be copied, altered or used to reveal enough information for another attack.

Mask names, destination identifiers, QR codes, balances and unrelated records. Keep only the date, amount, currency, status and minimal reference ending needed to distinguish the event. Never install remote-access software to show a transaction live. If another person already viewed the device, disconnect it, remove the access tool and secure financial and recovery accounts from a clean device.