What is a WHOIS record?
A WHOIS record is the public registration file of a domain name — the address of a website. It is held by the registry that runs the extension (.com, .org, .fr and so on) and it is deliberately public: anyone can query it, for free, over a protocol that has been around since the 1980s.
The raw output is not pretty, but it holds the facts that matter:
- Creation date — when the domain was first registered. The single most useful signal there is, because most fraudulent sites are only days or weeks old.
- Expiry date — when the registration lapses unless it is renewed. Someone paying five years ahead is not planning to disappear next month.
- Registrar — the company that sold the domain.
- Name servers — which DNS provider the domain points at.
- Registrant — the owner, when they are not hidden behind a privacy service. In Europe, personal details are usually redacted by law, so this being empty is normal rather than suspicious.
- Status codes — registry locks, pending deletion, and similar states.
WHOIS also tells you whether a domain is free. If the record comes back empty, nobody owns that name and you could register it yourself. If it shows an expiry date in the near past, the name may be about to drop and become available again.
How the trust score works
CheckWhois turns the WHOIS record, plus a handful of live tests against the website itself, into a score out of 100. Each criterion contributes a fixed number of points, and the report shows you exactly how many each one earned, so nothing is hidden in a black box.
| Criterion | Weight | What it measures |
|---|---|---|
| Domain age | 30 | Ten years old scores full marks; under a month scores nothing. |
| Secure connection | 18 | HTTPS with a certificate that actually validates. |
| Legal & policy pages | 14 | Terms, privacy policy and contact details published at the usual addresses. |
| Website status | 10 | Whether the site answers, and how fast. |
| Registration horizon | 10 | How long the domain is paid up for. |
| Registration country | 10 | Jurisdictions with high reported abuse rates score lower. |
| WHOIS transparency | 8 | Whether an owner is published or hidden behind a privacy service. |
Two penalties can be applied on top: −6 for extensions that are massively over-represented in abuse reports (.tk, .ml, .cf, .buzz and friends), and −5 when a domain resolves but serves no website at all. The final figure is clamped between 0 and 100.
Is a trust score reliable?
Not on its own, and it would be dishonest to pretend otherwise. Two failure modes are worth keeping in mind:
- A new site is not a scam site. An honest business that launched last month will score badly on age, expiry and policy pages all at once. Low score, legitimate shop. Treat it as a reason to be careful, not a reason to walk away.
- A high score can be bought. Organised fraudsters buy expired domains precisely because they come with history, add a free certificate and copy a privacy policy in five minutes. Age and HTTPS are cheap to fake in that direction.
The score is a fast first filter. What follows is what actually catches the rest.
How to avoid online scams
Check the address bar, character by character. The most effective attacks do
not build a convincing site, they build a convincing URL. One swapped letter, a hyphen
added, .co instead of .com, or a subdomain arranged so the real brand
appears in the middle of a longer address. Read it slowly before you type anything into it.
Do not click links in emails and text messages. If a message claims to come from your bank, your carrier or a marketplace, open the site yourself from a bookmark or by typing the address. Legitimate organisations never lose anything by you doing that; scammers lose everything.
Use strong, unique passwords. One password per site, generated rather than invented, stored in a password manager. A leak on a forum you forgot about should never open your email. You can generate one at createpass.net.
Never share card numbers or personal details in a chat. No support agent, delivery service or marketplace seller has a legitimate reason to ask for them in a conversation.
Pay in a way you can reverse. On a first order from a site you do not know, use a virtual or single-use card number — most banks issue them free — or a payment method with buyer protection. Bank transfers, crypto and gift cards are irreversible, which is exactly why fraudulent shops insist on them.
Be suspicious of pressure. Countdown timers, "only 2 left", a price 70% below everyone else, and a checkout that suddenly asks for a different payment method are all signs to stop.
Report what you find. Reporting a fraudulent site is what gets it taken down for the next person. In the United States, file with the FTC and the FBI's IC3. In the United Kingdom, use Action Fraud. In Canada, the Canadian Anti-Fraud Centre. In Australia, Scamwatch. Elsewhere, your national cybercrime unit or consumer protection authority. It is also worth reporting the site to the registrar named in its WHOIS record — registrars are required to act on abuse reports, and that is often the fastest route to a takedown.
Online fraud keeps growing year after year, and the sites get better looking, not worse. A quick lookup costs you ten seconds.