Fake courier sites, UPI scams, fake checkout pages, the ₹25 redelivery con — how scam campaigns are built, what they have in common, and how to break them down.
DomainScan blog — field notes from the diagnostic layer of the web.
Deep-dives on AI readiness, DNS, SSL, email authentication and the small engineering choices that make domain tooling actually trustworthy. Written by the team that builds the platform. New posts most weeks.
What we write about
Seven recurring topic threads. Skim by tag from the index page or read in chronological order:
Typosquatting, homograph attacks, punycode spoofing, dashed brand impersonation — the URL tricks behind most payment phishing, and the WHOIS checks that catch them.
How GPTBot, ClaudeBot and PerplexityBot read the web. llms.txt format, robots.txt AI policies, structured data for AI, brand mention signals, passage-level citability.
DNSSEC, propagation, resolver behavior, anycast, NSEC walks, CAA records, EDNS Client Subnet, the long tail of edge cases nobody documents.
Certificate transparency, OCSP stapling, post-quantum readiness, HSTS preload, mTLS, the tricky parts of CSP and Permissions-Policy. Plus the HTTPS padlock myth — why valid SSL doesn't mean safe.
SPF lookup arithmetic, DKIM key rotation, DMARC reporting analysis, BIMI, ARC chains and why your perfectly configured stack still hits spam.
How we build DomainScan — edge architecture, caching strategy, observability, performance budgets and the small choices that compound.
Recent posts
Before you type a card number or scan a UPI QR, run a site through these seven checks: domain age, SSL, nameservers, blacklist, reverse IP, HTTP headers, brand cross-check.
Exact patterns on fake checkout pages — new domains, hidden WHOIS, suspicious nameservers, fake trust badges and the QR-code tricks costing Indians ₹400 crore a year.
Walkthrough of the URL tricks behind payment phishing — typo swaps, dash insertions, homograph attacks and punycode spoofs — with real examples and the WHOIS checks that catch them.
The padlock only proves the connection is encrypted, not that the site is legit. Most phishing pages in 2026 have valid SSL — what to actually check instead.
Inside the ₹25 redelivery scam: how fraudsters impersonate India Post, DHL, FedEx and Blue Dart, the SMS hooks they use, and how to verify a courier URL in 60 seconds.
Why every domain needs to think about how GPTBot, Claude-Web and PerplexityBot see it — and the five signals (JSON-LD, llms.txt, SSR, bot-aware robots.txt, canonical hygiene) that actually move the needle.
The emerging convention for telling AI systems which of your pages matter most. Format spec, ship-it-this-afternoon playbook, and real-world examples from GitHub, Anthropic, Cloudflare, Stripe and Vercel.
Get new posts by email
Roughly one post per week. No drip campaigns, no upsell emails, no third-party tracking pixels — just the post in your inbox.
- Cadence One email per published post. Skip a week if there's no new post — never a filler send.
- Format Title, excerpt, link. Plain text version available — pick from the subscribe form.
- Unsubscribe One-click in every email. No login required. Removed from the list within minutes.