Contents

Building a fake website used to take real effort a bit of code, a stolen logo, and a few hours of patience. Not anymore. Generative AI tools can now clone a legitimate company’s entire homepage, complete with matching fonts, working navigation, a plausible privacy policy, and even a synthetic photo of its “CEO,” in a matter of minutes. The Anti-Phishing Working Group logged nearly 1.8 million new phishing and fake websites in just the second half of 2024, and by 2026, AI-generated sites already account for an estimated 6–7% of all phishing infrastructure (APWG, 2025a, 2025b).

The good news: fake websites still leave fingerprints. This guide walks through the same structured, section by section methodology used to train Certified Internet Research Specialists covering homepages, policy pages, “About Us” content, checkout flows, images, reviews, and the newer AI era threats like deepfakes and cloaking. Along the way, real annotated examples show exactly what these red flags look like in practice.

0M
New phishing/fake sites, H2 2024 (APWG)
0%
Of all phishing infrastructure is now AI-built (Panda Security, 2026)
0%
Human accuracy detecting deepfakes — barely above chance (iProov, 2025)
0$
US deepfake-related financial losses in 2025 (Keepnet Labs)

1. Homepage & Logo Verification

A homepage is the digital storefront, and it’s also where a rushed fake operation is most likely to show its seams. Because fraud sites prioritize speed over investment, logos are frequently just lifted from the internet and lightly edited usually only the company name changes.

The tell is in the pixels. A logo pulled from the web without buying the original high resolution file will show blurring, pixelation at the edges, and inconsistent anti aliasing when you zoom in. A logo built properly in Illustrator or Photoshop or licensed at full resolution stays crisp no matter how far you zoom.

Fig. 1 – Breakdown of Homepage and Logo Verification

Example teardown. A deliberately low-effort fake homepage: small, low-resolution images used to hide compression artifacts, a text-based “logo” instead of a real logo design, poor color contrast, and placeholder Latin filler text sitting next to the real content. Each of these is a red flag on its own; together, they’re a pattern.

The Reverse Image Search Test

Right click the logo, open it in a new tab to grab the raw file name and URL, then drop it into Google Images, Bing Visual Search, or TinEye. If the result points back to a stock photo library like Shutterstock or Getty, or to an entirely different company, that’s a serious red flag.


Fig. 2 — Original vs. licensed source. A reverse image search on “Gatesville University’s” homepage matched the high-resolution version of the logo to a Shutterstock listing, indicating that the operator never licensed the artwork they used to represent a real institution.

RESEARCHER TIP — LOGO VERIFICATION IN FIVE STEPS

  1.  Open the logo image in a new tab to see its raw URL and filename.
  2. Drop it into Google Images, Bing Visual Search, and TinEye.
  3. Check for stock-library matches or appearances on unrelated sites.
  4. Compare the high-resolution match against the claimed brand identity.
  5. Verify whether the same filename reappears across multiple unrelated domains, a signature of mass-deployed fake sites.

Layout and Navigation Red Flags

  • Dead links: navigation items that go nowhere or to placeholder pages.
  • Image-based navigation: menu bars built as a single flat image rather than real HTML; right click and “Inspect” to check.
  • Homepage-as-image: the entire page is one image file, which blocks text selection and spell-checking.
  • Aggressive monetization: pop-ups, countdown timers, and urgency-driven discount banners funneling straight to checkout.
  • Mismatched branding: logo colors that clash with the site’s own color palette, a sign the logo was bolted onto a template rather than designed for the brand.

2. Policy and Legal Pages

Privacy policies, terms of use, and disclaimers are boring by design, which is exactly why fake operators cut corners on them. Legitimate businesses invest legal review into these documents; fraudulent ones either skip them or lift boilerplate from a free generator or a competitor’s site.

The detection method is simple: copy a distinctive 815 word phrase from the policy and run it through Google in quotation marks. If identical wording turns up verbatim on unrelated sites, the content is plagiarized, and the business behind it likely doesn’t exist as described.

Go one step further and check internal consistency. A site claiming to be Canadian shouldn’t cite FERPA (a US education law) without acknowledging the jurisdictional mismatch. And a policy that still reads like 2019 boilerplate in 2026 with no reference to newer frameworks like the EU’s Digital Services Act or updated US state privacy laws suggests an abandoned or fraudulently repurposed domain (European Commission, 2026).

3. “About Us” Page Analysis

The “About Us” page is the most information-dense part of a suspect site and one of the most revealing. A fake version usually falls into one of two patterns: content plagiarized from a real organization or generic filler that reads well but says nothing verifiable.

A Five Point Completeness Test

Score the page against these criteria. 3 or more out of 5 suggests authenticity; fewer warrant a closer look:

  • A clear mission and organizational philosophy
  • Business structure details (formation date, corporate type)
  • Photos of directors and management with verifiable credentials
  • Contact emails on the company’s own domain (not generic Gmail/Yahoo)
  • Partner logos and awards with a verifiable, checkable source

THE AI-ERA TWIST

Large language models can now produce “About Us” copy that’s grammatically flawless and reads convincingly while making zero falsifiable claims. Content that’s polished but strangely short on verifiable specifics (exact dates, named partners, checkable credentials) is increasingly a signature of a sophisticated fake, not evidence of quality.

Case Study: Verifying an Executive’s Photo and Background

A real AOFIRS investigation into a post-secondary institution shows the full workflow. The site listed a “University President” with a name, phone number, and email address, all of which appeared plausible on the surface.

Fig. 3 — The reverse image search giveaway. Running the executive’s profile photo through Google Images returned a “best guess” match not to a university biography, but to an unrelated mergers-and-acquisitions firm. The photo had been borrowed to build a fictional identity.

The investigation didn’t stop at the photo. The physical address on the “About Us” page was cross checked against the actual signage at that location using Google Street View:

Fig. 4 — Physical address verification. Street View imagery of the claimed headquarters showed signage for a company unrelated to the institution named on the website, indicating a mismatch between the stated identity and the actual occupant of the address.

LinkedIn told the rest of the story. The “president’s” profile listed an implausible second full time role, endorsements from a car dealer and an unrelated technician rather than fellow academics, and education history that couldn’t be corroborated with any alumni network:

Fig. 5 — Social media Platform Profile Verification.

Network analysis. A senior university president would typically be endorsed by peers in education. Here, the account’s connections skewed toward unrelated industries, a pattern more consistent with a constructed identity than a genuine professional history.

Fig. 6 — Techniques are required to distinguish between fake and real.

Conclusion. Between the mismatched photo, unverifiable address, and anomalous professional network, the identity behind the listed executive was confirmed fraudulent, illustrating that no single check is sufficient; it’s the accumulation of small inconsistencies that closes the case.

  • Business name + “reviews”, “scam”, and “complaint”
  • Better Business Bureau directory (bbb.org)
  • Jurisdiction-specific business registry (Corporations Canada, US Secretary of State, Companies House UK)
  • SEC EDGAR for any US-publicly-traded claims (sec.gov/edgar)
  • Direct confirmation of any claimed award or ranking with the issuing body
  • Physical address cross-checked against Google Street View

4. Products & Services Verification

E-commerce fraud is one of the costliest forms of fake-website activity. One in three content-theft sites reportedly exposes visitors to malware, and a 2025 survey found that 36% of Americans who bought from a fraudulent online store never got a refund (Federal Trade Commission FTC, 2026). Deloitte projects AI-assisted scam losses could reach $40 billion globally by 2027.

Spotting a Counterfeit Product Listing

Fake product photography has its own tells: font weights and kerning that don’t match the brand’s real packaging, only one or two images instead of multiple angles, inconsistent lighting or staging, and missing or incorrect certification marks (CE, FCC, UL, CSA) on regulated goods.

Fig. 7 – Comparison between easily available store products.

Exhibit 1 — Color and shade comparison. Side by side, the counterfeit shows noticeably different color tones and font weight versus the genuine product, discrepancies invisible at thumbnail size but obvious under close examination.

Fig. 8 – Cosmetic products to catch counterfeit packaging.

Exhibit 2 — Font variation. Genuine packaging (top) versus a counterfeit (bottom): character spacing, kerning, and font weight differ measurably even without specialized tools, a fast, free way to flag suspect listings.

5. Checkout & Payment Verification

Checkout is where fraudulent sites are built to extract financial data, so this step is the highest-stakes stage to verify before entering payment details.

  • Invoice total: confirm it matches quantity, unit price, shipping, and tax before paying.
  • Refund and return policy: vague, restrictive, or absent policies are a strong warning sign.
  • Confirmation emails: a legitimate transaction generates at least two, one from the vendor and one from the payment processor.
  • Auto-renewal boxes: many fake sites default to pre-checked consent for recurring billing.
  • HTTPS is necessary but not sufficient: free, minimally verified TLS certificates (e.g., Let’s Encrypt) mean the padlock icon alone no longer proves legitimacy. Click the padlock to check the issuing certificate authority and validity window.
  • Trust seals: legitimate seals (DigiCert, Norton Secured, PayPal Verified, and BBB) are clickable and redirect to the issuer’s own verification page. A seal that’s just a static image is fabricated.

2025–2026 UPDATE

82.6% of phishing emails analyzed between September 2024 and February 2025 contained AI-generated content, and a significant share of the phishing sites they linked to carried valid TLS certificates. Treat HTTPS as baseline hygiene, not a trust signal.

6. Content, Video & Contact Verification

Content quality is a fast proxy for how much genuine investment went into a site. Persistent spelling and grammar errors on principal pages are hard to excuse in an age of built-in spell check, but so is the opposite extreme: flawless, AI-generated prose that makes no verifiable claims at all.

Video and Deepfakes

Deepfake volume has exploded: an estimated 8 million deepfakes were shared in 2025, up from 500,000 in 2023, a 1,500% increase in two years. Human detection accuracy is just 55.5% overall and drops to 24.5% for high-quality video deepfakes. A practical verification checklist:

  • Check whether the video is hosted locally or embedded from YouTube/Vimeo/social platforms.
  • Compare the upload date to the claimed original share date.
  • Look for blurring around moving objects, edge artifacts at face boundaries, or unnatural blinking.
  • Match environmental details (signage, plates, language) against the claimed location.
  • Run a reverse video search with the free InVID/WeVerify browser plugin.

Contact Information

Email Address Assessment
name@companydomain.com Correct — domain matches the organization
name@companydomain.membership.com Incorrect — subdomain of a different organization
name@amazoncustomerservice.com Incorrect — deceptive domain impersonating a brand
name.11901@companydomain.com Suspicious — numeric suffix typical of bulk email generation
name@gmail.com Inappropriate — personal address on a business contact page

Also verify: does the postal code match the stated city? Is the phone number a traceable landline or registered VoIP number, or an easily-abandoned burner? And does the copyright notice in the footer show a current, internally consistent year? An outdated one (often by several years) can indicate an abandoned or fraudulently repurposed domain.

7. Profile Photos & Image Verification

Executive and team photos are among the most commonly manipulated elements on fake sites, ranging from simple stock-photo reuse to fully AI synthesized faces.

Six Signs of a Stock Photo

  • Immaculate studio lighting with no natural shadow variation
  • Clean, distraction free backgrounds with no personal clutter
  • Absence of any brand identifiers or logos
  • Inconsistent quality, some images are professional, others clearly amateur
  • Exaggerated, universally “readable” facial expressions
  • Multiple near-identical variations turning up on reverse image search

Fig. 9 — Manipulated imagery at a glance. The same visual forensics approach used to compare authentic and altered product packaging applies directly to profile photos: look for inconsistent lighting, mismatched details, and signs that the image has been recomposed or synthetically generated rather than photographed.

For deeper forensic checks: pull the image’s EXIF metadata (Jeffrey’s Exif Viewer, ExifTool); stripped or contradictory GPS/timestamp data is suspect. Run Error Level Analysis at FotoForensics.com to spot inconsistent JPEG compression from digital editing. AI-generated faces have their own tells: unnatural symmetry, mismatched eye reflections, and hair that blends unnaturally into the background; tools like Hive Moderation and Illuminarty are built specifically to catch these.

8. Social Media & Background Checks

A legitimate business maintains active, aging social media accounts with genuine engagement. Fake operators typically spin up accounts concurrently with the fraudulent site: recently created, with low organic follower counts, generic, recycled content, and no history predating the current campaign.

SOCIAL MEDIA VERIFICATION PROTOCOL

  • Check account creation date — under 6 months old warrants scrutiny
  • Review posting history for continuity and genuine engagement
  • Check whether followers are identifiable, established accounts
  • Cross-reference profile photos against the website’s team photos
  • Look for location mismatches between the social profile and the site
  • Search for independent third-party mentions of the business

9. Third-Party Trust Marks

Fake websites frequently borrow the logos of well known organizations to imply a partnership, accreditation, or reseller status that doesn’t exist. Research from the European consumer organization ANEC found that seven in ten people say they’re more likely to trust a site displaying a trust mark logo, which is precisely why these are so often faked or unlinked.

Relationship Type What It Actually Means
Affiliate Promotes another company’s products for commission; not an authorized dealer
Authorized reseller Formally listed in the parent company’s own partner directory
Channel partner Enrolled in a formal partner program with brand-use agreements

Verification protocol: click every trust seal; a genuine one redirects to the issuer’s own verification page. Search the claimed parent company’s site for an official “Partner Finder” or “Authorized Reseller Locator.” And keep the three credential types straight: accreditation applies to organizations and is voluntary; licensing applies to individuals or facilities and is legally required; certification demonstrates a specific capability and is issued by a professional body. Each has its own public registry to check against.

10. Customer Reviews & Testimonials

Third-party reviews (Google, Yelp, Trustpilot) are independent of the business; testimonials on the site itself are curated by the operator and may be entirely fabricated. Watch for:

  • Fake negative reviews used as endorsements: e.g., a “complaint” that a diet pill worked too well
  • Duplicate reviews: with only minor word substitutions, a signature of AI-generated bulk campaigns
  • Buzzword saturation: the same promotional phrases recurring across many reviews
  • Reviews predating the product’s actual launch date: a definitive giveaway
  • Generic one-liners with no specific, checkable detail

To check authenticity, paste two to four distinctive phrases from a review into a quoted Google search. Identical text across multiple platforms confirms manufactured content.

11. AI-Era Threats: Cloning, Cloaking & Deepfakes

This is the fastest-moving part of the landscape. LLM-powered site builders can now clone a legitimate homepage’s visual design, functional navigation, meta tags, cookie banners, and even fabricated testimonials from a single screenshot or prompt output that’s increasingly indistinguishable from the original to a casual visitor.

A more insidious technique, documented against AI browsing agents like Perplexity’s Atlas and ChatGPT’s browsing tool, is AI cloaking: a site serves safe, legitimate-looking content to automated crawlers and fact-checking bots, while serving fraudulent or harmful content to human visitors. The implication is significant. No automated trust scanner should be treated as definitive on its own. Manual, multi-source verification is specifically resistant to this evasion.

0%
Deepfake fraud increase over 3 years (Keepnet Labs)
0
AI content-farm sites tracked across 16 languages (NewsGuard, 2026)

A Current Researcher’s Toolkit

Tool Use
ScamAdviser Trust score from 40+ data sources and law-enforcement reports
URLVoid / Google Safe Browsing Multi-engine blocklist and malware reputation checks
ICANN Lookup / Whois Domain registration date, registrar, registrant country
WeVerify / InVID plugin Reverse video search, keyframe and metadata analysis
FotoForensics.com Free Error Level Analysis for image tampering
Hive Moderation / Illuminarty AI-generated image detection
crt.sh Public Certificate Transparency log to audit a site’s TLS history

12. Quick Reference Checklist

Before trusting a site especially one asking for money or personal information run through this condensed version of the full audit:

HOMEPAGE & POLICY

  • Logo passes reverse image search (not a stock or unrelated-brand match)
  • Navigation is real HTML, not a single flat image
  • Privacy policy and terms fail a plagiarism check (i.e., are original)
  • Copyright notice is current and correctly formatted

IDENTITY & CONTENT

  • Named executives verified via LinkedIn and professional directories
  • Business registration confirmed in a public corporate registry
  • Physical address verified on Google Street View
  • No systemic grammar errors — or suspiciously “perfect” but unverifiable content

TRANSACTIONS & TRUST MARKS

  • HTTPS confirmed and certificate details checked
  • Trust seals are clickable and verify with the issuer
  • Two independent confirmation emails received after purchase
  • Claimed affiliations verified directly with the parent company

AI ERA CHECKS

  • Domain registration date checked via Whois
  • URL scanned in ScamAdviser or Google Safe Browsing
  • Site re-inspected in incognito mode (bypasses some AI cloaking)
  • Any video or executive photo run through reverse search and tamper analysis

Source:

This article is adapted from AOFIRS CIRS™ Training Module 9, Unit 23 — “Identifying Fakes in Website Content Pages: A Combined Research Report & Professional Training Guide.” Read the full report at https://aofirs.org/research-reports/identifying-fake-website-content-pages-research-training-guide/.
Watch video: The 5 Step Fraud Audit How to Expose AI Cloned Websites & Scam Pages
Read Research Report: Identifying Fakes in Website Content Pages
View infographics: Researchers Guide to Identifying Fake Websites
Explore Slide Deck: Identifying Fakes in the AI Era: A Visual Verification Toolkit for Investigators

Share This Story