If a mail message is apparently from the company which has sponsored your
toolbar, then to visit the site, use the links in the toolbar itself rather
than any link that you may receive in an electronic mail message. This protects
you against forged mail messages sent to you by fraudsters, where a URL
purporting to be to your bank's site actually links to the fraudsters' site.
The toolbar provides you with a wealth of information about the sites you
visit. This information will help you make an informed choice about the
integrity of those sites. Here is a brief list of points you should be aware of
when visiting a site which requires you to enter personal information of any
kind:
Look at the toolbar to see whether the site's netblock is registered to the company
you expect.
Look at the country code and flag on the Toolbar to check that the site is
hosted in the country that you expect. There is a list of countries which are
often used to host fraud sites here.
Who is the site's domain registered to? Be suspicious if this is not
the organisation you expect.
Who is running the DNS and reverse DNS for the site? Be suspicious if
these are not run by a host in a domain controlled by the organisation.
How new is the site? All other things being equal, the longer a site has
been around, the more you can trust it. "New Site" means the site you
are currently visiting has not been seen before by the Netcraft Web
Server Survey. This indicates that the site is probably less than one
month old. Phishing sites spring up overnight and disappear just as
quickly, and you should be extremely suspicious if you see this when
visiting what you believe to be a trustworthy site.
Does it have an SSLCertificate? Bank sites
that take authentication details will do this over SSL. Details of the SSL
Certificate (if any) will appear in the site report.
Is the site in the DNS? If the site has no hostname or domain name and
is a raw IP address be very suspicious.
If you are convinced that the site is a phishing site, please report it. If you are unable to report the URL via the
toolbar site, please send us the entire mail message intact as an attachment.
If you use Outlook you can do this by composing a new mail to toolbar@netcraft.com and dragging the fraud
mail on to it as an attachment.
Netcraft will send a reward to the first person to report each new
phishing site.
Let's take a look at an example. Below is a phishing attack aimed at customers of SunTrust Banks
which we received.
Note that the Toolbar shows that the site is hosted in the USA, at "Inktomi Corporation", and that the site is new. The
real SunTrust web site is
hosted in the USA at SunTrust Service Corporation.
Comparing the site reports is also telling; the fraudulent site's report contains many 'unknowns' whereas the
site report for the real
SunTrust web site shows plausible domain registration and DNS details.
You can find out more about reporting URLs in the tutorial on
reporting a suspicious URL.