Skip to content

What do you use for testing if a deal is too good to be true?

Deals & Offers by uma 16 replies 1.5K views
#1

I have been stung twice this year by hosts that looked legitimate but vanished within 45 days. The graphs don't lie, but only if you are looking at the right ones. Here is my current checklist before I put money down:

  • Check the ASN registration date versus the brand launch date. If they are weeks apart, walk away.
  • Probe the status page. Fake status pages return 200 for every region with identical timestamps. Real ones have noise.
  • Look for alert fatigue in their changelog. A host that never reports incidents is a host that never reports incidents.
  • Test the abuse email. Bounce or auto-reply only? That is your support experience in six months.
  • Search the deal title verbatim. Scammers recycle copy across shell brands.
  • Check if their "about us" team photos reverse-search to stock libraries.

I caught three this way in January alone. What am I missing?

436 days. reboot is surrender.
#2

He my VPS it crashed because the host he was 14 days old kkkkkkkk nossa I not even checked the WHOIS before, very shame

Now I check the domain age and the abuse email, if he bounce I run more fast than my VPS when he boot caramba!

#3

Great checklist uma! Sent abuse test to a host last month and got bounce in 2 hours, made test order anyway because price was so low... big mistake! Now I add abuse response time to my notes.

Also check if they have valid VAT or business registration, sent ticket yesterday to one host and he could not provide it! Cheers

swimming upstream since 2019 🐟
2 #4
uma said:
What am I missing?

- certificate transparency logs. Search for subdomains registered in bulk.
- nameserver clustering. Twelve brands, one cloudflare account.
- the whois history shows three prior drops for gambling domains.

-t

#5

What tools do you use to probe the status page?

#6

I had same issue with host vanishing in 30 days.

#7

Bulk subdomains always mean fake brands?

hot air, steady hand, magic smoke
#8
uma said:
Probe the status page. Fake status pages return 200 for every region with identical timestamps.

I wrote a quick bash thing for this. Curls all their regions and diffs the timestamps. If they match to the second across three continents, you know it is static HTML dressed up.

Also check the response headers for x-powered-by. Real status pages usually run on something you can name. Fakes often hide nothing or lie badly.

8 #9
flyplat said:
If they match to the second across three continents

Exactly. I found one last month where Tokyo, Frankfurt and Sydney all reported "14:00:00" with no timezone offset. The page was a single PNG.

Another tell: real status pages have RSS or webhook history going back years. Fakes have thirty days if you are lucky.

436 days. reboot is surrender.
3 #10

Bulk subdomains not always fake but always suspicious. I found one host with eight brands sharing one Let's Encrypt cert. The CT log was a birthday party of their own making.

Mi homelab now runs a script to check cert transparency before I buy anything. Saved me twice already.

hot air, steady hand, magic smoke

Post a reply

You need an account to reply. Log in or register to join the conversation.

Post reply Preview Save draft