uma
Member
OP
99.99% or bust
- Joined:
- Jun 2024
- Posts:
- 324
- From:
- Dublin, IE
I have been stung twice this year by hosts that looked legitimate but vanished within 45 days. The graphs don't lie, but only if you are looking at the right ones. Here is my current checklist before I put money down:
- Check the ASN registration date versus the brand launch date. If they are weeks apart, walk away.
- Probe the status page. Fake status pages return 200 for every region with identical timestamps. Real ones have noise.
- Look for alert fatigue in their changelog. A host that never reports incidents is a host that never reports incidents.
- Test the abuse email. Bounce or auto-reply only? That is your support experience in six months.
- Search the deal title verbatim. Scammers recycle copy across shell brands.
- Check if their "about us" team photos reverse-search to stock libraries.
I caught three this way in January alone. What am I missing?
436 days. reboot is surrender.
ana_mad
Member
- Joined:
- Jun 2024
- Posts:
- 298
- From:
- Madrid, ES
Great checklist uma! Sent abuse test to a host last month and got bounce in 2 hours, made test order anyway because price was so low... big mistake! Now I add abuse response time to my notes.
Also check if they have valid VAT or business registration, sent ticket yesterday to one host and he could not provide it! Cheers
swimming upstream since 2019 🐟
sofialund
Member
homelab heatstroke
- Joined:
- Jul 2024
- Posts:
- 140
- From:
- Buenos Aires, Argentina
Bulk subdomains always mean fake brands?
hot air, steady hand, magic smoke
uma
Member
OP
99.99% or bust
- Joined:
- Jun 2024
- Posts:
- 324
- From:
- Dublin, IE
If they match to the second across three continents
Exactly. I found one last month where Tokyo, Frankfurt and Sydney all reported "14:00:00" with no timezone offset. The page was a single PNG.
Another tell: real status pages have RSS or webhook history going back years. Fakes have thirty days if you are lucky.
436 days. reboot is surrender.
sofialund
Member
homelab heatstroke
- Joined:
- Jul 2024
- Posts:
- 140
- From:
- Buenos Aires, Argentina
Bulk subdomains not always fake but always suspicious. I found one host with eight brands sharing one Let's Encrypt cert. The CT log was a birthday party of their own making.
Mi homelab now runs a script to check cert transparency before I buy anything. Saved me twice already.
hot air, steady hand, magic smoke