Most of the scams on this blog take your money. This one takes your money and then takes something else along with it: a little of your willingness to ever give again. It isn't clever. It just waits for the exact moment somebody decides to be generous. That second theft is the part worth being angry about.

What does the FTC say is happening?

On 27 August 2026 the FTC published a consumer alert titled "When donating, support those in need, not a scammer." It's a warning that comes back after every major disaster, for the simple reason that the scam comes back after every major disaster.

The pattern they describe is not complicated: scammers set up charities that look official and claim to help people affected by a disaster, and they may also impersonate well-known charity organizations, counting on a familiar name to pull in your donation.

This scam doesn't need to be convincing for long. It only needs to survive the ninety seconds between "that's awful" and "donate". Urgency and sympathy are the two states in which we check the least โ€” and a disaster hands the scammer both at once.

Notice that there are two halves here. Some of these are invented organizations with perfectly plausible names: a "relief fund", a "disaster response network", something with the affected region in the title. Others are impersonations of a real charity you already trust, sitting on a domain that isn't theirs.

The invented ones are harder to catch by reading. There's no real name to compare against, because you have never seen the correct spelling of an organization that doesn't exist. ๐Ÿ˜…

Why is domain age the thing that matters here?

Most of this blog is about reading a domain carefully โ€” the swapped letter, the extra hyphen, the subdomain that parks a brand's name to the left of the real address. All of that still applies when a real charity is being impersonated.

But for the invented-organization version, the giveaway isn't spelling. It's timing.

A real relief organization has been serving donation pages from the same domain for years, because it existed before this disaster and it will still exist after it. A fund invented to collect donations for this event was registered after this event. That gap is the entire scam, and it sits right there in the domain's creation date.

Expecteda long-established relief domainregistered years before the disaster
Contradictiona "disaster relief fund" domainregistered days after the disaster it serves

Now, let's be fair about what this does and doesn't prove. Genuine grassroots fundraisers get set up quickly too, and a neighbor raising money for their flooded town will absolutely be on a domain that's a week old. A new domain is not evidence of fraud. Of course it isn't.

What it does is tell you which claim to test. A national organization presenting itself as long-established, on a domain registered last Tuesday, is saying something the record disagrees with.

And how do they want to be paid?

Domain checks only cover the address. The payment method is a signal all of its own, and it's worth knowing the shape of it. A genuine charity can take an ordinary card payment and send you a receipt. Pressure toward methods you can't reverse โ€” wire transfers, gift cards, payment apps to a personal account, cryptocurrency โ€” is a loud signal, because being irreversible is the whole point of choosing them.

A charity that can take a card but would really prefer a wire has just told you something about its plans for your money. ๐Ÿ˜‰

How do you check a donation page in about a minute?

  1. Don't use the link you were sent. This is the whole game. An email, a social post, a text โ€” the link inside it is the one thing that cannot verify the thing it points at.
  2. Look the organization up on your own. Search for it by name, or check a charity evaluator like Charity Navigator or the BBB Wise Giving Alliance at give.org. The FTC's own guide to donating safely walks you through it too.
  3. Compare the two addresses character by character. Copy them, don't retype them. Retyping silently fixes the very difference you're looking for.
  4. Check how old the domain is against the claim the organization makes about itself.
  5. Look at how they want to be paid. Wire, gift cards or crypto is a stop sign.
  6. Give yourself a day. Real need doesn't expire overnight, and a charity worth supporting on Tuesday is still worth supporting on Wednesday. Urgency is the scammer's tool, not the charity's.

So what can IP Tracker actually do here?

IP Tracker is my free Chrome extension. Paste a domain or a full email address into the popup; the free tier gives you 25 checks a day, no account, no tracking. Only the value you paste is looked up.

The limitation first, because you should hear it from me rather than discover it later. IP Tracker cannot tell you whether a charity is legitimate. It checks domains, not organizations. It has no idea whether a nonprofit is registered, whether it spends donations sensibly, or whether it exists at all. The lookalike comparison runs against about 125 heavily impersonated brands โ€” banks, couriers, payment services, big tech, government โ€” and charities aren't on that list. That question belongs to a charity evaluator, and no domain lookup will ever replace one.

What it does show you, in a few seconds, is the record around the address:

Every one of these is a signal for your judgment, not a ruling. "Nothing found" means the checks came back empty. It does not mean "this charity will spend your money well." IP Tracker surfaces what the record says about a web address. Who deserves your donation is still your call, and a charity evaluator is the better tool for that half.

To summarize

One last thing, and I mean it. None of this is an argument for giving less. The scammers would love that outcome too. It's an argument for giving one minute later than you were going to.

Happy giving! ๐Ÿ˜Š

Sources