A real enquiry we received, the checks we ran, and why we declined to quote.
In August 2026 we received a website enquiry through our contact form. It was a restaurant project — the kind of work we do routinely — and we very nearly sent a quote.
We didn’t. After a few hours of ordinary verification, we assessed the lead as high risk and chose not to proceed.
This is what we checked, in the order we checked it. Every check is one you can run yourself, most of them in minutes.
Three things to be clear about before we start.
This was a manual investigation, not a product verdict. We build ScamCheck, a free scam-detection tool for consumers — it checks messages, links and screenshots. We did not run this lead through it, and ScamCheck did not flag, score or detect anything here. What follows is a background check done by hand: public domain-registration records, DNS and HTTP responses, a crawl of the reference website, public-web research, and exact-phrase searches. We think that distinction matters, so we are stating it plainly rather than dressing up a manual investigation as a product demonstration.
We are not naming anyone. We have withheld the prospective client’s name, email address, the exact domain, the city, and the dates. We have also withheld the identity of the restaurant whose website we were given as a design reference — that business is real, legitimate and entirely uninvolved. This article is about a pattern, not a person.
Nothing was lost. No payment was requested or received. No development work began. No money changed hands in either direction, and no fraud loss occurred in this case. We declined before the conversation ever reached a payment stage — which also means we cannot tell you what would have happened next, and we won’t pretend otherwise.
1. The lead looked completely normal
The first contact arrived through our website contact form. Some weeks later, a detailed brief came back on the same thread.
Paraphrasing: the prospective client said they had opened a new restaurant in a US city and needed a website to grow the business. The brief supplied a reference website — a real, established restaurant in another state — and asked for something better. It specified the same overall page structure, English only, hosting included in the estimate, ongoing updates handled by us, and a launch date roughly six weeks out. Content, logos and artwork would come from a private project consultant. The budget was described as “super flexible”. It asked for a price estimate and a mobile number.
Read that again, because this is the part most scam-awareness writing gets wrong: none of it is unusual.
Restaurants need websites. Clients supply reference sites — most do. Asking for hosting in the estimate is normal. Wanting ongoing updates is normal. Having someone else hold the brand assets is normal; plenty of small businesses use a marketing consultant or a designer. A six-week deadline is tight but ordinary. A free email address means nothing at all — a large share of legitimate small businesses run on one.
We want to be precise here, because paranoia is expensive. Not one of those signals, on its own, is evidence of anything. Treat them as red flags and you will insult real clients and lose real work.
Only two details sat slightly apart. The budget was volunteered as open-ended, unprompted. And one requirement didn’t quite make sense.
2. The first strange detail
The brief asked for a shopping cart on the reservation page.
That phrase has no clear technical meaning. It could reasonably describe several different things:
- taking a deposit or card hold on a booking, to protect against no-shows
- selling tickets to events — a set menu, a live-music night, a holiday sitting
- letting people order food while booking a table
- an actual e-commerce cart for merchandise or gift cards
Those are four different products, with four different platforms, four different fee structures, and roughly a tenfold spread in build cost. They are also different intents — booking a table and buying a product are separate journeys that generally shouldn’t share one interface.
The ambiguity by itself wasn’t suspicious. Clients describe features in non-technical language constantly, and clarifying that is ordinary scoping work.
What made us pause was narrower. The brief said it wanted the same structure as the reference site — but nothing resembling a cart appeared on the reference site.
That is a mismatch between a stated source and a stated requirement. Unlike most of what arrives in a sales enquiry, it is also objectively checkable. So we checked it.
The lesson: when a requirement doesn’t correspond to the reference the client says they took it from, don’t paper over it. It is either a misunderstanding worth one email, or a sign the brief didn’t come from where the sender says it came from. Both are worth knowing before you price the job.
3. The domain contradiction
The brief said the prospective client did not yet have a domain, and named the one they wanted.
We looked it up — a free, instant, entirely public check using registry records rather than a reseller’s availability box.
The domain was already registered. It had been registered five days before the brief arrived.
It resolved to a registrar parking page. There was no website. The Internet Archive held no snapshot of it at any point — it had never hosted anything. The registration contact details were redacted, which is standard privacy protection at most registrars and is not in itself suspicious.
Here is how to read that responsibly, because it’s easy to overreach.
The requested name was a coined, unusual string — not a generic phrase a stranger would plausibly land on by chance. So the registration was, in all likelihood, connected to the sender’s side rather than an unrelated third party. There are two honest readings of that, and we cannot distinguish between them:
- Benign: the consultant secured the name and the prospective client either didn’t know, or meant “I don’t have a website yet.” This happens. It would even be mildly reassuring — it suggests someone had spent money on the project.
- Adverse: the domain was registered to make the enquiry look substantiated, and to create a line item in the quote that we would be asked to fund.
We could not tell which, and we still can’t. Registration data is redacted for good reasons, and we made no attempt to work around it. We are not asserting who registered that domain.
But either way, we now had a verifiable inconsistency between a statement in the brief and a public record — plus one hard commercial consequence: we could not quote to supply a domain that was already registered to someone else. We could not deliver it.
The lesson: a domain check is free, takes about thirty seconds, and returns a fact rather than an impression. It doesn’t prove intent. It tells you whether the story is internally consistent — a different and more useful thing.
4. What the reference site actually contained
Clients describe their reference sites from memory, and memory is unreliable. So we crawled it rather than trusting the description — the homepage, every subpage, the robots file, the sitemap.
What we found:
- Reservations were handled by an embedded third-party booking widget sitting in a section of the homepage. There was no reservation page at all.
- Online ordering was an outbound link to a third-party ordering platform. Ordering happened entirely off-site.
- There was no shopping cart anywhere on the site — no cart, no checkout, no basket, no payment form, on any page.
- The reference restaurant was in a different state from the city named in the brief.
So the requested feature did not exist on the reference site. Neither did the page it was supposed to sit on.
Worth stating plainly: the brief described a feature on a page, and the site it claimed to be following had neither the feature nor the page.
The crawl was commercially useful too, and this part applies to every project, suspicious or not. The reference site was built on a subscription website product rather than as a custom build — which means quoting a bespoke project against it anchors your price to the wrong thing. It also had weaker technical foundations than the brief’s “make it better than this” implied, and we’d have said so in a real proposal.
The lesson: inspect the reference yourself, always. It takes fifteen minutes, it tells you what you’re actually being asked to build, and it prices the job properly. Here, it turned a vague unease into a concrete finding.
5. The pattern match
This is the check that changed the decision.
The phrase “shopping cart on the reservation page” was odd enough that we searched it as an exact string, along with other distinctive wording from the brief.
The wording is publicly documented. In January 2025, a design studio published a scam-alert post reproducing, in full, an enquiry template it had received. That published template contains — in the same order, with the same construction — the reservation/cart line, a line about a private project consultant who holds the text content, logos and image artwork, a line requiring hosting in the estimate, a line about the price for a yearly update, a line asking for the same pages as the example site, a line specifying English only, a line confirming the recipient would be maintaining the site, and a line stating the sender has no domain yet and naming a preferred one. (Bianca Frank Design, 10 January 2025)
A second, independent source documents the same approach with the same cover story: an enquiry through an agency’s contact form, from someone describing a newly opened Irish restaurant in a Texas city, supplying a reference website, and describing the budget as “SUPER FLEXIBLE” — capitalised exactly that way. In that documented case the exchange proceeded to a quote, and then to a request to pay by mailed cheque. (EnspireFX, 16 February 2025)
Several other agencies have independently described receiving enquiries with the same structure, and specifically the “private project consultant holds all the content” line. (ZANZARRA · Alvalyn Creative)
Two points of honesty about what this does and doesn’t establish.
A template match is not an identity match. It establishes that the enquiry we received closely matched wording that has been publicly documented and circulated. It does not establish who sent it, or what they intended. Templates get copied, adapted and reused by different people, and we have no way to know which applied here.
The strength came from convergence, not from one sentence. A single odd phrase proves nothing. What mattered was that several independent checks pointed the same way: a public registry record inconsistent with a statement in the brief; a requested feature absent from the reference it was supposedly drawn from; distinctive wording matching a published template; and a claimed business we could find no independent trace of.
On that last point we want to be careful. We searched review sites, reservation platforms, delivery platforms, local directories, local press and publicly searchable permit information, and found no record of the claimed business. That is not proof it doesn’t exist. A genuinely new restaurant can be nearly invisible online for months, and some registries we’d have liked to check sit behind paid logins or form-only searches we chose not to use. Absence of a record is a weak signal, and we counted it as one.
6. The decision
We assessed the lead as high risk and stopped.
Specifically, we did not:
- send a price estimate
- give out a mobile number
- purchase any domain
- accept or agree to any payment arrangement
- begin any design, content or development work
We made no accusation then and we make none now. Our position was, and remains, that multiple inconsistencies emerged, that we could not independently verify the claimed business, and that this was sufficient for us to decline the opportunity without further engagement. Another agency looking at the same facts could reasonably have asked more questions instead. That would also have been defensible.
The one thing we’d have done to keep the door open costs nothing: ask for the registered business name, the physical address, and the food-service or licensing permit numbers — with no price attached. A real restaurant owner has those to hand in five minutes; they’re on their own paperwork. It’s a fair, non-accusatory question, and it resolves the matter either way.
7. The risk pattern this resembles
We need to be careful in this section. We did not reach a payment stage, so nothing below is something we observed in this case. What follows is the documented pattern that the published sources describe — a known risk pattern, not a finding about this enquiry.
The scheme those sources describe is generally known as an overpayment, payment reversal, advance fee, or third-party payout scam. It’s an old mechanism in new clothing — structurally the same thing we’ve written about in the context of overpayment and “refund the difference” requests and chargeback scams against sellers.
As documented, the shape is:
- A supplier is engaged and issues a quote.
- Payment arrives by an instrument the supplier didn’t propose — commonly a mailed cheque, sometimes a card payment — often for more than the invoiced amount.
- The supplier is asked to forward the excess to a third party. This is usually the “consultant” introduced early in the conversation.
- The original payment is later reversed or found to be fraudulent, weeks after the supplier has already sent real money onward.
Where that pattern plays out, the loss is not the unpaid work. The loss is the money forwarded. The unpaid labour is secondary. That structure is also why, in the documented cases, the consultant appears at the briefing stage rather than the payment stage, and why an open-ended budget is offered — a larger quote produces a larger sum to forward.
We’re deliberately not detailing the persuasion tactics used at the payment stage. The recognition signals above are what a supplier actually needs.
8. The checks worth running before you quote
Run these on any inbound project from a client you can’t verify. Most take minutes.
Verify the principal
- Ask for the registered business name and physical address. Real businesses answer immediately.
- Ask for a permit or licence number where the trade requires one.
- Look for the business independently — maps, reviews, local press, industry directories.
- Ask for a short video call. Treat an unexplained refusal as information, not proof.
- Remember: not finding a new business online is weak evidence. Weigh it lightly.
Verify the technical story
- Look up any domain named in the brief in public registry records. Check registration date, status and whether it resolves.
- Check the Internet Archive for whether it has ever hosted anything.
- Crawl the reference site yourself. Don’t rely on the description.
- Confirm every requested feature actually exists on that reference. Investigate any mismatch.
- Search distinctive phrases from the brief as exact strings. This is the highest-yield check here and it takes under a minute.
Protect the commercials
- Separate your development fee from third-party costs. Never bundle domains, hosting or platform subscriptions into one number.
- Have clients buy their own domain, hosting and platform accounts in their own name, on their own card. You configure; you don’t fund.
- Take a deposit in cleared funds, by a method you propose, before work starts.
- Never forward client funds to a third party. No exceptions.
- Never accept an overpayment. Return it by reversing the original transaction, never as a separate payment.
- Decline cheques and unusual instruments for remote commercial work.
- Don’t buy domains or services on behalf of an unverified prospect.
- Get a signed scope with a written change-order process before building anything.
Weigh the signals correctly
None of these, alone, means anything:
| Not a red flag | Why |
|---|---|
| A free email address | Most small businesses use one |
| A slow reply | People are busy |
| A thin online footprint | Every new business has one |
The .com already being taken | True of most short domains |
| Redacted domain registration data | Standard privacy protection |
| Picking the wrong service on your contact form | Extremely common |
| Imperfect English | Correlates with nationality, not fraud. Never treat it as a signal |
What matters is several independent checks failing at once.
9. A reusable seven-stage verification workflow
Stages 1–5 cost almost nothing and can run before you reply. Stages 6–7 apply once money enters the conversation.
| Stage | Question | What you check | Outcome |
|---|---|---|---|
| 1 — Identity | Who is this? | Named individual, business email, reachable role | Proceed / ask |
| 2 — Business | Does the business independently exist? | Maps, reviews, directories, press, permits, registries | Verified / not found / unknown — never “fake” |
| 3 — Domain | Does the domain story make sense? | Registry record, registration date, resolution, archive history | Consistent / inconsistent |
| 4 — Requirement | Does the request make technical sense? | Crawl the reference; confirm each named feature exists | Coherent / mismatched |
| 5 — Pattern | Has this wording been seen before? | Exact-string search on distinctive phrases | Clean / documented match |
| 6 — Payment | Is anything unusual about the money? | Instrument, third-party routing, overpayment, pressure | Normal / anomalous |
| 7 — Decision | Proceed, clarify, verify, or decline? | Weigh stages 1–6 together | Never on one stage alone |
How to weight it:
- One soft signal (stage 2 “not found”, a tight deadline) → proceed normally, ask a question.
- One hard signal (stage 3 inconsistency, stage 4 mismatch) → pause and clarify before quoting.
- Two or more hard signals, or any stage 5 match → verify formally before any quote.
- Any stage 6 anomaly → stop. Especially any request to forward funds onward.
Stages 3, 4 and 5 are the ones that produce facts — a registry record, a crawl result, a string match. Stages 1, 2 and 7 are judgement. Weight the facts more heavily.
The question you’re answering is not “is this person a criminal.” You can’t answer that, and you shouldn’t try. It’s: has this prospect given me enough verified information to safely commit time and money? If not, ask for it. A real client will give it to you.
What this taught us about our own product
One honest observation, clearly labelled as a future direction and not a current capability.
The decisive check in this investigation was noticing that distinctive wording matched a template that had been reused with a few details swapped — a different city, a different reference site, a different domain. That is a mechanical pattern, and mechanical patterns are the kind of thing software detects well.
ScamCheck does not do this today. It is built for consumer messages, links and screenshots, and it has no path for evaluating a business enquiry. Whether that should change — and whether template-matching can be made reliable enough to be useful rather than merely noisy — is something we’d need to validate properly before building anything. We’re recording it as an idea worth testing, not as a feature we’re announcing.
Frequently asked questions
How can a web designer verify a new client?
Ask for the registered business name, the physical address, and any permit or licence number the trade requires — then check those against public records and independent sources like maps, reviews and local press. Add a short video call. These are ordinary commercial questions, and a legitimate client will answer them quickly.
Why is a requested domain worth checking?
Because it’s free, instant, and returns a fact rather than an impression. Public registry records show when a domain was registered, whether it resolves, and whether it’s active, and the Internet Archive shows whether it has ever hosted anything. If a client says a domain is unregistered and the record shows otherwise, that’s worth one polite question. It is not, by itself, evidence of wrongdoing.
Why should reference websites be inspected?
Because a brief describing a reference site is a description from memory, and it may not match reality. Crawling the site yourself tells you what you’re actually being asked to build, prices the job correctly, and reveals any requested feature that doesn’t exist on the reference. That last mismatch is one of the few objectively checkable things in a sales enquiry.
What is an overpayment scam?
A documented fraud pattern in which a payment arrives for more than the invoiced amount and the recipient is asked to forward the difference to a third party. The original payment is later reversed or found to be fraudulent, leaving the recipient out of pocket for the money they forwarded. We cover the mechanism in detail in our guide to the “refund the difference” trick.
Should a freelancer ever forward client money to a third party?
No. There is no legitimate business reason for a client to route their consultant’s or supplier’s payment through you. If money needs to reach a third party, the client can pay them directly. Treat any request to forward funds as a stopping point regardless of how reasonable the explanation sounds.
What should you do when several unusual signals appear at once?
Stop and verify before quoting rather than trying to judge intent. Single unusual signals are common in legitimate enquiries and mean very little on their own. Several independent checks failing together — particularly ones that produce verifiable facts, like a registry record or a site crawl — is the point at which formal verification is warranted.
What if you’re wrong and the client was genuine?
Then asking for a business name, an address and a permit number costs you one email, and you get the job. Verification questions are normal commercial practice. Any client offended by them was going to be difficult anyway.
Where do I report this kind of approach?
In the US, the FTC and the FBI’s IC3. In the UK, Action Fraud. In India, cybercrime.gov.in or 1930.
Related reading
- Overpayment Scam: The ‘Refund the Difference’ Trick, Explained — the underlying mechanism
- Chargeback Scams for Sellers — payment reversal after delivery
- How to Verify a Payment Before You Ship — the same discipline for physical goods
- Fake Wire Transfer Proof Scam · Fake ACH Transfer Scam — when “payment sent” isn’t
- How to Identify Phishing Emails — inbound message red flags
- What To Do After Being Scammed — recovery steps
Sources
Our own investigation. Public domain-registration (RDAP) records, public DNS resolution, live HTTP response headers, Internet Archive availability records, and a direct crawl of the reference website including its robots file and sitemap. All performed read-only in August 2026.
Independent documented cases. Bianca Frank Design (10 Jan 2025) publishes the enquiry template in full. EnspireFX (16 Feb 2025) documents a complete exchange using the same cover story. ZANZARRA and Alvalyn Creative independently report the same approach, the latter a first-hand account that ends in bogus money orders for more than the agreed amount.
These are practitioner accounts published by working agencies and designers, not law-enforcement data or peer-reviewed research. We cite them as credible documentation of a recurring pattern, which is what they are.
General advice. The checklists in sections 8 and 9 are our own operating practice, developed from this investigation and our general commercial experience. They are not drawn from any single source.
This case study describes a real enquiry received by A Square Solutions. The prospective client’s name, email address, the exact domain, the city and the dates have been withheld. The reference website has also been withheld — that business is real, legitimate and entirely uninvolved. We make no allegation of criminal conduct against any person. No payment was received, no development work began, and no fraud loss occurred. We declined before any payment was discussed and cannot say what would have happened had we continued.

