A globe lit by a radar sweep against a dark green background

For Hotel and Chain Brands

We detect the fake sites using your name
the very moment they go live…

Fraudsters register domains that look almost exactly like yours, buy ads to rank at the top of search results, and defraud people who believe they are booking a real holiday — using your identity. Serpify was built to find those sites and channels early.

How we do it

A six-stage pipeline

Every morning all steps run in order. It starts from tens of thousands of possibilities and narrows down to the handful of files that need a human look.

  1. 01

    Discovery

    Lookalike domains, social media accounts, Telegram and Google ads. Five separate sources, each running independently.

  2. 02

    Enrichment

    Every address found is visited with a real browser; the page text, its screenshot, the domain record and the network details are collected.

  3. 03

    Scoring

    The collected data is turned into a risk score with stated reasons.

  4. 04

    Evidence

    For every site above the threshold, a full-page screenshot, an HTML copy and a signable PDF evidence pack are produced.

  5. 05

    Filing

    Depending on the case, you pick the authorities to file with from the admin panel, and the text for each one is drafted automatically in its own language.

  6. 06

    Report

    Only new findings are sent to you by email, every day.

Where we look

One source is never enough

We do not rely on a single source: automated searches run across every likely channel — lookalike domains, Google ads bought against your name, similar social media and Telegram accounts.

Domain permutation

We generate spelling variations from your brand and property names systematically: dropped letters, inserted letters, adjacent-key typos, look-alike characters (rn ↔ m, l ↔ I), inserted hyphens, and suffixes such as reservation, booking or official. These are combined with 18 different extensions and queried against DNS as more than forty thousand addresses on every scan; only the ones that actually exist enter the candidate list.

Certificate transparency logs (crt.sh)

When an HTTPS certificate is issued for a site, the record is written to a public log — so the name appears there before the site is even online. The system scans these logs with "brand + context word" and "brand + property name" patterns, which automatically filters out hundreds of unrelated records such as yournamesugar.com.

Search results (Google)

A site that does not even carry your brand in its name can rank first for "your brand reservation" by buying ads. The system runs the queries a guest would actually type — your brand and property names — in several languages and collects the organic results.

Paid ads (official archives)

The Google Ads Transparency Center and the Meta Ad Library are queried, limited to the Türkiye region. For a given domain we see the live ads and who is paying for them. Advertising against your brand name becomes a scored signal.

Social media profiles

Accounts using your brand and property names on Instagram and Facebook are found through the same search infrastructure. These channels matter especially for threats with no fake website at all: the fraudster sometimes builds no site, chats with the guest from an Instagram account using your name and your content, moves the conversation to their own WhatsApp, and shares the bank account details there.

Telegram channels

Channels and groups using your brand and property names are scanned. The public preview of each channel is read, and bank account numbers, phone numbers and the domains being pushed are extracted one by one. Operations that run entirely through a channel, with no website at all, are caught here.

Why Telegram?

That is where the operation is coordinated

Fraud operations in Türkiye largely coordinate on this platform: fake site templates, "clean" bank accounts and victim lists circulate in open channels. The public preview of those channels is read, and bank account numbers, phone numbers and the domains being pushed are extracted from the messages.

On Meta's channels Serpify looks at publicly available search results. The fake profiles it finds are reported through Meta's own official forms.

How we collect

Every address is visited with a real browser

Each address on the detection list is opened in the background with a real Chrome browser, and the following are checked one by one:

  • Full-page screenshot
  • HTML copy of the page
  • Page text
  • Domain registration record (RDAP)
  • IP address and name servers (NS)
  • Payment and form traces
  • WhatsApp numbers
  • Claimed TÜRSAB licence number
A case record in the Serpify panel — brand names are masked
A case record from the panel. Real brand names and domains are masked.

How we score

Every data point produces a score and a stated reason

The score alone is not the answer; next to every line sits a sentence explaining why it scored that way. When you open the case in the panel, you see the sentence that made the decision.

Signals that raise the risk

  • Does the property name appear directly in the domain?
  • Was a credit card field or a bank account number detected?
  • Is the domain less than 30 days old? (+15 points up to 90 days)
  • Is the brand name present in the domain?
  • Is there a booking form, or is WhatsApp the only contact channel?
  • Does the name differ by only one or two letters?
  • Does it describe itself as the "official site"?
  • Is it running paid ads against the brand name?
  • Does it combine the brand name with suffixes such as "reservation", "official" or "booking"?
  • Are the address, trade name and tax details present on the site?
  • Is the owner hidden in the Whois record?
  • Is it on a cheap extension such as .xyz, .top or .online rather than .com?

So the same case is never discussed twice

Allowlist

Legitimate sales channels such as ETS, Jolly Tur, Tatil Sepeti, Booking, Expedia and TripAdvisor, along with business partners, news sites and social media, are kept out of scope. You can also add your own allowlist entries from your panel.

Memory and manual marking

The daily report only announces new cases. A site reported once is not reported again the next day; it stays in the panel. A second case is never opened for the same address — "did we already report this one" is answered in a single file. And when a case is marked "legitimate" in the panel, the domain moves to the allowlist and never becomes a candidate again.

Evidence pack

The evidence stays with you even after the site goes down

For every case above the threshold a dated, page-numbered PDF is produced. The reason is simple: even if the fraudster takes the site down, the screenshot and the records held in the panel remain — the domain, the imitated brand, the first and last detection times, and the source it was found through.

  • The risk score and every reason, line by line
  • Domain record: registrar, age, estimated registration date, privacy status, IP, name servers
  • Payment and contact channels, published WhatsApp numbers
  • A side-by-side comparison with your official site
  • A full-page capture of the site being reported
The score reasons for a case in the panel — the brand name is masked
The score reasons for one case. Real brand names and domains are masked.

Where complaints go

Each channel does a different job

No. Channel What it can do
1 Domain registrar Can suspend the domain
2 Hosting provider / ASN Can take the site down
3 USOM (Turkish national cyber incident response centre) Can block access from Türkiye
4 BTK / ihbarweb.org.tr Fastest route to an access block
5 Google Safe Browsing, Microsoft SmartScreen, Netcraft, APWG Triggers a browser warning
6 WhatsApp / Meta Shuts down the line and the fake account
6 Instagram, Facebook (Meta brand form) Takes down the impersonating account
6 Telegram (abuse@ and dmca@) Closes the channel; two separate desks
7 Ministry of Culture and Tourism, TÜRSAB, Ministry of Trade (CİMER) Administrative action
8 Public Prosecutor's Office Criminal proceedings

Complaint content is drafted automatically — in English for international bodies and in Turkish for Turkish authorities. The Turkish texts cite the relevant statutes (Law 5651, Law 1618). These are not form letters: each one is built around concrete harm, verifiable evidence and a single clear request.

The daily routine

How the automated flow runs

  1. 07.00

    The scan starts

    All discovery sources run in order; every new domain found is visited and scored. Similar social media accounts that are detected fall into a separate list and wait for review.

  2. 07.45

    The report goes out

    New cases only, each with its three heaviest reasons and, where present, the WhatsApp number.

  3. All day

    The panel

    Case lists, evidence, allowlist management and everything else are followed and acted on from the Serpify panel, around the clock.

Contact

Let us run a scan for your brand

Leave your hotel's name and your official domain; we will show you the result of the first scan and how the panel works. We reply within one business day.