Aller au contenu
snorklee
Trafic IA Analytics Vigie Tarifs Manifeste Documentation Contact Connexion Essai gratuit 14 jours

The Clone watch: what if someone copied your site?

Scammers copy legitimate sites to trap their visitors — fake login forms, fake payment pages. The Clone watch warns you when a copy of your site is serving somewhere, and puts the proof in your hands.

Nothing to install: the watch relies on the Snorklee code already on your pages. When someone copies your site, that little witness usually travels with the copy. As soon as a visitor opens the copy, their browser tells us, by itself, the real address where the page runs. If it isn't yours, the watch sees it — and our servers then check the page themselves before alerting you.

Everything lives in the Clone watch tab of your dashboard; alerts that need a decision arrive in Actions.

The cases you may run into, one by one

"Confirmed copy" — the serious alert

Our servers went to the suspect page and found the Snorklee code on it: that domain really serves a copy of your site without belonging to you. You get one email (once per domain), and a card appears in Actions. What to do, in order:

  1. Download the page copy: the exact page served by the domain, kept with its date and a SHA-256 fingerprint — your exhibit, even if the copy later disappears.
  2. Copy the evidence file and use the links provided: see who registered this domain (ICANN), report to Google Safe Browsing, report to Phishing Initiative.
  3. Click "I've done it": the watch then watches the copy fade out — if the signals stop, you'll see it, numbers included.

"Not confirmed" — but not cleared either

Signals arrived, but during our check the page was not serving your site. Careful: this does not prove everything is fine — phishing kits know how to show a blank page to checkers and the real copy to victims. As long as the domain keeps sending signals, we re-check every 24 hours.

"Free hosting" — it might be you

Your page is running on a free subdomain (vercel.app, netlify.app…). Two possibilities: it's your own preview — click "This is my domain" and the alert disappears for good — or it's a free copy set up by an attacker: treat it as a report.

"Known service" and "dev or test" — never an alert

Google's cache, a translated page, a web archive, or your localhost: the watch recognises them and files them in the list without ever bothering you.

Your other domains — recognised as yours

You can mark a domain as yours (preview, a copy you manage, another domain you own): it never alerts again. You can do it ahead of time in the Clone watch tab, or with one click from an alert card. Good to know: a recognised domain also covers all of its subdomains, and subdomains of your own domain are already recognised — nothing to do for them. You can remove it at any time: the domain is then reclassified and re-checked.

What the watch cannot see — said plainly

  • A copy with the Snorklee code removed sends nothing: it stays invisible to the watch.
  • A copy that nobody has opened yet has not given itself away yet.
  • So no alert is never a guarantee that no copy exists — beware of anyone who promises otherwise.

Your visitors are not involved

The watch keeps the foreign domain name, a daily count and one sample page — that's all. No IP address, no identifier, no location. Visitors who decline measurement feed nothing.

What it costs

Nothing extra: the Clone watch is included in Snorklee, on every tier.