Fake mirrors are one of the more effective scams running on the onion network. They don’t ask you to do anything unusual, which is exactly why they work. You click a link that looks like a page you’ve seen before, and everything about it feels familiar enough that your guard drops. A few concrete checks can catch most of these before you ever type anything into them.

None of the checks below require any special tools or technical skill. They’re closer to the same habits people already use to avoid phishing emails and fake online stores. Here, they just apply to a network where the usual visual cues don’t work the same way. A familiar domain name or a padlock icon in the address bar won’t help you.
Check Where the Link Actually Came From
Where you found a link matters as much as what the link itself looks like. An address pasted into a random Telegram channel, a Reddit comment from a brand-new account, or a pop-up ad carries none of the accountability that a link posted by an established community carries. That doesn’t make community-sourced links automatically safe. But a link with zero traceable history behind it deserves the most skepticism of all, regardless of how convincing the page itself looks once you’re on it.
Compare the Address Character by Character
Onion addresses are long strings of characters for a reason: they’re computationally difficult to fake exactly, but trivially easy to fake approximately. A scam mirror will often use an address that’s nearly identical to the real one. It might differ by only a character or two in a spot most people never bother checking. If you have a trusted copy of an address from a previous visit or a reliable source, compare the new one against it directly. Don’t just trust that it “looks about right.”
Watch for Anything Asking for Money Upfront
Legitimate directories and mirrors don’t typically charge an entry fee. Any page demanding payment before it shows you content that’s normally free is behaving like a business built around one-time visitors who won’t complain. This applies whether the page impersonates a well-known name or presents itself as something new. Free content that suddenly wants payment is one of the more reliable tells in this category.
Be Suspicious of Anything Too Polished
Paradoxically, a page that looks unusually professional can be a warning sign rather than a reassurance. Community-run directories tend to look exactly like what they are: plain, inconsistent, occasionally ugly. A landing page with slick branding, matching colors, and marketing copy is investing in something that plain link lists have no real reason to invest in. That mismatch between the presentation and the actual utility of the page is worth noticing.
Cross-Reference Before You Commit
The single most reliable check costs nothing but a few minutes. Look for the same address mentioned independently across multiple sources that don’t appear to be copying each other. A link that only exists on one page, with no independent confirmation anywhere else, hasn’t earned anyone’s vetting but the poster’s. A link that shows up consistently across several unrelated, established sources has at least survived some degree of collective scrutiny, even if that scrutiny is informal.
Trust Your Hesitation
People often notice something is off before they can articulate what it is. That instinct is worth listening to rather than talking yourself out of. If a page rushes you toward a decision, uses urgency language, or just feels subtly wrong in a way you can’t pin down, that hesitation is data. Scammers rely on you overriding your own discomfort because a page looks otherwise convincing. Giving yourself permission to simply close the tab and come back later costs nothing and has no downside.
If You Already Clicked Through
Clicking a link by itself usually isn’t the dangerous part, and panicking over having visited a page rarely helps. What matters more is what you did once you were there. Did you type in a password, enter any personal information, or download and open a file? Those are the actions worth addressing. Change any reused password immediately. Treat any downloaded file as something to delete rather than open if you haven’t already run it. Simply landing on a fake mirror and immediately backing out is a non-event that requires no cleanup at all.
None of these checks are foolproof on their own, and a determined scammer can satisfy any single one of them. What they can’t easily do is satisfy all of them at once. That’s exactly why running through more than one check matters more than finding the perfect single test. A few minutes of comparison before you commit to anything is a small price for avoiding the more common traps.