Get the RTI Wiki appFree on iPhone and Android.
Differences
This shows you the differences between two versions of the page.
| — | how-to-verify-genuine-government-website-india [2026/09/03 03:30] (current) – created - external edit 127.0.0.1 | ||
|---|---|---|---|
| Line 1: | Line 1: | ||
| + | ====== How to Verify Genuine Government Website India (2026) ====== | ||
| + | |||
| + | |||
| + | |||
| + | |||
| + | {{page> | ||
| + | {{ : | ||
| + | |||
| + | //Last reviewed: 1 September 2026.// | ||
| + | |||
| + | <WRAP center round info 95%> | ||
| + | **Quick Reply:** Identify fake government sites: check .gov.in/ | ||
| + | </ | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | {{htmlmetatags> | ||
| + | |||
| + | An illustrative case (not a named person): a trader from Ludhiana lost money after entering PAN and bank details on **incomtax-efiling.org** — a clone site mimicking the genuine Income Tax portal. The fake site had stolen logos, working calculators, | ||
| + | |||
| + | > **Citizen Crisis Response Network** \\ | ||
| + | > Check domain suffix (only .gov.in/ | ||
| + | |||
| + | ===== Direct answer (featured snippet) ===== | ||
| + | |||
| + | To verify a genuine government website in India: 1. Confirm domain ends in **.gov.in** or **.nic.in** (never .org/.com). 2. Click the padlock icon; SSL certificate must be issued by **National Informatics Centre CA** or a government-approved authority. 3. Check for the **NIC seal** (S3WaaS logo) at footer. 4. Match the site against official directories at **india.gov.in** or **NIC' | ||
| + | |||
| + | ===== In this guide ===== | ||
| + | |||
| + | * [[#Why fake government websites proliferate in 2026]] | ||
| + | * [[#Anatomy of a phishing government portal]] | ||
| + | * [[#Five foolproof domain and SSL checks]] | ||
| + | * [[#NIC seal and S3WaaS certification explained]] | ||
| + | * [[# | ||
| + | * [[#What to do if you entered credentials on a fake site]] | ||
| + | * [[# | ||
| + | * [[#Case law and precedent: phishing prosecutions]] | ||
| + | * [[#How to report fake government websites to CERT-In]] | ||
| + | * [[#RTI application for official website confirmation]] | ||
| + | * [[#FAQ: Genuine government website verification]] | ||
| + | * [[#Myth vs reality table]] | ||
| + | |||
| + | ===== Why fake government websites proliferate in 2026 ===== | ||
| + | |||
| + | Phishing domains mimicking government portals remain a major cyber-fraud vector reported by the Indian Cyber Crime Coordination Centre (I4C). Attackers register lookalike domains (incomtax-efiling.org, | ||
| + | |||
| + | These sites exploit trust in government branding. Citizens searching " | ||
| + | |||
| + | Under **IT Act 2000 s.66D (punishment for cheating by personation using computer resource)** and the cheating provisions of the **Bharatiya Nyaya Sanhita 2023**, operating a fake government website attracts imprisonment up to three years and fines. Yet cross-border hosting, ephemeral domains, and cryptocurrency payment rails complicate enforcement. | ||
| + | |||
| + | > **Warning** — Google search results can display phishing ads above genuine links. Always type official URLs manually or bookmark verified sites. | ||
| + | |||
| + | ===== Anatomy of a phishing government portal ===== | ||
| + | |||
| + | A typical fake government website exhibits these features: | ||
| + | |||
| + | **1. Domain manipulation: | ||
| + | |||
| + | **2. SSL certificate theatre:** Fraudsters obtain free Let's Encrypt or commercial SSL certificates for fake domains. The green padlock appears, but the certificate is issued to the phishing domain—not the government body. Citizens see " | ||
| + | |||
| + | **3. Cloned design and working features:** Fake portals replicate HTML, CSS, JavaScript, captcha images, and even functional calculators from genuine sites. Login pages post credentials to attacker-controlled servers, then redirect victims to the real site with a " | ||
| + | |||
| + | **4. Pop-up OTP requests:** Genuine government sites never ask for OTP via pop-up, WhatsApp, or email. Phishing sites use fake " | ||
| + | |||
| + | **5. Absence of NIC seal and S3WaaS branding:** Legitimate central and many state government portals carry the **National Informatics Centre (NIC)** seal and S3WaaS (Secure, Scalable, and Sugamya Website as a Service) certification logo at the footer. Fake sites omit or crudely Photoshop these. | ||
| + | |||
| + | > **Most citizens miss this** — A padlock icon guarantees only that data is encrypted in transit, not that the recipient is a genuine government entity. Always verify the certificate issuer. | ||
| + | |||
| + | ===== Five foolproof domain and SSL checks ===== | ||
| + | |||
| + | **1. Domain suffix test:** All official central government portals use **.gov.in**. State portals may use state.gov.in (e.g., maharashtra.gov.in). National Informatics Centre sites use **.nic.in**. Departments under public sector undertakings may use .co.in or .org with official registration—cross-check against india.gov.in directory. **Never trust .com, .net, or .in domains** for sovereign functions. | ||
| + | |||
| + | **2. SSL certificate inspection (desktop): | ||
| + | * **Issued to:** Must match the exact domain (e.g., incometax.gov.in). | ||
| + | * **Issued by (CA):** Should be **NIC CA** or **Controller of Certifying Authorities (CCA) India** or another government-approved CA for DigiLocker/ | ||
| + | * **Validity period:** Government certificates are typically valid 1-2 years; phishing certs often have 90-day auto-renewal. | ||
| + | |||
| + | **3. SSL certificate inspection (mobile):** Tap the padlock or " | ||
| + | |||
| + | **4. WHOIS lookup:** Visit **https:// | ||
| + | |||
| + | **5. URL spelling and structure: | ||
| + | |||
| + | > **Do this immediately** — Bookmark verified government URLs after manual entry. Disable browser auto-complete for login pages to prevent credential leakage via saved form data. | ||
| + | |||
| + | ===== NIC seal and S3WaaS certification explained ===== | ||
| + | |||
| + | The **National Informatics Centre (NIC)**, under the Ministry of Electronics and Information Technology (MeitY), provides hosting, security, and digital identity infrastructure for government websites. Portals built and hosted on NIC infrastructure display: | ||
| + | |||
| + | * **NIC seal (logo):** Usually at footer, linking to **https:// | ||
| + | * **S3WaaS certification logo:** Indicates compliance with **Secure, Scalable, and Sugamya (accessible) Website as a Service** guidelines. S3WaaS sites undergo security audits, accessibility testing (GIGW compliance), | ||
| + | |||
| + | To verify the NIC seal: | ||
| + | |||
| + | 1. Right-click the seal image → "Open image in new tab." Genuine seals link to **nic.in** or are hosted on NIC infrastructure. | ||
| + | 2. Check the footer text for **" | ||
| + | 3. Cross-reference the site against the **NIC portal directory** at https:// | ||
| + | |||
| + | Absence of NIC branding does not automatically mean a site is fake—some statutory authorities (SEBI, RBI, IRDAI) use independent hosting—but for tax, passport, Aadhaar, and grievance portals, NIC involvement is the norm. | ||
| + | |||
| + | > **Trust signal** — Genuine government sites often include a "Web Information Manager" | ||
| + | |||
| + | ===== Government website directories and master lists ===== | ||
| + | |||
| + | **India.gov.in (National Portal of India):** The authoritative directory of all central and state government websites. Navigate to **https:// | ||
| + | |||
| + | **NIC state unit pages:** Each state NIC office maintains a list of official portals. Example: **https:// | ||
| + | |||
| + | **MeitY' | ||
| + | |||
| + | **Departmental " | ||
| + | * **Income Tax:** https:// | ||
| + | * **EPFO:** https:// | ||
| + | * **Passport Seva:** https:// | ||
| + | |||
| + | Cross-reference any site against these directories before entering credentials. | ||
| + | |||
| + | > **Citizen tip** — If a government service demands payment, verify the payment gateway bears the govt. e-marketplace (GeM) logo or recognised bank/ | ||
| + | |||
| + | ===== What to do if you entered credentials on a fake site ===== | ||
| + | |||
| + | **Immediate actions (within 1 hour):** | ||
| + | |||
| + | 1. **Change passwords: | ||
| + | 2. **Enable 2FA everywhere: | ||
| + | 3. **Freeze accounts (if banking details entered):** Call your bank helpline, request a temporary card/ | ||
| + | 4. **Check transaction history:** Log into genuine portals (net banking, Income Tax, EPFO) and review recent activity. Screenshot everything. | ||
| + | |||
| + | **Evidence preservation (within hours):** | ||
| + | |||
| + | 5. **Take full-page screenshots: | ||
| + | 6. **Save HTML source:** Right-click → "View Page Source" | ||
| + | 7. **Export browser history and cache:** Chrome: Settings → Privacy & Security → Clear browsing data → Download data first. | ||
| + | 8. **Note timestamps: | ||
| + | |||
| + | **Reporting (within 24 hours):** | ||
| + | |||
| + | 9. **File complaint on National Cyber Crime Reporting Portal:** Visit **https:// | ||
| + | 10. **Report to CERT-In:** Email **[email protected]** with subject " | ||
| + | 11. **Inform the genuine department: | ||
| + | |||
| + | > **Warning** — Cyber fraud response windows are measured in hours. Delayed reporting allows attackers to monetize stolen credentials via mule accounts and cryptocurrency mixers. | ||
| + | |||
| + | ===== Statutory framework: BNS 2023, IT Act 2000, and jurisdiction ===== | ||
| + | |||
| + | **IT Act 2000 s.66D (punishment for cheating by personation using computer resource): | ||
| + | |||
| + | **Bharatiya Nyaya Sanhita 2023 (cheating provisions): | ||
| + | |||
| + | **IT Act 2000 s.43 (penalty for damage to computer systems):** Unauthorized access, data theft, and introduction of malware attract compensation (adjudicated by the Adjudicating Officer under the IT Act). | ||
| + | |||
| + | **IT Act 2000 s.70B (Indian Computer Emergency Response Team):** CERT-In is the nodal agency for cybersecurity incident response. Under the IT (CERT-In and Manner of Performing Functions and Duties) Rules 2013, CERT-In can issue directions, coordinate with registrars on phishing domains, and share threat intelligence with law enforcement. | ||
| + | |||
| + | **Bharatiya Nagarik Suraksha Sanhita 2023 s.173 (information in cognizable cases / FIR):** Cyber fraud involving fake government websites is a cognizable offence. Under s.173(1), information may be given irrespective of the area where the offence is committed, so a victim may register a "zero FIR" at any police station or approach a Cyber Police Station. | ||
| + | |||
| + | **Jurisdiction: | ||
| + | |||
| + | > **Most citizens miss this** — Certain IT Act offences are compoundable under s.77A in defined circumstances, | ||
| + | |||
| + | ===== Case law and precedent: phishing prosecutions ===== | ||
| + | |||
| + | Indian courts have consistently treated online impersonation and phishing as serious offences under IT Act s.66D and the cheating provisions of the penal law. The settled position from reported phishing prosecutions is straightforward: | ||
| + | |||
| + | * The presence of an SSL certificate and a cloned design does not shield an operator from liability—if anything, a convincing clone shows premeditated intent to deceive. | ||
| + | * A victim' | ||
| + | * Intermediaries, | ||
| + | |||
| + | If you need authoritative citations for a specific FIR or prosecution, | ||
| + | |||
| + | > **Trust signal** — Courts recognize that citizens rely on visual cues (logos, padlocks). Operators of fake sites cannot plead "the victim should have been more careful." | ||
| + | |||
| + | ===== How to report fake government websites to CERT-In ===== | ||
| + | |||
| + | **CERT-In incident reporting: | ||
| + | |||
| + | 1. **Email:** [email protected] | ||
| + | 2. **Subject line:** " | ||
| + | 3. **Body (structured): | ||
| + | |||
| + | < | ||
| + | To: CERT-In Incident Response Team | ||
| + | Date: [dd-mm-yyyy] | ||
| + | Subject: Phishing Report – Fake Government Portal: incomtax-efiling.org | ||
| + | |||
| + | Incident Type: Phishing / Impersonation of Government Portal | ||
| + | Reported by: [Your Name], [City], [Mobile], [Email] | ||
| + | Incident Date & Time: [dd-mm-yyyy], | ||
| + | |||
| + | Fake Website Details: | ||
| + | - URL: https:// | ||
| + | - IP Address: [from your WHOIS / lookup] | ||
| + | - Registrar: [registrar name] | ||
| + | - SSL Certificate Issuer: [e.g., Let's Encrypt - not NIC CA] | ||
| + | - Cloned Portal: Income Tax Department e-filing (genuine: incometax.gov.in) | ||
| + | |||
| + | Evidence Attached: | ||
| + | 1. Full-page screenshot (filename: fake_site_screenshot.png) | ||
| + | 2. HTML source code (filename: fake_page_source.html) | ||
| + | 3. WHOIS lookup result (filename: whois_incomtax-efiling-org.pdf) | ||
| + | |||
| + | Action Requested: | ||
| + | - Coordinate domain takedown with the registrar. | ||
| + | - Add domain to CERT-In' | ||
| + | - Issue / support a public advisory via incometax.gov.in. | ||
| + | |||
| + | I have also filed a complaint on cybercrime.gov.in (Acknowledgment No. [your number]). | ||
| + | |||
| + | [Your Signature] | ||
| + | [Mobile] | ||
| + | [Email] | ||
| + | </ | ||
| + | |||
| + | **Follow-up: | ||
| + | |||
| + | **Domain takedown timeline:** Indian .in/.gov.in domains can usually be suspended quickly once a registrar acts. Foreign domains (.org, .com) hosted on international infrastructure can take longer, depending on registrar cooperation. | ||
| + | |||
| + | > **Do this immediately** — Simultaneously report to the impersonated department' | ||
| + | |||
| + | ===== RTI application for official website confirmation ===== | ||
| + | |||
| + | If you suspect a site is fake but lack technical certainty, file an RTI application under the **Right to Information Act 2005** to the concerned Ministry/ | ||
| + | |||
| + | < | ||
| + | To: Central Public Information Officer | ||
| + | Ministry of Finance, Department of Revenue | ||
| + | North Block, New Delhi – 110001 | ||
| + | |||
| + | Date: [dd-mm-yyyy] | ||
| + | Subject: RTI Application – Confirmation of Official Website Domain | ||
| + | |||
| + | Under Section 6(1) of the RTI Act 2005, I request the following information: | ||
| + | |||
| + | 1. List of all official website domains (URLs) operated, owned, or authorized by the Income Tax Department as of [current date]. | ||
| + | |||
| + | 2. Copy of any certificate or order authorizing the domain " | ||
| + | |||
| + | 3. Name and contact details of the Web Information Manager responsible for incometax.gov.in. | ||
| + | |||
| + | 4. Whether the Income Tax Department has filed any complaints with CERT-In or Cyber Police regarding fake domains impersonating the e-filing portal between January 2025 and March 2026. If yes, provide the list of fake domains reported. | ||
| + | |||
| + | 5. Copy of the latest public advisory issued by the Department warning citizens about phishing websites. | ||
| + | |||
| + | I am a citizen of India. | ||
| + | |||
| + | Please provide information within 30 days as mandated under Section 7(1). | ||
| + | |||
| + | [Your Name] | ||
| + | [Address] | ||
| + | [Mobile] | ||
| + | [Email] | ||
| + | </ | ||
| + | |||
| + | **Expected response time:** 30 days under RTI Act 2005 s.7(1). First Appeal lies to the designated First Appellate Authority of the Department if information is refused; a second appeal to the CIC thereafter. | ||
| + | |||
| + | **Use of RTI response:** Once you receive official confirmation of legitimate domains, share it with police (as evidence), attach it to your CERT-In complaint, and publish in citizen forums to warn others. | ||
| + | |||
| + | > **Citizen tip** — Public documents are admissible as evidence; under the Bharatiya Sakshya Adhiniyam 2023 (s.74, which replaced s.74 of the Indian Evidence Act 1872) records of public officers are treated as public documents. Photocopy and preserve any official reply for a cyber fraud FIR. | ||
| + | |||
| + | ===== FAQ: Genuine government website verification ===== | ||
| + | |||
| + | ==== Can a .org or .com domain ever be official government? ==== | ||
| + | |||
| + | Rarely. Some autonomous bodies and public sector undertakings (e.g., **csir.res.in**, | ||
| + | |||
| + | ==== Does HTTPS (green padlock) guarantee a site is genuine? ==== | ||
| + | |||
| + | No. HTTPS encrypts data but does not verify the site's identity beyond domain ownership. Phishing operators buy SSL certificates for fake domains. Always click the padlock and check **Issued to** (must match the exact domain) and **Issued by** (must be NIC CA or a government-approved CA). | ||
| + | |||
| + | ==== What if the fake site redirects to the genuine site after login? ==== | ||
| + | |||
| + | Classic phishing technique. Your credentials are captured in the first step, stored on attacker servers, then you're redirected to the real portal with a " | ||
| + | |||
| + | ==== How do I verify a government website on my mobile phone? ==== | ||
| + | |||
| + | Tap the padlock/ | ||
| + | |||
| + | ==== Can I trust a site if it appears in Google' | ||
| + | |||
| + | No. Phishing sites pay for Google Ads that appear above organic results, with an " | ||
| + | |||
| + | ==== What is the S3WaaS logo and why does it matter? ==== | ||
| + | |||
| + | S3WaaS (Secure, Scalable, and Sugamya Website as a Service) is NIC's framework for government portal development. Sites carrying the S3WaaS logo have passed security audits, accessibility (GIGW) compliance, and SSL hardening. While not foolproof, absence of this logo on a purported government site is a red flag. | ||
| + | |||
| + | ==== How long before police act on a cyber fraud complaint? ==== | ||
| + | |||
| + | Under **Bharatiya Nagarik Suraksha Sanhita 2023 s.173(1)**, police must register an FIR for a cognizable offence without delay. Cyber Police Stations are directed to act on I4C cases promptly. Investigation timelines vary (weeks for domestic cases; longer for transnational syndicates). You can seek progress updates as the investigation proceeds. | ||
| + | |||
| + | ==== Can I file an FIR in my city even if the fake website is hosted abroad? ==== | ||
| + | |||
| + | Yes. Under the zero-FIR provision in **BNSS 2023 s.173(1)**, information about a cognizable offence may be given irrespective of where the offence was committed, so you may file at any police station or approach a Cyber Police Station. For high-value cases, I4C and the CBI's cyber wing may have concurrent involvement. | ||
| + | |||
| + | ==== Who pays for losses if I lose money to a fake government site? ==== | ||
| + | |||
| + | There is no automatic reimbursement. You must file a cyber fraud FIR, seek an account freeze via police/ | ||
| + | |||
| + | ==== Should I report to CERT-In, cybercrime.gov.in, | ||
| + | |||
| + | Parallel reporting. **CERT-In** for technical takedown and domain blocking. **cybercrime.gov.in** for national database entry and I4C coordination. **Local Cyber Police** for FIR and investigation. All three channels serve different functions. Time-stamp each report. | ||
| + | |||
| + | ===== Internal links and resources ===== | ||
| + | |||
| + | * **RTI Assistant (drafter): | ||
| + | * **PIO Reply Checker:** https:// | ||
| + | * **Citizen Crisis Response Network:** https:// | ||
| + | * **RTI Act 2005 Complete Guide:** https:// | ||
| + | * [[https:// | ||
| + | |||
| + | ===== Myth vs reality table ===== | ||
| + | |||
| + | ^ Myth ^ Reality ^ | ||
| + | | A green padlock means the website is official government. | The padlock only certifies the connection is encrypted. Fake sites obtain SSL certificates for fraudulent domains. Always verify the certificate issuer is **NIC CA** or Controller of Certifying Authorities India. | | ||
| + | | Government websites can use .org or .com domains. | Legitimate central government portals exclusively use **.gov.in** or **.nic.in**. State portals use **[state].gov.in**. Any sovereign function on .org/ | ||
| + | | If a site appears in Google search results, it must be genuine. | Phishing sites pay for Google Ads (marked " | ||
| + | | I can ignore a suspicious site if I didn't enter any information. | Silence aids attackers. Report every fake government site to **CERT-In** and **cybercrime.gov.in**. Your report triggers takedown and protects thousands of potential victims. | | ||
| + | | Reporting to police is enough; no need to inform CERT-In separately. | Police handle investigation; | ||
| + | | I cannot verify websites on mobile; verification is desktop-only. | Mobile browsers display certificate details. Tap padlock/ | ||
| + | |||
| + | ===== Last word: trust but verify every government portal ===== | ||
| + | |||
| + | Fake government websites are the Trojan horses of 2026's digital India. Unlike street scams, they leverage institutional trust, visual perfection, and SSL theatre to harvest credentials at scale. The **Citizen Crisis Response Network** three-step verification protocol—domain suffix check (.gov.in/ | ||
| + | |||
| + | {{tag> | ||