39Design FAQ

How to spot fake orders and enquiries from your website.

A contact form or online order creates trust signals, but attackers can submit them too. Look for combinations of warning signs and verify unusual requests through independent channels.

Website securityUpdated August 2026
Frequently asked questions

Clear answers, without the jargon.

What are common signs of a fake website enquiry?

Watch for unusual urgency, vague requests that do not match your services, pressure to move to WhatsApp or another channel immediately, inconsistent names/domains, unexpected attachments, requests to click unfamiliar file-sharing links and payment proposals that make little commercial sense.

How can I safely check a suspicious enquiry?

Do not use links or phone numbers supplied in the suspicious message as your only verification route. Search for the organisation independently, check the sender domain, call a known published number and ask a colleague to review the request when money or sensitive information is involved.

What is an overpayment scam?

A fraudster may offer to pay more than required and ask you to forward part of the money to a third party, supplier or “designer”. Treat unusual payment-routing requests as high risk. Do not send money merely because a payment appears pending or a screenshot claims it has been made.

How do I spot a risky ecommerce order?

No single signal proves fraud. Review unusual order value, repeated payment attempts, mismatched customer information, high-risk delivery requests, expedited shipping pressure and warnings from the payment gateway. Use the gateway’s own fraud and authentication tools.

Can a contact-form attachment infect my computer?

Potentially. Treat unsolicited documents, archives and links cautiously. A form submission does not make an attachment safe. Where possible, restrict upload types, scan files and train staff not to enable macros or bypass security warnings.

Should I call every new website enquiry?

For high-value or unusual enquiries, a quick independent call can be an effective verification step. A dedicated business number or phone system also gives the sales team a consistent process for callbacks and logging. See our website phone-number guide.

How can I reduce automated contact-form spam?

Use layered controls such as server-side validation, rate limiting, honeypots, challenge systems where proportionate and a WAF/bot-management service for persistent abuse. Avoid relying only on a hidden field or client-side JavaScript.

What should staff do when they are unsure?

Stop the transaction or conversation long enough to verify it. It is better to delay a questionable order than to disclose credentials, open malware or send a fraudulent refund. Create a clear internal escalation route.

Specialist next steps

Useful services beyond the guide.

Keep exploring

Related website FAQs.

Need this applied to your own website?

© 2026 39 Design Ltd · Company 11113271 · MatthewSouthgate.co.uk · 39D.co.uk · Build 0.2.2