Check the URL bar
The URL bar should show iplfantasylive.com as the domain. Watch for look-alike domains: ipl-fantasy-live.com, iplfantasylive.net, etc.
Phishing and copycat sites are common in the fantasy sports industry. Here's how to verify you are on the real site.
Phishing and copycat sites are common in the fantasy sports industry. This page explains how to verify you are on the official IPL Fantasy Live site, and what to do if you land on a suspected copycat.
The URL bar should show iplfantasylive.com as the domain. Watch for look-alike domains: ipl-fantasy-live.com, iplfantasylive.net, etc.
The padlock icon in the URL bar confirms an SSL certificate is in place. Click the padlock to view the certificate issuer and the registered domain.
Once you have verified the URL, bookmark it in your browser. Use the bookmark for future visits - never follow a link in a promotional email or SMS without verifying.
For routine use, the mobile app is the most reliable way to access the platform. Download it from the official App Store or Google Play listing, not from a link in an email or SMS.
Copycat and phishing sites often mimic a real brand's look and feel, but use a slightly different domain. If you land on a site that looks like IPL Fantasy Live but the URL is not iplfantasylive.com, do not enter any personal information.
Report the suspected site to the CERT-In (Indian Computer Emergency Response Team) via the official phishing-reporting page. You can also report to Google Safe Browsing and Microsoft SmartScreen if the site is impersonating our brand.
If you send us the suspected URL via our contact page, we will review it within 48 hours and, where appropriate, request takedown action through CERT-In and the hosting provider.

Phishing sites evolve quickly, but the underlying tactics stay the same. Here are the three most common patterns.
An email that looks like it is from a legitimate brand, with a link to a copycat site. The email may claim your account is locked, your KYC needs updating, or you have won a prize.
An SMS claiming to be from a legitimate brand, with a short link. SMS is a particularly common phishing vector in India because most users trust SMS more than email.
Copycat sites that buy Google Ads targeting the legitimate brand's name. The ad looks like the real site, but the URL is different. Always check the URL bar, not just the ad copy.
If you have already clicked a phishing link and entered personal information, work through these steps in order.
If you entered KYC details, disconnect from the network immediately. The phishing site may be exfiltrating data in real time.
Take a screenshot of the URL bar and the page you landed on. This evidence is useful for reporting.
If you used the same password on any other account, change those passwords immediately. Use unique passwords going forward.
If you entered bank account details, monitor your statements for unauthorised transactions. Contact your bank immediately if you see any.
Report the URL to the legitimate brand (us, in this case), to CERT-In via the official portal, and to Google Safe Browsing if the URL appears in search results.
The single most effective defence against phishing is a browser bookmark to the legitimate site. Once you have bookmarked iplfantasylive.com, use the bookmark - never a search engine link or an email link.
Open the site, click the star icon in the URL bar, save the bookmark to your bookmarks bar. Pin it for one-click access.
On iOS Safari, tap the share button and choose "Add to Home Screen". On Android Chrome, tap the menu and choose "Add to Home Screen". This creates a one-tap icon on your phone's home screen.
Every legitimate website has an SSL certificate issued by a trusted certificate authority. Here is how to verify it.
The padlock icon in the URL bar confirms an SSL certificate is in place. Most browsers also show "Connection is secure" when you click the padlock.
Click the padlock to view the certificate issuer, the issuing certificate authority, and the registered domain. The issuer should be a recognised certificate authority like Let's Encrypt, DigiCert, or Comodo.
The certificate should be issued for the exact domain you are visiting. A certificate for a different domain is a strong red flag.
SSL certificates have a validity period - typically 90 days for Let's Encrypt or 1 year for paid certificates. An expired certificate is a red flag.
Once you have verified the official domain and SSL certificate, bookmark it in your browser. Use the bookmark for future visits - never a search engine link or an email link.
Open the site, click the star icon in the URL bar, save the bookmark to your bookmarks bar. Pin it for one-click access.
On iOS Safari, tap the share button and choose "Add to Home Screen". On Android Chrome, tap the menu and choose "Add to Home Screen". This creates a one-tap icon on your phone's home screen.
Every legitimate website has an SSL certificate issued by a trusted certificate authority. Here is how to verify it.
The padlock icon in the URL bar confirms an SSL certificate is in place. Most browsers also show "Connection is secure" when you click the padlock.
Click the padlock to view the certificate issuer, the issuing certificate authority, and the registered domain. The issuer should be a recognised certificate authority like Let's Encrypt, DigiCert, or Comodo.
The certificate should be issued for the exact domain you are visiting. A certificate for a different domain is a strong red flag.
SSL certificates have a validity period - typically 90 days for Let's Encrypt or 1 year for paid certificates. An expired certificate is a red flag.
Once you have verified the official domain and SSL certificate, bookmark it in your browser. Use the bookmark for future visits - never a search engine link or an email link.
Open the site, click the star icon in the URL bar, save the bookmark to your bookmarks bar. Pin it for one-click access.
On iOS Safari, tap the share button and choose "Add to Home Screen". On Android Chrome, tap the menu and choose "Add to Home Screen". This creates a one-tap icon on your phone's home screen.
For mobile users, the simplest way to access the official site is to add it to your phone's home screen as a PWA (Progressive Web App). One tap, no browser UI.
Open the site in Safari, tap the share button (square with an arrow), scroll down and tap "Add to Home Screen". The site appears as an icon on your home screen.
Open the site in Chrome, tap the three-dot menu, tap "Add to Home Screen" or "Install App". The site appears as an icon on your home screen.
Three reporting channels for suspected phishing sites that impersonate IPL Fantasy Live or related brands.
The Indian Computer Emergency Response Team accepts phishing reports via the official portal. Reports are reviewed within 48 hours and, where appropriate, takedown action is requested.
Google's Safe Browsing programme accepts phishing reports via the official report form. Reported sites are flagged in Chrome and other Google services.
Microsoft's SmartScreen filter accepts phishing reports for sites that target Microsoft Edge users. Reports are reviewed within 24 hours.