---
title: "Scam & Fraud Glossary | LEGITTAP"
description: "Plain-language definitions for phishing, smishing, vishing, spoofing, social engineering, reshipping scams, fake checks, look-alike domains, and fraud terms."
canonical: "https://legittap.com/glossary/"
dateModified: "2026-09-22"
last_updated: "2026-09-22"
---

# LEGITTAP Scam and Fraud Glossary

> Plain-language definitions for phishing, smishing, vishing, spoofing, social engineering, reshipping scams, fake checks, look-alike domains, and fraud terms.

## How to use this glossary

Scam vocabulary is useful because it gives names to patterns that otherwise feel vague. Use these definitions to understand what a scan is describing, then look at the full context rather than treating one label as proof. For example, a new domain can be a risk clue without being malicious, a spoofed caller ID can imitate a legitimate organization, and a message can use social-engineering pressure without matching every feature of a known scam. Strong decisions come from combining multiple independent signals.

## Fraud signals are strongest in combinations

One unusual detail may have an innocent explanation. Several aligned details deserve more caution. A rushed payment request sent from a look-alike domain, a recruiter asking you to forward packages, or a caller requesting a one-time security code creates a stronger pattern than any one clue alone. LEGITTAP uses this same principle when it weighs evidence: deterministic rules, threat intelligence, domain or phone metadata, and AI analysis can contribute different pieces of the picture while uncertainty remains visible.

## Why precise terms help when you report a scam

Clear terminology also makes reports more useful. Saying that a message involved phishing, a spoofed caller ID, a fake-check request, or a reshipping job gives a bank, employer, platform, support team, or investigator a faster starting point than a vague description of “something suspicious.” Keep the original evidence when it is safe to do so, note dates and contact details, and separate what you directly observed from what you suspect. Precise language does not make the conclusion certain, but it helps other people compare the incident with known fraud patterns and decide what records or actions matter next.

## Phishing

Fraudulent messages or sites designed to trick someone into revealing credentials, payment information, or other sensitive data.

## Smishing

Phishing delivered by SMS or other text-message channels.

## Vishing

Voice phishing that uses phone calls, voicemail, or voice systems to impersonate a trusted organization or person.

## Spoofing

Manipulating identifying information, such as caller ID, sender details, or web addresses, to make a communication appear to come from somewhere else.

## Social engineering

Manipulating a person into taking an action, revealing information, sending money, or bypassing normal security procedures.

## Impersonation scam

A fraud attempt in which the scammer pretends to be a company, government agency, employer, relative, executive, or other trusted party.

## Reshipping scam

A fake job or work arrangement that asks someone to receive, relabel, or forward packages, often connected to stolen payment methods or identity fraud.

## Fake check scam

A scheme involving a fraudulent check or payment that appears available before the bank later determines it is invalid, often after the victim has already sent money elsewhere.

## Credential theft

Attempts to obtain usernames, passwords, one-time codes, recovery codes, or other authentication secrets.

## Look-alike domain

A domain name designed to resemble a legitimate brand or site by using misspellings, extra words, misleading subdomains, or visually similar characters.

## Domain age

How long a domain has existed. A very new domain can be a risk clue in context, but age by itself does not prove legitimacy or fraud.

## Threat intelligence

External data about known malicious URLs, domains, infrastructure, or other indicators. A no-match result does not prove an item is safe.

## Risk score

A summary score derived from the evidence available to a LEGITTAP scan. It is decision support, not a legal or identity-verification conclusion.

## Unable to verify

A result used when available evidence is insufficient to responsibly assign a stronger risk conclusion.

[Check something with LEGITTAP](https://legittap.com/#web-check)

## Sitemap

See the full [LEGITTAP sitemap](https://legittap.com/sitemap.md) for all public pages.
