The only official AllSwap entry point for consumers is `https://allswap.io`. The AllSwap Terms of Service confirm that the service is provided through this domain and its subdomains. However, consumers should type and bookmark the main website themselves rather than treating a search ad, shortened URL, QR code or “alternative website” sent in a private message as official. A padlock icon alone does not prove that a website is safe. If either the domain or the page behaves unexpectedly, stop immediately: do not connect a wallet, sign an authorization or send funds.
How do I check the AllSwap domain character by character?
Do not rely on the logo, page colors or title shown in search results. Click the browser's address bar, reveal the complete URL and read it carefully. DNS hostnames are case-insensitive and browsers commonly normalize them to lowercase. What matters is that the ASCII sequence a-l-l-s-w-a-p, the .io top-level domain and every dot boundary are exactly correct.
If a feature is hosted on a subdomain, its complete hostname must end in `.allswap.io`, with a dot immediately before that suffix. Technical, API and back-office subdomains are not consumer swap entry points. Do not proactively visit one or pay through one because a stranger told you to do so.
None of the following examples is the official domain:
- A spelling with added, missing or rearranged characters, such as
all-swap.ioorallswapio.com; - A different top-level domain, such as
.com,.netor another suffix; - The brand placed in front of someone else's domain, such as
allswap.io.example.com, whose actual registered domain isexample.com; - A URL that uses
@to mislead the eye, such ashttps://[email protected], where the actual hostname is stillexample.com; - A name containing Unicode lookalike characters. They may resemble the Latin letters
a,lorowhile actually belonging to another alphabet. Browsers may display such internationalized names as Punycode beginning withxn--. The AllSwap main domain does not require accented or internationalized characters.
A URL may contain a long path after /, but that path does not change who controls the domain. To verify ownership, first identify the hostname between https:// and the next /; merely finding the word “allswap” somewhere in the entire URL is not enough.
What does an HTTPS certificate actually prove?
HTTPS, established through a TLS certificate, primarily shows that the browser is communicating with the domain currently covered by that certificate and reduces the chance that traffic will be read or altered in transit. It does not review a page for phishing and does not guarantee a swap outcome. A fake domain can obtain a valid certificate too.
You therefore need both conditions: the domain must be correct character for character, and the browser must show no certificate warning. Clicking through a certificate warning removes an important layer of protection.
Even if the address bar appears correct, DNS hijacking, a malicious browser extension, an untrusted root certificate installed on the device or a compromised front-end dependency could still alter page behavior. If the website unexpectedly asks you to connect a wallet, sign an unfamiliar message, install an extension, or pay a “verification deposit” or “unfreezing fee” outside the order flow, do not continue merely because the domain looks right. Close the page and recheck it from an updated device without suspicious extensions and over a trusted network. Never ignore a certificate error.
How should I handle search results, short links and social messages?
A high search ranking or “Sponsored” label shows placement or advertising, not verification by AllSwap. Shortened links, QR codes and buttons conceal their final destination. Social profiles can copy a display name, avatar or verification-style badge, and a genuine account can also be compromised.
For routine access, type https://allswap.io manually the first time, verify every character, then create your own bookmark and use it thereafter. Do not open a payment page directly from a private message, group chat, email or advertisement.
AllSwap's currently published consumer flow does not require you to connect a wallet, sign a token approval, or reveal a recovery phrase, private key, wallet password or verification code. Treat any request for screen sharing or remote control as a serious warning. The same applies to demands for an extra “tax,” “security deposit,” “verification payment” or “unlocking fee” outside the normal order. The AllSwap security guidance also states that users should never share private keys or wallet access.
What should I do if I find a suspicious AllSwap link?
- Stop interacting immediately. Do not connect a wallet, sign anything, enter credentials, pay the address shown by the page or make another transfer at the request of “support.”
- Preserve non-sensitive evidence. Record the full URL, sender address, complete social username, date and time, and screenshots. Never include a recovery phrase, private key or verification code in a screenshot.
- Find support again from the verified main website. Manually enter the main domain, open the AllSwap Help Center, and confirm the email address and social username currently listed there before contacting anyone. Do not reply to the original private message or use the support button on the suspicious page.
- If you already paid, preserve the on-chain evidence. Keep the order ID, if available, as well as the network, asset, payment address, transaction hash, and wallet or exchange withdrawal record. Give those details to official support. Blockchain transfers are generally irreversible; contacting support is not a promise that misdirected assets can be recovered.
- If wallet credentials were exposed, treat the wallet as compromised. On a clean device without suspected malware, create a new wallet, move any remaining assets promptly, and inspect and revoke suspicious token approvals. Do not disclose the new address, new recovery phrase or revocation process to the original “support” contact.
If the suspicious behavior appears to involve the certificate, DNS or front-end security of the real AllSwap website, report it through the channel described in the AllSwap vulnerability disclosure policy. Do not publish exploitable details in a public group.

