BETBDT নাম, logo বা page color দেখে কোনো domain-এর পরিচয় নিশ্চিত করবেন না। Address bar-এর hostname, redirect history, browser warning এবং credential behavior মিলিয়ে তারপর সিদ্ধান্ত নিন। HTTPS connection encrypt করতে পারে; এটি official identity প্রমাণ করে না।
দুই মিনিটের domain check
- Hostname পড়ুন: extra letter, missing letter, hyphen, subdomain এবং top-level domain লক্ষ্য করুন।
- Redirect দেখুন: link click-এর পরে final hostname বদলেছে কি না।
- Browser warning পড়ুন: certificate, dangerous download বা deceptive site warning bypass করবেন না।
- Password manager দেখুন: credential অন্য domain-এর জন্য হলে auto-fill বন্ধ করুন।
- Page request দেখুন: login-এর আগে payment, APK বা remote access চাইছে কি না।
HTTPS-এর সীমা
Lock icon browser ও server-এর encrypted connection বোঝায়। Fraudulent বা look-alike site-ও certificate পেতে পারে। তাই HTTPS-এর সঙ্গে exact domain spelling, page purpose এবং unexpected redirect দেখুন। Certificate warning ignore করে Password লিখবেন না।
Redirect chain-এ কী দেখবেন
| লক্ষণ | ঝুঁকি | সিদ্ধান্ত |
|---|---|---|
| একই domain-এর internal page | কম, তবু page purpose দেখুন | Address bar পড়ে এগোন |
| অন্য brand/domain | Identity mismatch | Credential দেবেন না |
| Multiple short links | Final destination লুকানো | Link বন্ধ করুন |
| Download সঙ্গে সঙ্গে শুরু | Unverified package | File open/install করবেন না |
OTP ও Password
OTP একটি one-time authorization code; support question-এর উত্তর নয়। Phone, chat, email বা screen share-এ OTP দেবেন না। Password reuse না করে password manager ব্যবহার করুন। Password manager domain mismatch দেখালে সেটি একটি useful warning—manual copy/paste করে bypass করবেন না।
APK source ও permission
Message, QR code, ad বা file-sharing link থেকে APK এলে source independently verify করুন। Package install-এর আগে requested permissions পড়ুন। SMS, accessibility, screen overlay, contacts, screen capture বা remote-control permission বিশেষ সতর্কতা দাবি করে। Verified publisher information না থাকলে install না করাই নিরাপদ সিদ্ধান্ত। App guide-এ mobile web alternative ও device checks আছে।
Payment recipient check
Recipient name/number account screen-এর written instruction-এর সঙ্গে মিলান। ব্যক্তিগত number-এ “temporary” payment, refund release বা account unlock-এর অনুরোধ সন্দেহজনক। OTP/PIN দিয়ে payment reverse করার কথা বিশ্বাস করবেন না। Transaction reference সংরক্ষণ করুন এবং duplicate payment বন্ধ রাখুন।
Fake support-এর সাধারণ সংকেত
তাড়াহুড়ো
“এখনই না করলে account বন্ধ” বলে দ্রুত সিদ্ধান্তে চাপ দেয়।
Secret চাওয়া
Password, OTP, PIN, recovery code বা full NID চায়।
Payment চাওয়া
Unlock fee, tax, verification fee বা refund fee personal Wallet-এ চায়।
Device control
Screen share, AnyDesk-ধরনের remote-control app বা accessibility permission চায়।
Screen sharing ও remote-control app
Screen share-এ OTP notification, Wallet balance, saved Password এবং document দেখা যেতে পারে। Remote-control app অন্য ব্যক্তিকে tap, type বা file access দিতে পারে। Sensitive session-এর আগে sharing বন্ধ করুন। ইতিমধ্যে access দিয়ে থাকলে network disconnect, app permission revoke, app remove, Password বদল এবং transaction history review করুন।
Browser warning দেখলে
- Warning bypass করবেন না এবং download continue করবেন না।
- Page URL ও warning text নোট করুন; screenshot-এ personal data রাখবেন না।
- Browser tab বন্ধ করে known-safe page থেকে নতুন করে শুরু করুন।
- Credential লিখে ফেললে correct domain থেকে Password বদলান এবং active session review করুন।
- Payment করে ফেললে reference সংরক্ষণ করে Bank/Wallet record পরীক্ষা করুন।
Incident note template
তারিখ ও সময়, suspicious URL, কী action হয়েছিল, কোন credential exposed হতে পারে এবং transaction reference—এই পাঁচটি তথ্য private note-এ লিখুন। Full Password, OTP, PIN বা card number note-এ রাখবেন না। betbdt.cyou operator support নয়; correction channel-এ personal incident data পাঠাবেন না।
Account access-এর জন্য Login guide, package checks-এর জন্য App guide এবং payment evidence-এর জন্য Payment guide ব্যবহার করুন।