Safety checklist

Check the source before you trust the file

A polished page, familiar logo or top search position does not prove ownership. Verify the domain, file, permissions and support request separately.

Before opening a download link

  • Type or compare the full domain, including unexpected extra words or characters.
  • Confirm HTTPS is present, while remembering that encryption alone does not prove legitimacy.
  • Look for a consistent publisher identity and working policy pages.
  • Avoid links received from strangers, pop-ups or unsolicited private messages.

Before installing a file

CheckSafer signReason to stop
PublisherMatches an independently confirmed developerUnknown or inconsistent developer name
Protection scanNo warning from current device protectionInstruction to switch protection off
PermissionsLimited to features the app actually needsSMS, contacts, accessibility or device-admin access without a clear purpose
IntegrityPublished checksum matches the fileNo verifiable version or integrity information
Never share these with “support”:

Your password, one-time code, recovery phrase, full payment card details or remote-control access to the device.

If something already feels wrong

  1. Disconnect the suspicious app or page and do not send more information.
  2. Change the affected password from a clean device; do not reuse the new password elsewhere.
  3. Review recent transactions and contact the relevant bank or wallet provider through its official channel.
  4. Remove unfamiliar apps, profiles and device-administrator permissions.
  5. Run the built-in security scan and update the operating system.

Device-specific guidance

On Android, keep Google Play Protect enabled. On Apple devices, manually installed enterprise apps can require developer trust; confirm the developer before changing management settings. Android also publishes current information about developer verification for apps installed outside official stores.

Useful official sources

Last reviewed: 3 September 2026