The official domain is the only safe entry point

The official Andar Bahar domain is the only safe entry point. Bookmarks should be set after one verification. this guide documents the URL bar check, the TLS certificate check and the lookalike-reporting route.
How to check the URL bar
Open the URL bar in the browser. Read the domain exactly. The official domain is andarbaharin.com. A lookalike domain (for example, andarbaharin.app, andarbaharin.in, andarbaharin-login.com) is a phishing signal.
How to verify the TLS certificate
Click the padlock in the URL bar. Read the certificate issuer. The certificate issuer should be a recognised certificate authority. A self-signed certificate is a phishing signal.
What to do if a redirect appears
If the URL bar changes after the page loads, treat that as a redirect and close the tab. The editorial recommendation is to navigate to the official domain manually rather than clicking through from a search result or an email.
How to report a lookalike domain
Report lookalike domains to the operator through the verified customer-care channel. The verified channel is in-app chat first, then email. The customer-care route documents the verified channels.
The bookmark angle
Set the bookmark after one verification. The bookmark should point to the official domain, not to a lookalike. The editorial recommendation is to check the bookmark once a month.
The email link angle
Do not click through from an email to the official domain. The editorial recommendation is to navigate manually. A phishing email will use a lookalike domain in the link; the URL bar will reveal it.
The search result angle
Search results can include lookalike domains. The editorial recommendation is to read the URL bar before clicking through. A lookalike domain in a search result is a phishing signal.
The social channel angle
Social channels can include lookalike accounts. The verified app exposes the official social handles inside the wallet screen; a lookalike account is a phishing signal.
What to do if you clicked a lookalike
If you clicked a lookalike, do not enter any credentials. Close the tab, clear the browser cache and navigate to the official domain manually. The editorial recommendation is to change the password on the verified app if credentials were entered.
The TLS certificate angle for the verified app
The verified app uses TLS for the in-app connection. The TLS certificate is managed by the operator; the editorial recommendation is to verify the certificate inside the wallet screen.
The phishing report angle
Report phishing to the operator, to the platform that hosted the phishing content, and to the Indian Computer Emergency Response Team (CERT-In). The CERT-In website is the editorial reference; cross-check the URL before reporting.
What to do on a new device
On a new device, navigate to the official domain manually. Do not import bookmarks from a previous device without verifying them. The editorial recommendation is to check the bookmarks one by one.
Where to go next
Open the customer-care page to read the verified channels, or the app page to read the publisher and version check.
The bookmark angle
Set the bookmark after one verification. The bookmark should point to the official domain, not to a lookalike. The editorial recommendation is to check the bookmark once a month.
The email link angle
Do not click through from an email to the official domain. The editorial recommendation is to navigate manually. A phishing email will use a lookalike domain in the link; the URL bar will reveal it.
The search result angle
Search results can include lookalike domains. The editorial recommendation is to read the URL bar before clicking through.
The social channel angle
Social channels can include lookalike accounts. The verified app exposes the official social handles inside the wallet screen; a lookalike account is a phishing signal.
Where to go next
Open the customer-care page to read the verified channels, or the app page to read the publisher and version check.
What to do on a future domain change
Domain changes are rare but possible. The editorial recommendation is to verify the URL bar after any operator communication.
Where to go next
Open the customer-care page to read the verified channels, or the app page to read the publisher and version check.
The URL bar check is the first step in any visit
The URL bar check is the first step in any visit. Open the URL bar in the browser; read the domain exactly. The official domain is andarbaharin.com. A lookalike domain (for example, andarbaharin.app, andarbaharin.in, andarbaharin-login.com) is a phishing signal and the editorial recommendation is to close the tab.
The TLS certificate check is the second step
The TLS certificate check is the second step. Click the padlock in the URL bar; read the certificate issuer. The issuer should be a recognised certificate authority. A self-signed certificate is a phishing signal; the editorial recommendation is to close the tab.
The redirect check is the third step
The redirect check is the third step. If the URL bar changes after the page loads, treat that as a redirect and close the tab. A redirect to a lookalike domain is a phishing signal; the editorial recommendation is to navigate to the official domain manually rather than clicking through.
The bookmark check is the fourth step
The bookmark check is the fourth step. Set the bookmark after one verification; the bookmark should point to the official domain, not to a lookalike. The editorial recommendation is to check the bookmark once a month; a stale bookmark may point to a domain that has been sold.
The email link check is the fifth step
The email link check is the fifth step. Do not click through from an email to the official domain; navigate manually. A phishing email will use a lookalike domain in the link; the URL bar will reveal it. The editorial recommendation is to forward the phishing email to the operator's customer-care channel.
The search result check is the sixth step
The search result check is the sixth step. Search results can include lookalike domains; the editorial recommendation is to read the URL bar before clicking through. A lookalike domain in a search result is a phishing signal; the editorial recommendation is to navigate to the official domain manually.
The social channel check is the seventh step
The social channel check is the seventh step. Social channels can include lookalike accounts; the verified app exposes the official social handles inside the wallet screen. A lookalike account is a phishing signal; the editorial recommendation is to report the lookalike account to the platform.
The CERT-In reporting route is the eighth step
The CERT-In reporting route is the eighth step. Report phishing to the operator, to the platform that hosted the phishing content, and to the Indian Computer Emergency Response Team (CERT-In). The CERT-In website is the editorial reference; cross-check the URL before reporting.
The URL bar check above is editorial
The URL bar check above is editorial. The check is the first step in any visit; the editorial recommendation is to read the domain exactly. A lookalike domain is a phishing signal; the editorial recommendation is to close the tab.
The TLS certificate check above is editorial
The TLS certificate check above is editorial. The check is the second step; the editorial recommendation is to read the certificate issuer. A self-signed certificate is a phishing signal; the editorial recommendation is to close the tab.
The redirect check above is editorial
The redirect check above is editorial. The check is the third step; the editorial recommendation is to close the tab if the URL bar changes after the page loads. A redirect to a lookalike domain is a phishing signal.
The bookmark check above is editorial
The bookmark check above is editorial. The check is the fourth step; the editorial recommendation is to set the bookmark after one verification and to check it once a month. A stale bookmark may point to a domain that has been sold.
The CERT-In reporting route above is editorial
The CERT-In reporting route above is editorial. The reporting route is the eighth step; the editorial recommendation is to report phishing to the operator, to the platform that hosted the phishing content, and to CERT-In. The CERT-In website is the editorial reference.