Most insurance fraud advice begins after a payment has already left the account. The cheaper moment to intervene is the purchase flow itself: the landing page, the OTP, the UPI handle, the PDF that arrives by WhatsApp. This guide is a verification checklist for that moment, built from IRDAI's own warnings and the digital design rules regulators have started to enforce.

Method and data basis

Checklist items map to public IRDAI Be Alert! guidance on spurious calls and premium diversion, IRDAI warnings against impersonation sites such as policyholdergov.org and fake grievance portals, RBI and IRDAI positions on dark patterns (including bundled consent and price withheld until personal data is handed over), and BimaNiti coverage of digital arrest and refund-lure scams that start from a fake or spoofed insurance touchpoint. It is deliberately a pre-purchase list: post-loss recovery routes (insurer grievance officer, Bima Bharosa, 1930) are covered in the companion fraud guides and are not repeated as the primary defence here.

Before you enter anything: five checks

  • Domain: type or bookmark the insurer's known domain. Do not follow a search ad or message link into a lookalike URL that swaps a letter or adds a hyphen. Impersonation sites have used near-identical IRDAI and policyholder branding to harvest details and premium.
  • Registration: on aggregator or broker sites, confirm the entity is an IRDAI-registered intermediary or insurer, not a lead form that resells your number. The entity name on the payment page should match the entity name on the policy schedule.
  • Price before phone: if you cannot see premium and key benefits until you surrender a mobile number or email, treat that as a dark pattern, not a normal funnel. Regulators have explicitly targeted price-behind-login designs.
  • Contact path: the page should offer a verifiable insurer channel (official website, published phone, app). A WhatsApp-only close with a personal UPI ID is a stop signal.
  • Brochure versus wording: you must be able to open the policy wording or key features document before payment, not only after. Exclusions and waiting periods live there.

At payment: what legitimate flows look like

Pay only through the official gateway or the insurer's designated collection account. Never transfer premium to a personal UPI handle, a QR code sent in chat, or a bank account named after an individual agent. If someone claims your existing policy will lapse unless you pay 'them' immediately, hang up and call the insurer on the number on its official site. That is the classic premium-diversion pattern IRDAI's Be Alert! material is built around.

After payment, same day

  • Confirm the policy appears in the insurer's own app or portal, not only in the email attachment.
  • Check sum assured, tenure, premium, nominee and start date on the schedule against what you selected.
  • Save the proposal, payment receipt and signed wording. If the proposal asked health or income questions, keep the exact answers: non-disclosure disputes start there.
  • If the 'insurer' only exists as a chat thread and the policy never appears in any official portal, treat it as suspected fraud immediately and escalate through the insurer's published grievance channel and Bima Bharosa.

Dark patterns that are sales tactics, not always scams

Not every aggressive funnel is criminal. Pre-checked add-ons, countdown timers, default higher cover, and forced annual pay to unlock a 'discount' are manipulative design and may be restricted under newer directions, but the money still goes to a licensed insurer. The distinction matters: licensed-but-manipulative complaints go to the insurer and regulator; impersonation and fake-premium collection go to fraud channels. Both deserve action; they are not the same failure.

What not to do

Do not share OTP, KYC images or policy PDFs with anyone who cold-calls claiming to be IRDAI, a TPA, or 'policy verification'. Do not pay to 'activate' or 'unlock' a policy you believe you already bought. Do not skip the wording because the app summary looked clean.

Connect the cluster

For what to do after a fake call or diverted premium, read the spurious-calls and Bima Bharosa guides. For the regulatory backdrop on deceptive app design, see the dark-patterns explainer. For live warnings on impersonation portals, see our fake grievance portal and policyholder site coverage.