Source check
Confirm the download URL is the official domain.
The four desk passes in this desk read are sequential. Complete the first three before opening the file; the fourth is the post-install sanity check.
Confirm the download URL is the official domain.
Confirm the version number and file size.
Prepare the device before installing.
Identify unsafe installers before they cause harm.
If the platform offers a direct download outside the major app stores, the file will live on a URL on the official domain. Anything else — a third-party APK mirror, a Telegram post, a forwarded link — is a red flag.
Cross-check the URL across at least two of the platform's own channels: the official website, the platform's verified social accounts, and the official customer-care channel. Mismatches are a hard stop.
The platform's verified domain is the one published on the official website, in the app-store listing, and on verified social channels. Treat every other domain — even visually similar ones — as suspect.


Five small preparation steps before install reduce the surface area for trouble. None of them require technical skill.
Six warning signs mean a download is unsafe. If any appear, delete the file and re-verify through an official channel.

Two checks take less than a minute and they catch most unsafe installers. Both are required reading before any install.
Compare the downloaded file size against the size published on the official latest-version note.
The version in the installer header should match the platform's latest-version note. Older versions can hide known vulnerabilities.
Where the platform publishes a signing certificate, verify the installer against the published certificate.
Compare the build date inside the installer metadata against the latest-version note. Stale builds warrant a fresh download.
The URL is one character off from the official domain. Common substitutes include zero for O, hyphen for underscore, and added prefixes.
The file is hosted on a third-party APK mirror that is not linked from the official website.
The downloaded file size differs significantly from the published latest-version size.
The link came through a forwarded message, a Telegram post, or a social-media DM rather than the official channel.
The installer is unsigned or signed by a different developer than the one published on the platform.
The installer arrives with extra APKs, advertisement SDKs, or modified resources not listed in the official build notes.
If you have the file already, the verification guide walks through what to check before you install it.