The official-website guide below is a short hygiene reference, not a directory. The operator's current primary domain is the canonical reference; we do not republish it because it can change, and a republished URL on a third-party page ages badly. Instead, we describe how to verify the URL you intend to visit, so you can spot the phishing sites that impersonate the brand.
The single most important rule
Type the URL yourself in the address bar of your browser. Never click a link in an SMS, email, or social-media DM to reach any login or KYC page. This one rule prevents the vast majority of phishing attempts.
What a legitimate address looks like
- HTTPS (padlock in the address bar)
- The primary domain matches the operator's corporate name exactly — no typos, no hyphenated prefixes, no look-alike subdomains
- The certificate is issued by a trusted certificate authority (click the padlock for details)
What a phishing address looks like
- Look-alike domain ("dream1l.com", "dream11-help.com", "dream11-login.net")
- HTTP (no padlock) or self-signed certificate warning
- Excessive subdomains before the real domain ("dream11.account-update.suspicious.com")
- URL shorteners hiding the real destination
- Pages that ask for your password, OTP or PAN outside the standard login or KYC flow
If a "Dream11" link arrives in your inbox
- Do not click it
- Open a new browser window and type the operator's primary domain yourself
- Navigate to the relevant section (login, KYC, customer support) from the official site's menu
- Report the suspicious link to the operator's security team via the in-app flow



