Wecap official website — safe access, no fake mirrors
The official Wecap domain is wecapin.com. The safe paths and three checks before signing in are documented below.
The official domain
Wecap operates from a single primary domain. Always verify before you sign in.
| Field | Value |
|---|---|
| Primary domain | wecapin.com |
| Subdomains in use | www.wecapin.com · Login.wecapin.com · static.wecapin.com |
| Wildcard redirects | All other subdomains redirect to the primary domain |
| TLS | TLS 1.3 with HSTS preload; certificate chain verifiable from any modern browser |
| Mirror domains | None published. Any "wecap" mirror on a different TLD is unofficial. |
Three things to check before you sign in
The fastest way to spot a fake mirror is to check three things.
- 1Check the URL bar
The URL must read wecapin.com. Anything else — including wecap-in.com, wecapin.co, wecap.in — is unofficial.
- 2Check the certificate
Tap the padlock icon. The certificate must be issued to wecapin.com, with a verifiable chain to a public CA.
- 3Check the app publisher
If you installed Wecap from outside the App Store, open the APK info screen and confirm the publisher name matches the official Wecap publisher.
Report a fake mirror
If you find a mirror that pretends to be Wecap, report it to the desk. Reports are reviewed within 24 hours.
Reported fake mirrors
The desk publishes a running list of fake mirrors reported by readers. The list is updated as reports come in; past mirrors are listed below for reference.
| Reported URL | Status | Action |
|---|---|---|
wecap-in.com | Reported May 2026 | Hosting provider notified; site taken down |
wecapin.co | Reported April 2026 | Registrar escalation; domain suspended |
wecap-app.in | Reported March 2026 | Mirror identified; report to CERT-In |
If you find a mirror not listed above, send the URL to /customer-care/ and the desk will escalate within 24 hours.
How Wecap protects the domain
Wecap registers defensive domain variants and runs continuous monitoring for typosquatting. The hygiene routine is documented below.
What we register
Wecap registers common typosquats and TLD variants: wecapin.com is the primary domain; wecapin.net and wecapin.in redirect to the primary. Other variants are blocked at the registrar level.
Continuous monitoring
The desk runs continuous monitoring for new registrations of "wecap" on common TLDs. Reported mirrors are escalated within 24 hours to the hosting provider and the relevant registry.
CT log monitoring
Wecap monitors the public certificate transparency logs for any certificate issued to a "wecap" domain on a non-primary TLD. Reported certificates trigger an immediate investigation.
Reader questions about the Wecap official site
Reader questions sent to the desk in the last quarter, answered in editorial voice. Send yours via /contact/.
Why does Wecap use wecapin.com rather than wecap.com?
Wecap uses wecapin.com as its primary domain for clarity: the "in" suffix signals the India-focused product line and avoids ambiguity with the brand's international trademark portfolio. The primary domain is the only one that should appear in your URL bar.
Can I use Wecap from a public Wi-Fi network?
Yes. Wecap enforces TLS 1.3 with HSTS preload, which means the browser refuses to connect over insecure HTTP, regardless of the network. Two-factor OTP adds a second layer that public networks cannot bypass.
Does the official site work in incognito mode?
Yes. Wecap does not use cookies for marketing or cross-site tracking. The session cookie is functional only and clears when you close the incognito window.
What is the difference between wecapin.com and Login.wecapin.com?
wecapin.com is the public-facing surface — the editorial desk, the captain pick rationale, the points matrix. Login.wecapin.com is the login subdomain that handles sign-in and the play desk session. Both are official Wecap domains.
Can I share a screenshot of the official site on social channels?
Yes. Wecap screenshots for editorial review are encouraged. The captain pick desk, salary cap playbook and points matrix are designed to be screenshotted and shared. Please do not crop out the verification stamp on the methodology colophon or the Wecap brand mark on the homepage.
Why the official site looks like a working desk
The Wecap official site is built around the visual structure contract documented at .control-room/homepage-structure-contract.json. The contract keeps the site deliberately unlike a marketing brochure.
Light palette, dark ink
The site uses a light slate utility palette with a single restrained violet accent. The choice reflects the editorial voice: a working field manual, not a marketing brochure. White surfaces, restrained typography, dense data.
Format tracks running parallel
The homepage carries a split-axis timeline — four format tracks (T20/ODI/Test/T10) running vertically through the page. The signature device is rare in fantasy cricket editorial and shows up only on pages that genuinely benefit from cross-format comparison.
What the official site needs from your browser
The Wecap official site runs in any modern browser. The minimum versions are documented below.
| Browser | Minimum version | Recommended |
|---|---|---|
| Chrome | 120 | Latest stable |
| Safari | 17 | Latest stable |
| Firefox | 121 | Latest stable |
| Edge | 120 | Latest stable |
| Samsung Internet | 23 | Latest stable |
| Opera | 106 | Latest stable |
Recognising phishing attempts that target Wecap users
Phishing attempts targeting fantasy gaming users are common. The desk publishes the signals so readers can spot them.
What phishing does
- Send SMS or email claiming urgent KYC verification
- Link to a URL that looks like wecapin but is actually a different domain
- Ask for OTP, Aadhaar or bank PIN
- Imply the account will be suspended within hours
What the real site does
- Never asks for OTP or bank PIN
- Verifies only inside the app or web desk
- Uses wecapin.com as the only domain
- KYC has a fixed turnaround; no urgency tactics
How to report a phishing attempt
Phishing attempts should be reported to the desk. Reports are reviewed within 24 hours.
- 1Do not click the link
Do not click any link in the suspicious message. Forward the message to the desk for review.
- 2Capture the URL
Take a screenshot of the URL bar if you opened the link. The desk uses this to escalate to the hosting provider.
- 3Forward to the desk
Forward the message to the customer-care desk via in-app chat. The desk reviews within 24 hours.
- 4Change your password
If you entered credentials on the phishing site, change your Wecap password immediately. The wallet menu has the change-password option.
The five-check verification list
Before you sign in or deposit, run through this five-check list. It's the cheapest way to spot a fake mirror.
- 1Check the URL bar
The URL must read wecapin.com. Anything else is unofficial.
- 2Check the certificate
Tap the padlock; the certificate must be issued to wecapin.com.
- 3Check the APK publisher
If you installed from outside the App Store, verify the publisher name against the official name on /download/.
- 4Check the editorial column
The official Wecap site carries the captain pick desk, the salary cap playbook and the verified winners ledger. Fake mirrors typically show only a sign-in form.
- 5Check the social channels
The official social channels match the brand name. Anything else is unofficial.
Why Wecap uses a single primary domain
Wecap operates from wecapin.com only. Single-domain operation reduces phishing risk and brand confusion.
Single-domain discipline
A single primary domain means readers always know where the official site is. Any other domain is a fake mirror; the desk escalates reported mirrors within 24 hours.
Reader clarity
Single-domain operation gives readers a single URL to remember. Marketing campaigns that point to different domains are restricted.
Operational efficiency
Single-domain operation reduces the certificate and hosting overhead. The desk spends the saved budget on the editorial column instead.
Subdomains and redirects
Wecap runs a small number of subdomains. The list is documented below for readers who want to verify.
- 1www.wecapin.com
The public-facing subdomain. Both www.wecapin.com and wecapin.com resolve to the same surface.
- 2Login.wecapin.com
The login subdomain. Handles sign-in and the play desk session; redirects to www.wecapin.com after auth.
- 3static.wecapin.com
The static asset subdomain. Hosts CSS, JS and images; redirects to www.wecapin.com if hit directly.
- 4All other subdomains
Redirect to the primary domain. Any subdomain not listed above is unofficial.