How to Tell an Official Source From a Pirated One

Official sources identify their operator, sell through recognised payment processors, carry complete and consistent catalogue metadata, and honour removal requests. Unauthorised sites hide ownership, monetise through intrusive advertising, host inconsistent re-encodes, and offer current releases free in full.

Last updated Mon Aug 03 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

Legitimate distribution leaves a paper trail that unauthorised distribution cannot afford to imitate: an identifiable corporate operator, a mainstream payment processor, complete catalogue metadata, and a working process for handling removal requests. Everything else — site design, video quality, size of catalogue — is cheap to fake and tells you nothing.

Being able to read that difference matters for three separate reasons: legal exposure varies by jurisdiction, unauthorised sites are where malicious advertising and payment fraud concentrate, and the performers whose work you are looking for are only compensated by one of the two.

What signals actually distinguish them?

Weight them by how expensive they are to fake.

Signal Official source Unauthorised source
Named operating company, address, registration details Published, usually in a legally required disclosure page Absent, vague, or an offshore shell with no contact route
Payment method Mainstream card processors, established regional methods Crypto-only, obscure processors, or "free" with no payment at all
Catalogue metadata Consistent codes, release dates, runtimes, credited performers Inconsistent, missing, or scraped and mismatched
File naming The studio's own code Code plus added suffixes marking a re-encode
Availability of current releases Paid, windowed, region-dependent Latest titles free and in full
Advertising Its own products, or none Pop-unders, redirect chains, fake players, adult-dating and gambling ads
Removal requests A documented process that is honoured No process; removed material reappears
Domain history Stable, long-lived, matches the brand Frequently rotating domains and mirrors

The row that resolves most cases in one step is the fifth. Current commercial releases available free and in full is not a business model — it is the definition of unauthorised distribution. No amount of professional design changes what that row means.

Why does the operator disclosure matter so much?

Because legitimate commercial distribution cannot operate anonymously, and unauthorised distribution cannot operate openly.

A licensed distributor needs a bank, a payment processor, and contracts with rights holders. All three require a real, identifiable legal entity, and consumer-protection and e-commerce rules in most markets require that entity to be disclosed to customers. An unauthorised operation cannot survive that disclosure, so it does not make it.

This is why "who operates this site, and where can I write to them" is a more informative question than anything about the content itself.

What are the practical risks of unauthorised sites?

They are concrete and mostly not about copyright.

Risk How it shows up
Malicious advertising Redirect chains, fake "update your player" prompts, drive-by download attempts
Fake subscription and phishing pages Payment forms imitating a real platform, harvesting card details
Payment fraud Charges from unrelated merchants, recurring billing that cannot be cancelled
Malware disguised as media Files that are executables, archives requiring a "codec" to open
Non-consensual and withdrawn material Content removed elsewhere by request continues to circulate here
Synthetic and misattributed content Re-encodes with altered or substituted footage, with no accountable source
Legal exposure Varies significantly by jurisdiction; obtaining and distributing are treated differently in different countries

The fifth and sixth rows connect to a point worth making explicitly. Sites with no accountable operator have no removal process, which is exactly why material that has been withdrawn — including at a performer's request — persists there. That is not an incidental flaw; it is a structural consequence of anonymity.

How do you verify a title's official home?

Work from the code, which is the identifier official catalogues index on.

  1. Get the release code from the cover, the opening titles, or by identifying the performer and working through the filmography.
  2. Identify the label from the prefix. The letters tell you which studio released it.
  3. Check that studio's own catalogue for the code. That listing is the authoritative record of what the release is.
  4. Follow the studio's listed distribution partners rather than searching the code in a general search engine, where unauthorised aggregators rank well.
  5. Compare metadata. If a site's runtime, release date or credited performers disagree with the studio's listing, that site scraped its data and is not a licensed distributor.

Step 5 is a useful test because unauthorised aggregators build metadata by scraping, and scraped data drifts. Disagreement with the studio's own record is a reliable tell.

Where does face search fit in?

At step 1, when you have no code — and as a check on attribution.

A frame with a visible face identifies the performer, and the filmography gets you to the code that official catalogues can be searched with. Our index holds 241,792 faces with 2,333 linked to a named performer across 106 sites (our index, 2026-08 snapshot).

It also helps with the sixth risk row above. Sites that redistribute without accountability also mislabel: a title credited to the wrong performer, or footage attributed to someone who is not in it. Comparing the face in the frame against the credited name is a direct check on that.

Boundary worth stating: we index faces, not licences. A match tells you who appears in the frame; it cannot tell you whether the site you found it on is authorised, and 2,246 of our 2,333 named performers have their representative image from a single source, so coverage is uneven by construction.

Related questions


If you are trying to check whether a site's attribution is honest, start with the frame: upload it here and compare the identified performer against the name the site credits. Detection runs in your browser and the original never leaves your device.

Frequently asked

Is a site with a professional design likely to be legitimate?
Design says nothing. Templates are cheap and unauthorised aggregators routinely look polished. Operator identity, payment method and catalogue consistency are the signals that cost money to fake.
What is the most reliable single indicator?
Whether a real, named company is identified as the operator, together with a mainstream payment processor. Legitimate distribution requires both; unauthorised operations can sustain neither.
Why do file names on unauthorised sites carry extra suffixes?
Because those files are re-encodes. Suffixes are added by whoever processed and redistributed the file, and their presence signals that you are not looking at the studio's own release.