How Scam Check Analyzes Content
A transparent look at every stage of the analysis pipeline — from input to actionable results.
Any Content That Looks Suspicious
Scam Check accepts the formats scams actually arrive in — because the danger is rarely a bare URL.
Text Messages
Paste entire SMS, WhatsApp, Telegram, or iMessage conversations — including suspicious links and callback numbers.
URLs & Links
Submit any link. We decode shortened URLs and inspect the underlying domain, hosting, and TLS certificate.
Screenshots
Upload a screenshot of a chat, email, or pop-up. Vision analysis reads the on-screen content and flags red flags.
Emails
Paste phishing or suspicious emails to check the sender domain, urgency language, and credential-harvesting prompts.
Step 1: You Submit Content
Paste text messages, paste a URL, or upload a screenshot. Scam Check accepts multiple input formats so you can check whatever you received.
Step 2: Technical Analysis
The system inspects domain reputation, HTTPS certificate validity, hosting provider history, top-level domain risk signals, and DNS records for the URL you provided.
Step 3: Content Analysis
The engine scans for behavioral manipulation patterns — urgency language, authority impersonation, credential harvesting prompts, emotional pressure tactics, and social engineering markers.
Step 4: Evidence Collection
Each technical and content finding becomes a discrete piece of evidence. No signal is assumed — every indicator is captured with its specific context.
Step 5: Risk Calculation
Evidence is scored, deduplicated, and weighted. Domain signals, content patterns, and known threat database matches are combined into a composite risk assessment.
Step 6: Results
You see what was found, what wasn't found, and what action to take. The report shows evidence breakdowns, confidence levels, and specific next-step recommendations.
Where Our Confidence Stops
Real tools know their limits. We report only what the evidence supports — and we are always honest about what we cannot know:
- ✕Cannot determine the real-time intent of the person who sent you the message.
- ✕Cannot access private backend systems or internal databases of companies.
- ✕Cannot verify identity — it analyzes content and infrastructure, not people.
- ✕Cannot detect brand-new zero-day threats that have never been seen before.
- ✕Is not a substitute for official law enforcement reporting or banking fraud claims.
A Report That Helps You Decide & Act
The goal is not a scary score — it is a clear answer plus the exact next step.
Risk Rating
A clear LOW / MEDIUM / HIGH / CRITICAL risk level computed from scored, weighted evidence.
Evidence Breakdown
Every finding is shown individually with its source and context — no hidden verdicts.
Confidence Levels
Each check reports how confident we are, distinguishing "possible" from "confirmed".
Actionable Steps
Specific next actions: block, report, change passwords, contact your bank — matched to your result.
See It In Action
Submit any suspicious content and watch the analysis pipeline work in real time.