How verdicts work
ScammersCheck queries multiple independent threat intelligence sources simultaneously and combines their signals into a single risk score and verdict. Here is exactly how it works.
The checking process
The five verdict tiers
The entity has been confirmed as malicious by one or more authoritative threat intelligence sources. It appears on known scam databases, phishing blocklists, or has a documented history of fraudulent activity. Avoid all interaction.
Multiple strong signals indicate this entity is likely involved in scam or fraud activity. It may not yet be on official blocklists but exhibits patterns consistent with known threats. Exercise extreme caution.
Some signals suggest this entity may be problematic — for example, a recently registered domain, community reports, or unusual patterns. Proceed with caution and verify through additional channels before engaging.
No significant threat signals were detected across our sources. This does not guarantee the entity is safe — it simply means no known threats were identified at the time of checking. Always exercise reasonable caution.
The entity could not be analysed — this may be because the input format was not recognised, the APIs were temporarily unavailable, or the content was too ambiguous to classify. Try again or rephrase your input.
Signal sources
| Source | What it checks |
|---|---|
| Google Safe Browsing | Checks URLs against Google's phishing, malware, social-engineering, and potentially harmful application data when a URL is present. |
| VirusTotal | Retrieves or submits a primary URL for multi-engine URL analysis when the service is available. |
| IPQualityScore & SkipCalls | Provide phone, email, or IP reputation and phone-spam information for the input types they support. |
| RDAP, certificate history & hosting-IP data | Provide contextual domain registration, certificate, and infrastructure evidence for relevant URLs or domains. |
| Phishing and malware blocklists | Relevant URL domains can be compared with Phishing Army, Spamhaus DBL, SURBL, URIBL, URLhaus, and ThreatFox, subject to availability and safeguards. |
| Local technical analysis | Pattern, domain-anomaly, and phone-intelligence checks analyse the submitted content locally. |
| Contextual message analysis | For applicable messages and non-text entities, contextual analysis helps explain patterns in the submitted content and available evidence. |
| Community reports | Community scam and safe reports are rate-limited, not independently verified, and have additional safeguards for phone-number reports. |
Important limitations
ScammersCheck results are risk indicators, not definitive verdicts. A clean result does not mean an entity is safe — new scam infrastructure is created daily and may not yet appear in threat databases.
Results depend on the quality and freshness of third-party data sources, which are outside our control. Always cross-reference with other sources before making important decisions.
The service is not a consumer reporting agency and must not be used to make employment, credit, insurance, or housing decisions about individuals.
How to use a result responsibly
A check is most useful as a pause button. It can help you notice a known warning or a pattern that deserves closer attention, but it cannot prove who is behind an account or predict what will happen next. Treat the result as one piece of evidence in a decision you still control.
When a result raises concern
Stop the conversation before sending money, codes, identity documents, or passwords. Do not use a phone number or link supplied by the message to “confirm” the story. Instead, contact the organisation through a number or website you found independently.
When no threat is found
Check the context as well as the entity. A new domain, newly issued number, compromised legitimate account, or targeted message may not yet have a public record. Verify payment requests, urgency, identity, and account changes through a separate trusted channel.
When coverage is limited
A limited or insufficient coverage note means fewer applicable sources returned usable information. It is not a low-risk result. The safest response is to delay the decision and seek independent confirmation.
If money or information was shared
Contact your bank or card provider immediately using its official channel, change affected passwords from a trusted device, and report the incident to the relevant national authority. Preserve messages, payment references, and headers for the organisation handling the report.
What “independent sources” means here
Independence is about using different evidence paths, not counting every response as proof. A blocklist hit, domain-registration context, community report, and local pattern signal answer different questions and can be incomplete or wrong. We therefore show source-level evidence, retain provider-availability context, and avoid presenting a score as a probability of fraud.
Source availability changes over time. Our describes the current source categories, while the explain how public guidance is reviewed. For independent safety advice, consult the UK National Cyber Security Centre phishing guidance and Action Fraud.