How this tool works
A security tool that will not explain itself is asking to be trusted on faith. Here is what it actually does.
Last reviewed 28 August 2026
Where the checking happens
The detection runs on your own phone or computer, inside the page. When it runs that way, the message is never sent anywhere, because there is nowhere for it to be sent. That is not a promise about what we do with your message; it is a description of how the thing is built.
It also means the checker works with no connection at all. On a train, in a village, on a dead network, you still get an answer.
What it looks for
The checker holds a library of 48 signals, grouped into 10 kinds. Every point in the score comes from a named signal, which is why the result can show you its working rather than just a number.
- Asks for a secret
The message asks for something no genuine bank or company will ever ask for: an OTP, a PIN, a CVV, a UPI PIN, a card number, a net banking password, an Aadhaar or a PAN. - Rushes or threatens you
The message manufactures a deadline or a threat so you act before you think: an account blocked, a KYC expiring today, legal action, a last warning. - The link is wrong
What the address actually points at: shortened links, a bare IP address, a lookalike domain, an unusual ending, deep nesting, plain HTTP, or a brand name in the wrong part of the address. - Offers you something
Bait rather than fear: a lottery win, cashback, a refund pending, a prize to claim, an unclaimed parcel, or a job you never applied for. - Pretends to be someone
The message claims to be a bank, a telecom operator, a courier, a tax or government scheme, a wallet or an electricity board. - The sender is wrong
An institution's message arriving from an ordinary personal 10-digit number, rather than a registered commercial header. - Tells you to pay
UPI handles, account numbers, QR references, and the classic 'transfer 1 rupee to verify'. - Wants you to install something
A request to download an APK or install a screen-sharing app, which hands your phone to someone else. - Written to defeat filters
Excessive capitals, spacing tricks, hidden characters, mixed scripts and bulk-template grammar. - Looks ordinary
Patterns recognised as normal, which pull the score down so that genuine OTP and delivery messages are not flagged as scams.
The last group matters as much as the others. Without signals that pull the score down, a checker flags everything, and a tool that calls your real bank OTP a scam is worse than no tool.
Why the keywords are not published
The groups and the reasoning are here in full. The specific words and the weight each carries are not. Publishing those would hand whoever writes these messages a checklist of exactly what to avoid, and the people it would protect are not the ones reading this page.
Signals together, not signals added up
A request for a one-time code is one thing. A request for a code, alongside a hidden link and a deadline of today, is far more than those three added together, and the score reflects that. Combinations are shown separately in the breakdown so you can see where the extra weight came from.
What it will not do
- It never opens a link from your message. Not to inspect it, not to follow a redirect. Opening one would tell whoever sent it that your number is live.
- It never looks anything up against an outside service, so checking a message does not tell any third party that you received it.
- It does not read your inbox. It only reads what you paste in.
- It does not report anything to anyone on your behalf.
Signal library version 0.7.0, last updated 2026-09-05. What happens to your message.