The checks that earn their place in a small business are the ones applied to a routine: verifying a payment change, checking a link before clicking, and checking a domain against your own name.
Small businesses are targeted because they move money quickly, decide with few people and rarely have a verification routine. The attacks are mostly administrative: an invoice with new bank details, a supplier emailing from a similar domain, a message from a director who is travelling.
The free tools here cover the checking part of that. The rest is a process, and a process is cheaper than any product.
Where the checks fit into a normal week
- Before paying an invoice with changed bank details, verify the change by calling a number you already had. Never the number in the email.
- When a supplier's message arrives from a domain you have not seen, check the domain before the reply.
- Before staff scan a QR code from a poster, a delivery note or an invoice, check the destination where possible and prefer typing the address.
- When training happens, use the checks live on real messages rather than on slides. People remember what they ran themselves.
- When a lookalike domain appears, check it here to record the pattern, then report it to the host and the registrar.
What is honestly not offered yet
- No shared business console, no team accounts and no centrally managed watchlist. That needs the account backend.
- No continuous monitoring of your domains or mailboxes, which would need a running service rather than a static site.
- No guarantee, certification or compliance claim. The checks return reasons and signals, not assurance for an auditor.
- No ability to see your employees' individual checks, and there will not be. Monitoring staff through a security tool is how a tool stops being used.
A process you can adopt today
- 1Write down one rule: any change to payment details is verified by callback to a previously known number.
- 2Name who may approve that change, and make it one person plus a second signature for larger amounts.
- 3Check a supplier domain before replying to it the first time, and keep the check as part of supplier onboarding.
- 4Check your own domain and obvious variants for lookalikes, monthly or after any press mention.
- 5Give staff one place to check a suspicious link or message, and state that checking costs nothing and never counts against them.
- 6Review after every near miss. A near miss is free training, and it is only useful if it is written down.
Frequently asked questions
Is there a business plan with a dashboard?
Not yet. A shared console needs accounts and a backend, and neither is built. The checks themselves are free and usable by staff today.
Can I check all my employees' email addresses?
Not from here, and the product is not intended to work that way. Breach checks are for an address you are entitled to check; monitoring staff through a security tool is not a feature here.
Will this satisfy a compliance requirement?
No, and it should not be presented as if it would. These are risk signals with explanations, useful for a decision, not an audit certificate.
Written by The BaitScan team
Last updated September 16, 2026
Results are automated risk estimates based on public indicators and heuristics.