Skip to main content

Transparency report

Where the data behind a result comes from

Results combine our own checks with public and licensed third-party data. Those sources set both the coverage and the credit requirements.

Every check on this site is built from two ingredients: what can be determined from the item itself, and what third-party data says about it. Naming them is part of using them honestly.

Some sources carry licence terms that require attribution. Where that is the case, the attribution is shown with the result it contributed to, not buried on a credits page.

Sources and what each covers

  • Our own analysis of the submitted item: the structure of a URL, domain or address, the message text, and the patterns that reveal a lookalike or a bulk sender.
  • Published blocklists of known phishing and malware infrastructure. These report what is already known, which is why they cannot catch a domain created this morning.
  • Public domain registration data, used as an indicator of how long a domain has existed. Registration is often privacy-protected, so the available facts can be sparse.
  • Breach-exposure data for email addresses, provided by third parties. Email monitoring uses XposedOrNot, and the attribution its terms require is displayed alongside the data. The password check uses Pwned Passwords, operated by Have I Been Pwned and published under the Creative Commons Attribution 4.0 licence, credited in the same way.
  • Password-checking services that use a range of the password's hash rather than the password itself, so the password never leaves your device and is never stored.

How third-party terms are respected

  • Attribution is shown where the data appears, together with a link to the source's licence.
  • Data is not resold, and it is not presented as our own work.
  • Terms that restrict automated bulk querying are respected; checks here are made for the person doing the checking, not to build a dataset.
  • Where a source's terms are unclear, the feature is not built on it. An unclear licence is a reason to leave something out, not to include it quietly.

What this means for a result

  1. 1If a check relies on third-party data, its accuracy is bounded by that data's accuracy and by how recently it was updated.
  2. 2If no source has anything to say about an item, that is reported as 'not found', which is not the same as 'safe'.
  3. 3If a source is unavailable, the affected part of the result is marked as unavailable rather than assumed to be clean.
  4. 4If you want the credit behind a specific finding, it is shown with the finding itself.

Frequently asked questions

Do you sell or store the things people check?

Queries are made to provide the result being asked for. Passwords are never transmitted or stored — only a partial hash is sent, which cannot be reversed into the password.

What licence applies to the breach data?

Third-party data is only ever shown together with the name of the source that supplied it. Email monitoring uses XposedOrNot, and that name appears wherever its data does. The password check uses Pwned Passwords, operated by Have I Been Pwned, whose Creative Commons Attribution 4.0 licence requires the same treatment.

Why is a domain I know is new not automatically flagged?

Because age alone does not distinguish a new legitimate business from a new fraudulent one. It is treated as a signal that adds weight to other findings, which is why a single indicator rarely decides a result.

Written by The BaitScan team

Last updated September 16, 2026

Results are automated risk estimates based on public indicators and heuristics.