A score summarises observable signals about a link, address or number. It tells you how much caution is warranted, not whether something is objectively criminal.
People want a yes or a no. A checker can give neither honestly, because the question 'is this safe?' depends on context the checker does not have: what you plan to do, what account you use, what you have already shared.
What a checker can do is describe what it observed and how unusual that combination is. That is what the score is: a readable summary of observations, ordered so the most decisive ones come first.
What goes into a score
- The address itself: its structure, its domain, and whether the domain is a lookalike of one you would recognise.
- Domain age and registration facts where they are publicly available, because young domains are disposable by design.
- Whether the domain appears on published blocklists used for known phishing infrastructure.
- The content of a message: urgency, payment requests, requests for credentials or codes, and mismatches between who it claims to be from and where it actually points.
- For phone numbers and email addresses, the format, the provider and patterns that are characteristic of bulk automated sending.
What a score cannot do
- It cannot prove a site is fraudulent. A legitimately new business and a fake shop look similar in the data.
- It cannot prove a site is safe. Infrastructure is often compromised after it was clean, and reputation data lags reality.
- It cannot see what happens after you arrive: a page can be changed the hour after it was checked.
- It cannot know your context — whether you are already logged in, whether you are expecting this message, whether you have already shared the details it asks for.
- It cannot read a screenshot, an image, a voice note or a video. If it was not text or a link, nothing was analysed.
How to use a score well
- 1Read the reasons, not only the number. The reasons are the part you can act on.
- 2Treat a high score as a reason to stop and verify through a route you chose yourself — the organisation's own site or a number you already had.
- 3Treat a low score as permission to be less suspicious, not as permission to skip a verification step that a message is asking you to skip.
- 4If money is involved and the score is anything other than clearly safe, verify before paying. Payments are the one thing that is hard to undo.
Frequently asked questions
Why is nothing ever simply 'safe' or 'dangerous'?
Because both words are claims about the world that a checker cannot verify. A score describes what was observed and how unusual it is; the decision stays with you, which is also where the responsibility belongs.
Can I rely on a low score?
Use it to calibrate caution, not to skip it. If a message asks you to pay, to log in, or to share a code, verify through a route you chose yourself regardless of the score.
Do the scores improve over time?
The signals come from public and licensed sources, so they improve as those sources do. Their limits do not disappear: novelty and compromise after the fact remain invisible to any reputation-based method.
Written by The BaitScan team
Last updated September 16, 2026
Results are automated risk estimates based on public indicators and heuristics.