Everything here was checked as text. Images, audio, video, private messages and anything behind a login were not analysed and cannot be scored.
A limit stated in advance is a feature. A limit discovered later is a betrayal. This page is the list of things the checker does not do, so that a result is never read as more than it is.
If your case is not on the list, assume it was only covered if the text or the link was actually submitted.
Not analysed at all
- Screenshots, photographs and images. Text inside a picture is invisible to a text check, and image content is not read.
- Voice notes, phone calls and video. There is no audio analysis and no transcription.
- Anything sent by a private channel whose contents you did not paste in: direct messages, encrypted chats, app notifications.
- What is behind a login, a paywall or a form. Only the public page was fetched.
- Files and attachments. A malicious document does not need a URL to be dangerous, and this check does not open files.
Analysed, but with a real limitation
- Reputation data describes the past. A domain that was clean last week can host a phishing page today, and a blocked domain can be cleaned and reused.
- Shorteners hide the destination. A short link may be resolved, but the page it opens can behave differently for a second visit.
- A very new but legitimate site will look like a very new site. Age is a signal, not a conclusion.
- Cloned pages are often on compromised real sites. The domain being genuine does not make every page on it genuine.
- Text was written by a person who wants to persuade. No automated check replaces judgement — particularly when the message knows things about you.
What to do instead
- 1For images and screenshots: read them yourself and copy the important text into a text check, or verify the claim through the organisation's own site.
- 2For calls and voice notes: hang up, or wait, and call back on a number you find yourself.
- 3For anything urgent: treat the urgency as the signal. A legitimate request survives a delay of an hour.
- 4For anything involving payment: verify the recipient through a channel you chose, before the money leaves.
- 5For a message that already feels personal and informed: that is worth more caution, not less, because it means your data is already circulating.
Frequently asked questions
Can I upload a screenshot for analysis?
No. Images and their text are not read. Copy the text out and check the links or the sender details in the tool instead.
A page was reported as safe but I was still scammed there. How?
Page content is not static. A page can be changed, replaced or injected into after any check, and checks that depend on reputation report the past, not the current moment.
Does a check look at whether a shop delivers?
No. Delivery, refund behaviour and customer service are not observable from a URL or a message. That is what the payment method is for — card disputes, not checkers.
Written by The BaitScan team
Last updated September 16, 2026
Results are automated risk estimates based on public indicators and heuristics.