ScamLens

Dwg. ScamLens / Sheet 01 / Scale 1:1

Suspicious message?
Inspect the evidence.

Paste an email, text message or link. ScamLens runs deterministic checks for the patterns scammers rely on, from look alike domains to urgency scripts, and shows you each finding with its evidence instead of a mystery score.

Nothing you paste is saved. Analysis runs and the content is discarded.

Detail A: intercepted messageSMS
Your package could not be delivered. Pay the redelivery fee within 2 hours or it will be returned: https://bit.ly.example/rZk1q
  1. D1Artificial urgencymediumA two hour deadline pushes you to act before thinking.
  2. D2Payment requestmediumUnexpected fees by link are a common pretext for card theft.
  3. D3Shortened linklowThe true destination is hidden behind a shortener.

Documented rules

Automated tests

Things stored by default

URLs ever visited

Schedule of checks

Every rule, on the drawing

Read what each one means
  • URL_IP_LITERAL

    IP address used instead of a domain

    high

  • URL_PUNYCODE

    Internationalized (punycode) domain

    info

  • URL_SHORTENER

    Shortened link

    low

  • URL_DECEPTIVE_SUBDOMAIN

    Deceptive subdomain structure

    high

  • URL_LOOKALIKE_DOMAIN

    Look-alike domain

    high

  • URL_USERINFO

    Username trick in URL

    high

  • URL_MALFORMED

    Malformed URL

    low

  • URL_UNUSUAL_STRUCTURE

    Unusually long or deep hostname

    low

  • EMAIL_DISPLAY_NAME_BRAND_MISMATCH

    Display name imitates a brand

    high

  • EMAIL_REPLY_TO_MISMATCH

    Reply-To goes to a different domain

    medium

  • EMAIL_AUTH_FAILURE

    Email authentication reported failures

    medium

  • LANG_URGENCY

    Artificial urgency

    medium

  • LANG_THREAT

    Fear or threat language

    medium

  • LANG_CREDENTIAL_REQUEST

    Credential request

    medium

  • LANG_PAYMENT_REQUEST

    Payment request

    medium

  • LANG_GIFTCARD_CRYPTO

    Gift card or cryptocurrency payment

    high

  • LANG_SECRECY

    Request for secrecy

    medium

  • HTML_LINK_TEXT_MISMATCH

    Link text does not match destination

    high

Generated from the live rule registry, ruleset 1.0.1.

Method

How a message gets read

D1

Extract

URLs, sender addresses, links hidden in HTML and pasted email headers are pulled out and normalized, including punycode and the true registrable domain.

D2

Check

Eighteen independent rules look for structural tricks and social engineering language. Each rule is documented, versioned and tested against false positives.

D3

Explain

Every finding shows its evidence, why the pattern matters and what to do instead. The overall assessment follows a published decision table with no opaque percentages.

What ScamLens will not tell you

It will never say a message is safe. A clean result means the current rules found nothing, and sophisticated scams can pass every static check. It will never say something is certainly a scam either. It shows you the indicators and lets the evidence speak.

Private by construction

Content is analyzed in memory and discarded. No accounts, no database, no analytics. Submitted URLs are never visited, so the analysis is purely static. Read the privacy model.

Paste the thing that felt off.

Sixty seconds from a bad feeling to a list of reasons, or an honest nothing.