Dwg. ScamLens / Sheet 01 / Scale 1:1
Suspicious message?
Inspect the evidence.
Paste an email, text message or link. ScamLens runs deterministic checks for the patterns scammers rely on, from look alike domains to urgency scripts, and shows you each finding with its evidence instead of a mystery score.
Nothing you paste is saved. Analysis runs and the content is discarded.
Your package could not be delivered. Pay the redelivery fee within 2 hours or it will be returned: https://bit.ly.example/rZk1q
- D1Artificial urgencymediumA two hour deadline pushes you to act before thinking.
- D2Payment requestmediumUnexpected fees by link are a common pretext for card theft.
- D3Shortened linklowThe true destination is hidden behind a shortener.
Documented rules
Automated tests
Things stored by default
URLs ever visited
Schedule of checks
Every rule, on the drawing
URL_IP_LITERALIP address used instead of a domain
high
URL_PUNYCODEInternationalized (punycode) domain
info
URL_SHORTENERShortened link
low
URL_DECEPTIVE_SUBDOMAINDeceptive subdomain structure
high
URL_LOOKALIKE_DOMAINLook-alike domain
high
URL_USERINFOUsername trick in URL
high
URL_MALFORMEDMalformed URL
low
URL_UNUSUAL_STRUCTUREUnusually long or deep hostname
low
EMAIL_DISPLAY_NAME_BRAND_MISMATCHDisplay name imitates a brand
high
EMAIL_REPLY_TO_MISMATCHReply-To goes to a different domain
medium
EMAIL_AUTH_FAILUREEmail authentication reported failures
medium
LANG_URGENCYArtificial urgency
medium
LANG_THREATFear or threat language
medium
LANG_CREDENTIAL_REQUESTCredential request
medium
LANG_PAYMENT_REQUESTPayment request
medium
LANG_GIFTCARD_CRYPTOGift card or cryptocurrency payment
high
LANG_SECRECYRequest for secrecy
medium
HTML_LINK_TEXT_MISMATCHLink text does not match destination
high
Generated from the live rule registry, ruleset 1.0.1.
Method
How a message gets read
Extract
URLs, sender addresses, links hidden in HTML and pasted email headers are pulled out and normalized, including punycode and the true registrable domain.
Check
Eighteen independent rules look for structural tricks and social engineering language. Each rule is documented, versioned and tested against false positives.
Explain
Every finding shows its evidence, why the pattern matters and what to do instead. The overall assessment follows a published decision table with no opaque percentages.
What ScamLens will not tell you
It will never say a message is safe. A clean result means the current rules found nothing, and sophisticated scams can pass every static check. It will never say something is certainly a scam either. It shows you the indicators and lets the evidence speak.
Private by construction
Content is analyzed in memory and discarded. No accounts, no database, no analytics. Submitted URLs are never visited, so the analysis is purely static. Read the privacy model.
Paste the thing that felt off.
Sixty seconds from a bad feeling to a list of reasons, or an honest nothing.