Back to scanner
Method
How a scan becomes a verdict.
A scan combines high-confidence reputation checks with resilient local signals so the output stays useful even when one provider is degraded. Each signal resolves independently, and verdict confidence explains how much clean or risky coverage actually supported the final score.
Scoring approach
High-confidence evidence moves the verdict most.
Safe Browsing matches, community feed hits, and stronger multi-engine detections outweigh softer context. DNS posture, TLS quality, WHOIS age, and redirect behavior still matter, but they are supporting evidence rather than the primary driver.
Risk-moving signals
- Google Safe Browsing
- Threat feeds: URLhaus and OpenPhish — matches use the exact listed URL string, not directory or hub pages.
- VirusTotal multi-engine detections
- Local ensemble consensus
Resilience signals
- TLS validation and certificate metadata
- WHOIS age, registrar, and country
- DNS anomalies and passive observations
- Redirect-chain hops and terminal reachability
Using the console
How to read lanes, batches, and feeds.
- Summary vs full
- Summary prioritizes the highest-impact lanes; full shows every outcome, including caveats.
- Batch stays isolated
- Queue short lists, then open any finished row in single-scan mode from the scan console.
- Browser-only history
- Saved scans stay on-device unless you export or share them. See privacy for what the server still processes.
- Feed hits need the full URL
- URLhaus and OpenPhish match the exact IOC string you paste — not browse pages like urlhaus.abuse.ch/browse/.