Skip to content

How a scan becomes a verdict.

Eight signals resolve independently and stream into one score. High-confidence reputation checks carry the most weight; local context keeps the result useful when a provider is degraded.

Scoring

Safe Browsing matches, community feed hits, and multi-engine detections move the verdict most. TLS quality, WHOIS age, DNS posture, and redirect behavior are supporting evidence rather than the primary driver.

Risk-moving
Google Safe Browsing, threat feeds (URLhaus, OpenPhish), VirusTotal detections, ML ensemble consensus.
Supporting
TLS validation, WHOIS age and registrar, DNS anomalies, redirect-chain hops.

Score bands

0–24
Safe
25–54
Suspicious
55–79
Malicious
80–100
Critical

Confidence

Confidence is coverage-aware, not just score bands. A safe verdict loses confidence when primary reputation sources time out; a risky verdict gains confidence when independent categories agree. Partial coverage is always stated next to the verdict.

Using the scanner

  • Each signal row expands to its full evidence — engines, certificate fields, redirect hops.
  • Batch rows resolve independently; open any finished row in the scanner for the full result.
  • Saved scans stay on this device unless you export or share them — see privacy for what the server still processes.
  • URLhaus and OpenPhish treat exact listed URLs as high-confidence evidence and hostname-only fallbacks as medium confidence. Browse pages like urlhaus.abuse.ch/browse/ are not matches.