Is it a scam? ← Home
Methodology

How a verdict is made.

A service that says “trust us” about scams should show its working. This page explains the three verdicts and what each one promises, why an unknown sender is never called safe, and what happens when we get one wrong.

The three verdicts, and what each promises

Looks fine

Something concrete vouches for this message — and we say what it is.

Be careful

Nothing looks wrong, and nothing proves it's safe. Check before acting.

This is a scam

It matches a known scam pattern — and we name the pattern.

Green requires positive proof

The most important rule in the engine is about what it will not say. A message is never called safe just because nothing looked wrong. “Looks fine” has to be earned by a positive signal: the sender is in the family's trusted contacts, or the link resolves to a verified official sender — the real Australia Post, the real myGov, a bank's actual domain.

An unknown sender with a clean-looking message stays at “be careful”, because a clean-looking message from a stranger is exactly what a good scam looks like. This is also why the free web checker answers “be careful” so often: a pasted message arrives with no sender and no family context, so there is nothing that can vouch for it. That's the honest answer, not a hedge.

The same rule holds when our own systems stumble. If a lookup we rely on is unavailable mid-check, the verdict can stay cautious or get stronger — it can never soften to green on a check we couldn't fully run.

Rules first, with reasons you can read

Every check runs through a deterministic rules engine first: several hundred named patterns built from real Australian scams. Each verdict carries its reason codes — FAMILY_EMERGENCY_PATTERN for “Mum, I've been in an accident, don't tell Dad”, WRONG_NUMBER_OPENER for the friendly stranger who texted the “wrong number” and kept chatting, SAFE_ACCOUNT_PATTERN for a “bank” asking you to move money somewhere safe.

Deterministic means the same message always gets the same answer, any verdict can be replayed and audited afterwards, and when we tell someone why a message is a scam, the reason is the actual reason — not a story written after the fact.

An AI second opinion runs on top when it adds value, and the reply says so when it does. It can strengthen a warning; it is never allowed to overrule the rules into a green.

New scams, and the safe direction to fail

Most “new” scams are old shapes wearing new words, and the rules target the shapes: urgency plus a payment method, a relative in trouble plus secrecy, a prize plus a fee. A genuinely novel template can score “be careful” before it scores “scam” — which is the failure direction we chose on purpose, because amber already does the protective work: it tells the person to check before acting.

Then the network effect closes the gap. Campaign fingerprints update from live forwards across all covered families, so the second household to receive a campaign benefits from the first one that forwarded it.

Tested against lists we didn't write

A detector tested only by its own authors proves nothing much, so we run the engine against third-party scam catalogues and publish the results either way. Two so far, most recently August 2026 — and the number that matters is the first one:

0 of 38
rated “looks fine”. Across both catalogues, not one scam was called safe. That is the failure that would actually hurt someone, and it is the number we hold ourselves to.

Panda Security's 20 scam-text examples — delivery, tolls, bank fraud, fake jobs, gift cards, the “wrong number” opener.

20 rated scam

INS LifeGuard's top threats facing Australians in 2026 — voice-clone family emergencies, deepfake investment lures, myGov and Medicare impersonation, remote-access cons.

17 rated scam

The eighteenth is held at “be careful” on purpose. It is a bare “Mum, I've been in an accident” — no money asked for, no secrecy, nothing else. A real one reads exactly the same, so we will not call it a scam. And we don't need to: “be careful” already says the one thing that is right either way — ring them on the number you already have for them. Making that message red would earn us a rounder number here at the cost of telling a mother her injured son is a scammer.

1 by design

Read these honestly. These are our own runs against outside catalogues, not an independent audit, and catching known shapes is table stakes. The harder half is the innocent side: the same suite checks that a genuine super statement, a gym promo, a surprise-party text and a real “sorry, wrong number” are not called scams — because a service that cries wolf teaches people to stop forwarding, and then it protects nobody.

When we're wrong

Anyone can reply WRONG to any verdict — it's in the reply itself. Every WRONG is read by a human, the message content is retained encrypted for 30 days precisely so mistakes can be reviewed, and confirmed misses update the rules and blocklists for every family at once. A verdict is a second opinion to help someone pause and check — it is not a guarantee, and we'd rather say that here than in small print.