Useful certainty, honest uncertainty
What happens after you paste a link
You shouldn’t need to become a cybersecurity expert just to read your messages. We turn several technical checks into one plain answer — including when the honest answer is “we haven’t seen this before”.
First, we look for a match
We compare the address with warnings from OpenPhish, PhishTank, phishunt, security researchers and reports sent in by the public. Twice a day we also look for new scams aimed at South African banks, SASSA, SARS, retailers and couriers.
Then, we inspect the trail
Suspicious links can be checked in a remote security sandbox using urlscan.io. The page does not open on your phone. The scan can show us which brand it copies, how it behaves and whether other researchers have marked it as malicious.
What we refuse to pretend
A result of “new to us” does not mean safe. No database knows every scam, and a convincing message can be dangerous before anyone reports it. We show what we know without manufacturing confidence.
What we never collect
We don’t collect stolen passwords, PINs or victim details. If a scam is leaking information, we report the location to the affected brand or a CERT so they can act. We do not download the data ourselves.
If you think you’ve been scammed
- Phone your bank’s fraud line immediately (use the number on your card).
- Change any password or PIN you may have entered.
- Report it to SAPS and to SABRIC (the SA Banking Risk Centre).
- Warn friends and family who might get the same message.
Still holding that suspicious link?
Get a second opinion