Five analyzers — website, email, text message, QR code, and screenshot — each return a single 0–100 Trust Score with a plain-language verdict and a concrete next step.
The five analyzers
The same deterministic pipeline runs on every input type — same rules, same weights, same band cutoffs.
Paste a domain or URL — the analyzer scores the host, scheme, brand signals, and path patterns.
Paste email headers and body — the analyzer checks sender domain, reply-to divergence, and pressure language.
Paste an SMS or chat — the analyzer scans sender shape, urgency phrasing, and any embedded links.
Upload a QR image — the analyzer decodes the payload server-side and routes it through the URL rules.
Upload a screenshot — the analyzer extracts text, finds links, and runs keyword and URL rules against what the image says.
Signals
The same deterministic weighted rules run on every input. Eight categories cover the patterns that drive BEC, smishing, package-redelivery, and brand-impersonation scams.
The email's sender domain is impersonating a widely-trusted brand — the real PayPal never sends from paypa1-secure.example. We compare the sender host against an offline brand-token list and flag the impersonation.
The Reply-To address lives on a different domain than the From: — replying routes your message to an attacker-controlled inbox that need not belong to the brand that sent it.
Less common top-level domains (.top, .xyz, .click …) are cheaper to register in bulk and over-represented in scam infrastructure. A score penalty isn't dispositive on its own, but a known-bad TLD combined with another signal is.
"Act now or your account will be closed." Banks do not threaten; they notify. We scan the body for urgency, legal-threat, and code-request phrasing — the lexicon shared by BEC, sextortion, and package-redelivery scams.
Attorney invoices, vendor payment changes, and rental deposits increasingly ask for wire transfer or crypto wallet addresses instead of the established card-on-file. We flag the wording and pause the pattern.
Hosting a brand token as a subdomain on an unrelated registry is the canonical phishing shape — secure-paypal.example.com is not PayPal. We match the brand token against the registrable domain, never the path.
A shortened link hides the destination, so the URL pipeline can't fingerprint it before you click. We recognise the host and call it out — never resolve the redirect ourselves, so we can't be weaponised into a phishing payload either.
Punycode (xn--) hosts, mixed-script tokens, and digit-substituted brand names (paypa1, g00gle) are designed to slip past human eyes. We decode the IDN, compare against the brand list, and raise the signal you missed.
The 0–100 scale
A higher score means fewer warning signs were matched — not“verified safe”. Veridex does not advertise an accuracy percentage.
| Score range | Risk label | Verdict phrase | Next step |
|---|---|---|---|
| 75–100 | Low Risk | no major warning signs detected | Standard caution still advised — sign in only on sites you reached yourself. |
| 40–74 | Medium Risk | potential warning signs detected | Verify the sender through a separate channel before clicking or signing in. |
| 0–39 | High Risk | potential warning signs detected | Do not enter credentials, payment details, or one-time codes. |
Recommended actions
Each result surfaces exactly three concise next steps written for a non-technical reader. Actions are keyed to the band — they describe what to do with the message, not a claim about the target.
Score 0–39
Score 40–74
Score 75–100
Limitations
Honest about what the score does not tell you.
Veridex provides automated AI-powered security assessments based on hundreds of technical and behavioral signals. Trust Scores are informational assessments and should not be interpreted as definitive factual statements. Users should independently verify important decisions before relying on any assessment.
Premium and Family plans unlock all five analyzers, unlimited checks, and advanced AI explanations.
View plans