How it Works

How Veridex computes a Trust Score

Five analyzers — website, email, text message, QR code, and screenshot — each return a single 0–100 Trust Score with a plain-language verdict and a concrete next step.

The five analyzers

Pick the input that matches what you want to check.

The same deterministic pipeline runs on every input type — same rules, same weights, same band cutoffs.

Website Trust Checker

Paste a domain or URL — the analyzer scores the host, scheme, brand signals, and path patterns.

Open

Email Scam Detector

Paste email headers and body — the analyzer checks sender domain, reply-to divergence, and pressure language.

Open

Text Message Analyzer

Paste an SMS or chat — the analyzer scans sender shape, urgency phrasing, and any embedded links.

Open

QR Code Scanner

Upload a QR image — the analyzer decodes the payload server-side and routes it through the URL rules.

Open

Screenshot Analyzer

Upload a screenshot — the analyzer extracts text, finds links, and runs keyword and URL rules against what the image says.

Open

Signals

What the pipeline looks for.

The same deterministic weighted rules run on every input. Eight categories cover the patterns that drive BEC, smishing, package-redelivery, and brand-impersonation scams.

Sender domain mismatch

Pattern

The email's sender domain is impersonating a widely-trusted brand — the real PayPal never sends from paypa1-secure.example. We compare the sender host against an offline brand-token list and flag the impersonation.

  • Sender host takes a known brand token and parks it as the look-alike
  • Display name says one brand, but the actual domain isn't theirs

Reply-to divergence

Pattern

The Reply-To address lives on a different domain than the From: — replying routes your message to an attacker-controlled inbox that need not belong to the brand that sent it.

  • From: support@brand.com — Reply-To: reply@brand-help.example
  • Any time the two domains differ, the divergence is recorded

Suspicious TLDs

Pattern

Less common top-level domains (.top, .xyz, .click …) are cheaper to register in bulk and over-represented in scam infrastructure. A score penalty isn't dispositive on its own, but a known-bad TLD combined with another signal is.

  • Uncommon sender TLD on an email From: address
  • Uncommon host TLD on a URL the message links to

Urgency and pressure language

Pattern

"Act now or your account will be closed." Banks do not threaten; they notify. We scan the body for urgency, legal-threat, and code-request phrasing — the lexicon shared by BEC, sextortion, and package-redelivery scams.

  • Urgency lexicon hits shared by the email and SMS pipelines
  • Legal-threat or law-enforcement mentions
  • Asks you to reply with a verification code or PIN

Payment redirection to wire or crypto

Pattern

Attorney invoices, vendor payment changes, and rental deposits increasingly ask for wire transfer or crypto wallet addresses instead of the established card-on-file. We flag the wording and pause the pattern.

  • Asks for payment to a new recipient (wire, gift card, crypto wallet)
  • Mentions an attachment or tap-to-view media carrying the redirect

Brand impersonation patterns

Pattern

Hosting a brand token as a subdomain on an unrelated registry is the canonical phishing shape — secure-paypal.example.com is not PayPal. We match the brand token against the registrable domain, never the path.

  • Brand name used as a subdomain of an unrelated registry
  • In-message link points at a brand-spoofing host
  • Display name mentions a brand the sender domain isn't

URL shorteners

Pattern

A shortened link hides the destination, so the URL pipeline can't fingerprint it before you click. We recognise the host and call it out — never resolve the redirect ourselves, so we can't be weaponised into a phishing payload either.

  • Known URL shortener used as a host in the URL pipeline
  • Shortener link embedded in an email or SMS body

Homoglyphs

Pattern

Punycode (xn--) hosts, mixed-script tokens, and digit-substituted brand names (paypa1, g00gle) are designed to slip past human eyes. We decode the IDN, compare against the brand list, and raise the signal you missed.

  • Punycode in the host IDN
  • Brand token with a digit replacing a letter (paypa1, g00gle)
  • Numeric label parked next to a brand token in the host

The 0–100 scale

Three bands, fixed cutoffs.

A higher score means fewer warning signs were matched — not“verified safe”. Veridex does not advertise an accuracy percentage.

Score rangeRisk labelVerdict phraseNext step
75–100Low Riskno major warning signs detectedStandard caution still advised — sign in only on sites you reached yourself.
40–74Medium Riskpotential warning signs detectedVerify the sender through a separate channel before clicking or signing in.
0–39High Riskpotential warning signs detectedDo not enter credentials, payment details, or one-time codes.

Recommended actions

Three next steps, keyed to your score band.

Each result surfaces exactly three concise next steps written for a non-technical reader. Actions are keyed to the band — they describe what to do with the message, not a claim about the target.

High Risk

Score 0–39

  • Avoid entering credentials, payment details, or verification codes.
  • Do not use contact information from the message — look up the brand independently.
  • Navigate to the brand yourself by typing the URL in a new tab.
Medium Risk

Score 40–74

  • Verify the sender through a separate channel — call the official number, not the one in the message.
  • Reply only via the original surface, not via a link or number given in the message.
  • Forward to the brand's published support address if you remain unsure.
Low Risk

Score 75–100

  • Treat the result as a starting-point check — not a green light.
  • Never paste a code back into the channel that asked for it.
  • Verify through a separate channel if anything about the message changes.

Limitations

What this score is, and isn’t.

Honest about what the score does not tell you.

  • Heuristic, not a guarantee. Veridex is an automated informational tool. Results may be inaccurate and provide no guarantee. Users must independently verify information before acting.
  • No accuracy percentage is advertised. A higher score means fewer red flags were matched — not “verified safe”. We never claim a thing is safe; we claim we did not see the usual scam signals.
  • Nothing auto-blocks. Veridex surfaces the score, the matched signals, and a concrete next step — the click is always yours.
  • A snapshot, not a label. Re-running the same input can produce a different score as the rule set evolves. The score reflects today’s rules, not a permanent verdict.
  • No inbox pipe, no live site crawl. The email checker reads only the headers you paste. There is no connection to your mailbox, and scoring is offline — DNS, heuristics, and brand lists.

Veridex provides automated AI-powered security assessments based on hundreds of technical and behavioral signals. Trust Scores are informational assessments and should not be interpreted as definitive factual statements. Users should independently verify important decisions before relying on any assessment.

Ready to check?

Get unlimited Trust Score checks.

Premium and Family plans unlock all five analyzers, unlimited checks, and advanced AI explanations.

View plans