Methodology

How TapSafely checks a message, and how our numbers are made

What happens when you press Check, how the score is worked out, where the AI fits in, and how the Scam Index and our other data are produced. Written so you can judge how far to trust each part.

1. The check, step by step

  1. Pattern rules. The text is tested against dozens of warning signs taken from real scams and official advice: pressure and deadlines, requests for codes or passwords, unusual ways to pay (gift cards, crypto, transfers to a "safe account"), prizes, threats, and pretending to be a bank, a courier, a government office or a relative. Each rule has a weight for how strongly it predicts a scam on its own. The quick version of these rules runs in your browser, so a result appears in about a second.
  2. Link checks. Every link in the message, up to three, is examined on our server without opening it on your device: the real domain behind it, look-alike spellings of well-known brands, how long ago the domain was registered (from the public RDAP registry), where it redirects, and what the landing page asks for. Where available, we also ask Google Web Risk whether the address is a known threat.
  3. AI review. A language model reads the message for newer tricks the rules might miss, and suggests a scam type. It is instructed never to call anything safe. For screenshots, the AI first reads the text in the image, and the same rules and link checks then run on that text.
  4. Score and level. The rule weights are added up and turned into a score from 0 to 100 that rises quickly with the first strong signs and levels off as more are added. When the AI review runs, its score is blended with the rules' (55% AI, 45% rules), but the result can never fall below 90% of the rules' own score: a strong, known pattern is not talked down.
ScoreLevelWhat it means
70 to 100High riskStrong signs of a scam.
40 to 69SuspiciousSeveral warning signs. Treat it as a scam until proven otherwise.
15 to 39Some warning signsA few things look off. Check through an official channel before acting.
0 to 14No common scam signs foundThat does not prove it is safe.

2. What the checker can't do

  • It can't see who really sent a message, or confirm a phone number's owner. Caller ID and sender names are easy to fake.
  • It can't catch a scam that looks exactly like a normal message until the ask arrives. The request for money, codes or details is what matters most.
  • A brand-new domain is a warning sign, not proof. Real businesses launch new sites too.
  • It is not legal, financial or police advice. If money has gone, call your bank first, then the official reporting service in your country.

3. What we keep

We don't store the messages, links or screenshots you check. For each check we keep one anonymous row: the day, the country (from the connection, never more precise), the kind of check, the scam type, the risk level and the score. Rows are deleted after 180 days. The full details are in our privacy notice.

4. How the Scam Index is made

The Scam Index and Scam Weather are built only from those anonymous rows.

  • Checks is every check run in the week (Monday to Sunday, UTC). Flagged is the checks rated High risk or Suspicious.
  • Share is a scam type's part of the flagged checks that week, as a percentage.
  • We withhold any count below 10, and report a week with fewer than 50 checks as "not enough data". The current week is marked as partial.
  • It shows what people bring to TapSafely, not how common each scam is in the population. People check what worries them, so a scam that makes headlines can show a rise in checks before it rises in losses. Read it next to the official statistics.

5. The reporting directory and the statistics

Every reporting route was opened and checked against an official government, police, regulator or network-operator page on 2026-09-16. Every statistic comes from the publisher's own report, is quoted as published and carries its date and link. We don't cite other scam-advice websites. We review both every few months, and whenever a reader tells us something has changed. See our editorial policy.

6. Checking ourselves

Every result asks "Did we get this right?", and the answers are counted by scam type. Corrections sent to hello@tapsafely.com are read by a person. When a rule keeps misjudging a kind of message, we change the rule and record the engine version, which every API response includes.

Questions

Can a low score prove a message is safe?

No. A low score means we didn't find the patterns we know about. New scams appear every week, so we never describe anything as safe.

Do you train AI on what people check?

No. The messages, links and screenshots people check are not stored and are not used to train any model.

Can a company pay to change a verdict?

No. Nobody can pay to be rated safe or to have a competitor flagged. Advertising and affiliate partners have no access to the checker.

How do you know when you get it wrong?

Every result asks "Did we get this right?". We count the answers by scam type, read every correction sent by email, and adjust the rules when a pattern keeps being misjudged.