Frequently asked questions
How often does ScamWatch discover new sites?
The autonomous engine runs every 5 minutes, pulling from Certificate Transparency logs and multiple threat-intel feeds, then scanning up to 320 targets per cycle in parallel.
What does the risk score mean?
It is a heuristic 0–100 score based on typosquatting, form behavior, DNS/WHOIS signals, hosting reputation, redirect chains, and learned patterns. Higher = more likely malicious.
Do you actively attack scanned sites?
No. ScamWatch performs static fetching and public-record lookups only. It never executes exploits or bypasses authentication.
How do takedown reports work?
For high-risk sites the engine auto-drafts abuse reports for the registrar, hosting provider, Google Safe Browsing, and APWG using the collected evidence. Analysts can review and dispatch.
My legitimate site is listed by mistake — what do I do?
Email xapp431@gmail.com with the hostname. Verified appeals are removed promptly.
Is there a public API?
Yes. GET /api/public/v1/sites returns the flagged directory with full evidence. Rate limits and terms apply.
More questions? Email xapp431@gmail.com.