FAQ

Frequently asked questions

How often does ScamWatch discover new sites?

The autonomous engine runs every 5 minutes, pulling from Certificate Transparency logs and multiple threat-intel feeds, then scanning up to 320 targets per cycle in parallel.

What does the risk score mean?

It is a heuristic 0–100 score based on typosquatting, form behavior, DNS/WHOIS signals, hosting reputation, redirect chains, and learned patterns. Higher = more likely malicious.

Do you actively attack scanned sites?

No. ScamWatch performs static fetching and public-record lookups only. It never executes exploits or bypasses authentication.

How do takedown reports work?

For high-risk sites the engine auto-drafts abuse reports for the registrar, hosting provider, Google Safe Browsing, and APWG using the collected evidence. Analysts can review and dispatch.

My legitimate site is listed by mistake — what do I do?

Email xapp431@gmail.com with the hostname. Verified appeals are removed promptly.

Is there a public API?

Yes. GET /api/public/v1/sites returns the flagged directory with full evidence. Rate limits and terms apply.

More questions? Email xapp431@gmail.com.