Threat Categories
Every analysis is filed under one of these, and under the organisation it impersonates in the archive
How It Works
The full process, including what we never touch, is on the methodology page
We Receive the Email
Readers and our own inboxes supply the specimens. We keep the headers, the body and a screenshot exactly as received.
We Reproduce It in Full
The complete message is published verbatim, typos and all, with the recipient's details removed. Links and attachments are never opened.
We Dissect the Red Flags
Sender domain, reply-to, registry records, the claims in the text and the payload — each flag is tied to evidence in the message itself.
We Explain How It Plays Out
How the scam escalates if you reply, what to do now, and how to verify through a channel the attacker does not control.
Spotted Something Suspicious?
Help us protect the community. Report suspicious emails, messages, or scams — and we'll analyze and publish them to spread awareness.