FAQ

Frequently asked questions

How often does ScamWatch discover new sites?

The autonomous engine runs every 5 minutes, pulling from Certificate Transparency logs and multiple threat-intel feeds, then scanning up to 320 targets per cycle in parallel.

What does the risk score mean?

It is a heuristic 0–100 score based on typosquatting, form behavior, DNS/WHOIS signals, hosting reputation, redirect chains, and learned patterns. Higher = more likely malicious.

Do you actively attack scanned sites?

No. ScamWatch performs static fetching and public-record lookups only. It never executes exploits or bypasses authentication.

How do takedown reports work?

For high-risk sites the engine auto-drafts abuse reports for the registrar, hosting provider, Google Safe Browsing, and APWG using the collected evidence. Analysts can review and dispatch.

My legitimate site is listed by mistake — what do I do?

Email xapp431@gmail.com with the hostname. Verified appeals are removed promptly.

Is there a public API?

Yes. GET /api/public/v1/sites returns the flagged directory with full evidence. Rate limits and terms apply.

Which brands do you protect against impersonation?

The engine tracks 250+ named brands across payments, banking, big tech, retail, shipping, crypto, government and gaming — including regional targets in Latin America, Africa, the Middle East, the Nordics, Eastern Europe and APAC. The homepage lists them by sector.

How many hosting countries are covered?

Every scanned host is geolocated to an IP, ASN, ISP, city and country, so coverage follows the attackers — currently 60+ hosting countries appear in the directory, and the country list on the homepage is generated live from real detections.

How fast are new sites discovered?

A scheduled cycle runs every 5 minutes: it pulls six live URL feeds plus Certificate Transparency buckets, then scans hundreds of hosts in parallel. Freshly-issued certificates with suspicious keywords are often scanned within minutes of issuance.

More questions? Email xapp431@gmail.com.