SMS, email and phishing scam detector — check if a message is fraud

Active forensic engine · +40 signals

Received a suspicious message?

Paste text on the left. ORTSLAB analyzes origin, links, sender identity, and fraud patterns — in seconds.

👤
Citizens

SMS from bank, Post office or DGT. Know in 10 seconds if it's a scam.

⚖️
Lawyers & experts

Downloadable expert report with technical evidence and forensic scoring.

🏢
Companies

Targeted phishing, vendor domains, corporate impersonation.

SPF / DKIM / DMARC Covert redirects SMS Aliases VirusTotal API Domain age Unicode Homoglyphs Forensic PDF QR Quishing Expert report
FREE · NO REGISTRATION · NO STORAGE

Detect if an SMS, email or WhatsApp is a scam — results in seconds

ORTSLAB is a forensic message analysis engine developed by a certified judicial IT expert. Paste any suspicious SMS, email or WhatsApp message and the engine analyzes over 40 fraud signals: the real sender origin, hidden links, domain authenticity and language patterns used by scammers. No registration, no data storage, nothing to install.

What is this phishing and SMS scam detector for?

Every day millions of people receive fraudulent messages impersonating their bank, a delivery company, a government agency or services like Netflix or Amazon. These messages — known as phishing (by email) or smishing (by SMS) — trick you into clicking a fake link or providing your personal and banking details.

ORTSLAB analyzes the message in real time and accurately determines whether it is legitimate or a scam, explaining exactly which signals were detected. If the result confirms fraud, you can download a forensic report in PDF format valid for presenting to authorities or in legal proceedings.

Most common SMS and email scams

  • Fake bank SMS — Barclays, HSBC, Santander — warning of a suspicious charge or account block.
  • Parcel delivery email from Royal Mail, FedEx or UPS with a package on hold requiring customs payment.
  • Tax agency email promising a refund or threatening an audit.
  • Amazon or Netflix message asking you to update your payment method.
  • WhatsApp from a family member from an unknown number asking for urgent money.
  • Job offers or prize notifications asking for personal details or an upfront payment.
  • PDF invoices or attachments containing malicious code that activates when opened.
  • QR codes in physical or digital messages redirecting to fraudulent sites.

How does the forensic message analysis work?

The ORTSLAB forensic engine verifies in real time the sender's authenticity (SPF, DKIM, DMARC), checks whether links redirect to fraudulent domains, queries the domain reputation in international threat databases (VirusTotal) and analyzes domain age via RDAP. It also detects advanced evasion techniques such as Unicode homoglyphs, recently registered domains and malicious QR codes.

The result includes a forensic score, a clear verdict (from Trusted to Danger) and a detailed list of evidence found. Professionals can export the report in PDF forensic format.

What should I do if the message is confirmed as a scam?

Do not reply, do not click any links and do not call any number in the message. If you have already provided banking details, contact your bank immediately to block any potential charges.

If you need to document the fraud for a formal complaint or legal proceedings, request a signed forensic report from Oscar Orts, certified judicial IT expert.

ORTSLAB Technical Observatory

The green padlock means nothing: how to spot scam websites your browser says are safe
Article
The green padlock means nothing: how to spot scam websites your browser says are safe

The padlock is there. The connection is secure. The browser shows no warnings. And yet, the website in front of you is a...

29/08/2026Read →
Email forensic analysis: what it is, when you need it and what the expert report includes
Article
Email forensic analysis: what it is, when you need it and what the expert report includes

You receive an email that appears to come from a supplier, a partner or someone inside your company. They ask you to mak...

27/08/2026Read →
Quishing: how QR code phishing bypasses corporate security filters
Article
Quishing: how QR code phishing bypasses corporate security filters

The email looks legitimate. The logo is correct, the tone is familiar, and the subject line says you need to verify acce...

23/08/2026Read →
SpyNote and WindRelay: two malware tools that drain your bank account in 13 minutes from a phone call
Article
SpyNote and WindRelay: two malware tools that drain your bank account in 13 minutes from a phone call

The phone rings. Someone claims to be from your bank and warns you of a problem with your card. They ask you to install ...

15/08/2026Read →
Why AI has made phishing blocklists obsolete
Article
Why AI has made phishing blocklists obsolete

For years, the standard response to phishing was always the same: detect the malicious domain, add it to a blocklist, an...

08/08/2026Read →
STAC4749: fake IT support calls on Teams that end in ransomware in under 17 hours
Article
STAC4749: fake IT support calls on Teams that end in ransomware in under 17 hours

The phone rings inside Microsoft Teams. The screen shows the name of someone from the IT support team. A calm voice expl...

01/08/2026Read →
FakeAgent: a fake Claude app on Bing installs the SectopRAT trojan
Article
FakeAgent: a fake Claude app on Bing installs the SectopRAT trojan

You search for "Claude" on Bing. The first result is a sponsored ad that takes you directly to a page hosted on Claude's...

24/07/2026Read →
BoryptGrab: 292 fake GitHub repositories distribute malware stealing passwords and crypto wallets
Article
BoryptGrab: 292 fake GitHub repositories distribute malware stealing passwords and crypto wallets

You search for a security tool, a Mac utility, an encrypted email client or some cryptocurrency software. You find a Git...

18/07/2026Read →
Forg365: when phishing becomes a monthly subscription
Article
Forg365: when phishing becomes a monthly subscription

Forg365: when phishing becomes a monthly subscription On 18 June we published an analysis of EvilTokens: the techniqu...

11/07/2026Read →
Five things a forensic expert checks before opening the email
Article
Five things a forensic expert checks before opening the email

Five things a forensic expert checks before opening the email There is a tool I used every day that at some point sto...

10/07/2026Read →
The smishing that needs no link: when fraud asks you to reply
Article
The smishing that needs no link: when fraud asks you to reply

The smishing that needs no link: when fraud asks you to reply For years, the advice has been the same: don't click th...

03/07/2026Read →
Bank text with no link: how to spot the fraud that asks you to reply CANCEL
Article
Bank text with no link: how to spot the fraud that asks you to reply CANCEL

A text message arrives from your bank. It alerts you to a purchase you don't recognise — a specific amount, a named shop...

29/06/2026Read →
No articles found for this search.

Threat Observatory

Aggregated real-time data · 1,683 analyses
Total analyses
1,683
accumulated
Threats
55%
suspicious + danger
Origin countries
24
distinct detected
Unique domains
245
analyzed
Verdicts
Institutional Whitelist Proximity Commercial Trusted Neutral Threat
Weekly evolution
Threats Safe
Top countries
US USA
850
XX XX
154
ES Spain
149
GB United Kingdom
141
CA Canadá
81
DE Germany
67
Fraudulent domains detected
--- 68×
eu.org 34×
lifelovelupus.com 21×
menssupplementfactor.com 19×
educaweb.info 16×
notaria.org 14×
arcadejackpot.pt 13×
ricosnaamerica.com 13×
Most frequent TLDs in threats
.com
570
.---
68
.org
59
.br
45
.net
30
.info
24
Aggregated and anonymized data · Partial IPs · Real-time updates
Threat types detected
Distribution by type(123 records)
Phishing 100%
Input channel
Email
94%
SMS
6%
Weekly evolution by type
Phishing

🚨 Scams detected

Fraudulent domains identified by the ORTSLAB engine. If you have received a message from any of them, it is a confirmed scam — analyse it here.

0
week
119
total
Dominio Tipo Veredicto País Última
eu.org Phishing PELIGRO USEE.UU. 01/08/2026 34×
educaweb.info Phishing PELIGRO GBReino Unido 01/08/2026 21×
menssupplementfactor.com Phishing PELIGRO FRFrancia 09/08/2026 19×
notaria.org Phishing PELIGRO ESEspaña 29/07/2026 14×
arcadejackpot.pt Phishing PELIGRO USEE.UU. 08/08/2026 13×
heveanhouserestrobar.com Phishing PELIGRO USEE.UU. 01/08/2026 13×
ricosnaamerica.com Phishing PELIGRO USEE.UU. 01/08/2026 13×
antato.com Phishing PELIGRO USEE.UU. 08/08/2026 12×
oqtide.com Phishing PELIGRO USEE.UU. 08/08/2026 12×
web.id Phishing PELIGRO USEE.UU. 01/08/2026 12×
receptif-24-heures.com Phishing PELIGRO USEE.UU. 01/08/2026 12×
cantorea.com Phishing PELIGRO USEE.UU. 01/08/2026 12×
movendoseaoexito.com.br Phishing PELIGRO USEE.UU. 08/08/2026 11×
hifiprofileuk.com Phishing PELIGRO USEE.UU. 01/08/2026 10×
mcdlv.net Phishing PELIGRO USEE.UU. 08/08/2026 10×
gohitpublicschool.com Phishing PELIGRO USEE.UU. 01/08/2026 10×
onlinepharmas.com Phishing PELIGRO USEE.UU. 01/08/2026 10×
unknownscripts.com.br Phishing PELIGRO USEE.UU. 01/08/2026 10×
droodlefy.com Phishing PELIGRO DEAlemania 01/08/2026
biz.ua Phishing PELIGRO NLPaíses Bajos 21/08/2026
antesadms.space Phishing PELIGRO AUAustralia 01/08/2026
pp.ua Phishing PELIGRO EEEstonia 01/08/2026
oftopsurvey.com Phishing PELIGRO NLPaíses Bajos 01/08/2026
sahabat303login.my Phishing PELIGRO USEE.UU. 01/08/2026
decryptedlabshub.com Phishing PELIGRO USEE.UU. 01/08/2026

25 active campaigns · last 90 days · ORTSLAB v10.9

📡 The green padlock means nothing: how to spot scam websites your browser says are safe

Need help or have a question?

🛡️ Análisis gratuito · inmediato

Para saber si un SMS, correo o WhatsApp es una estafa. Usa el Scanner — resultado en segundos, sin registro, sin coste.

⚖️ Informe pericial oficial

Para denuncias ante la Policía, procedimientos judiciales o reclamaciones bancarias. Informe firmado por perito informático judicial colegiado, con validez probatoria ante tribunales.

  • Análisis forense de correos, SMS y dispositivos
  • Fraude bancario y suplantación de identidad
  • Estafas en compraventa online
  • Acoso digital y delitos informáticos
Solicitar peritaje → orts.cat

Oscar Orts · Perito Informático Judicial · Colegiado · Barcelona

Submit inquiry

¿Tienes dudas sobre un caso concreto o necesitas orientación antes de solicitar un peritaje? Escríbenos.

Sobre el proyecto

ORTSLAB es una herramienta pública y gratuita de análisis forense de mensajes digitales, desarrollada por Oscar Orts, perito informático judicial colegiado, con base en Santa Bàrbara (Tarragona).

El proyecto nace con una motivación clara: prevenir que ciudadanos caigan en ciberestafas. El motor analiza más de 40 señales de fraude en tiempo real, especializado en los patrones lingüísticos y técnicas de ingeniería social del mercado hispanohablante.

Sin registro. Sin almacenamiento de mensajes. Sin publicidad.

📍 Santa Bàrbara · Terres de l'Ebre ⚖️ Perito Judicial Colegiado 🛡️ Motor v11.0 🌍 Mercado hispanohablante
Detector de amenazas activo
Phishing / Smishing✓ Activo
BEC / CEO Fraud✓ Activo
Quishing (QR)✓ Activo
PDF malicioso✓ Activo
Recovery Fraud✓ Activo