About & privacy
What we store, and what we never store
Detection here is hardcoded pattern logic — no machine learning, no external analysis services, nothing sent off-device for scoring.
Never stored
The message you paste
Analysed in memory and discarded. It isn't written to a database, sent to a third party, or used to train anything — screenshots and .eml files included, and QR decoding happens entirely on your device.
Never opened
The links inside it
We read the URL as text. We don't visit it, so the sender never learns you checked and no tracking pixel fires. Our security policy blocks the browser from contacting any outside server at all.
Stored, scrubbed
Reports you choose to submit
Only if you submit the report form — and personal details are removed before storage, not before display. What's kept is the scam: the link, the sender, the wording.
Counted only
How many checks ran
A running total with no content attached. That's what the numbers on the reports page come from.
What this is
Veriguard is a free scam checker built for Australians, with local coverage for the UK, US, New Zealand and Ireland as well. Paste a suspicious link, text, email or phone number and get an instant best-effort verdict — no account, no tracking, no data sold. It's an independent project by Aleks Linde (opens in a new tab), not a government service.
It gives a best-effort check only — it can't guarantee it catches every scam. For official reporting, use Scamwatch (scamwatch.gov.au) and ReportCyber (cyber.gov.au/report).
Where we work
Anyone, anywhere can paste a message here. The universal checks — links, shorteners, redirects, tracking, and requests for personal details — run the same way everywhere, because those tricks don't respect borders.
What varies is local knowledge: the brands scammers impersonate, the tax deadlines they exploit, the phone-number formats that signal a fake. We cover Australia, the UK, the US, New Zealand and Ireland in full, Canada in part, and fall back to country-neutral checks everywhere else.
To pick the right set we use a two-letter country code, and nothing finer — derived from your connection by the network, never read from your IP address by us, and not stored when you run a check. If it guesses wrong, because you're travelling or on a VPN, you can change the region yourself and check again.
Outside the countries we cover properly, “nothing found” can just mean “we have no local rules to find it with”. You'll see a note saying so — treat a quiet result as “not checked”, not “safe”.
Threat radar & scam calendar
The threat radar lists campaigns doing the rounds in the last few weeks, and the scam calendar shows when scams spike through the year — tax time, Black Friday, the Christmas parcel rush. Both are hand-written from published threat intelligence and read nothing about you; they're the same pages for everyone in your country.
Both are there to teach, and neither changes a verdict. The date is never part of the score: a tax scam in March is still a scam, and a genuine ATO email in July is still genuine. The radar also says plainly which campaigns we catch and which we don't yet.
When you report a scam
A report stores exactly these things, and nothing else:
- The scam content and identifiers you submit — with tracking parameters stripped, your own email headers removed, and personal details (emails, phone numbers, tax file numbers and the like) automatically scrubbed before storage. Everything shown publicly is also “defanged” so it can't be clicked or dialled by accident.
- A coarse location, never your IP address. At submission time we derive a region from the connection — state level for Australia (e.g. “NSW, Australia”), country level elsewhere — and store only that string. It's shown on the public report so people can see where a scam is circulating. Your IP is used in memory for rate limiting while the request is processed and is never stored by the application; city-level detail is deliberately not used.
- Your email, only if you choose to give it. It's used solely to follow up on your report. It is never published, never shared with anyone, and never used for anything else.
Public reports are community-submitted and unverified. Want one removed or have a question about your data? Use the “Report a bug” button (bottom-right) with your report reference and your email — we'll sort it out.
Why the rules are public
Detection logic is intentionally open source. Transparency lets the community improve it, and obscuring keyword lists wouldn't stop sophisticated scammers — it would only stop you from checking our work.
Bug reports & tracking
A wrong verdict is a bug worth knowing about, in either direction. If something breaks we may offer to send diagnostics, but nothing is ever sent without your explicit consent — you see the exact details (page, browser, error message) before deciding. The scam content you pasted and any files you uploaded are never included.
No analytics scripts, no advertising pixels, no cookies for tracking. Your language preference and view settings live in your own browser's storage and never leave it. The site's security policy prevents pages from talking to any third-party server at all.
Blocking & reporting spam
Step-by-step guides for blocking and reporting spam — in Gmail, Outlook, Apple Mail and Yahoo, and on iPhone, Android and messaging apps — live on the Learn page.