About this tool
Review SMS, WhatsApp, and email text locally for common scam warning patterns and get safer next steps without sending the message anywhere.
Scam Message Triage is a local checklist that scans the text of an SMS, WhatsApp message or email against ten deterministic scam-pattern rules — urgency, hard-to-reverse payment, OTP and PIN requests, remote-access instructions, authority and relationship claims — plus structural checks on any links and hidden Unicode characters. It returns a 0-100 signal score, the exact phrases that matched, and a list of safer next steps tailored to what it found. The message never leaves the page, which matters because the thing you want checked usually contains your own name, account details or a link you were told to open.
Open Scam Message Triage on AltFTool — it loads instantly in your browser.
Under "Paste the message", choose the Message source — SMS, WhatsApp or Email — and paste the text into the "Message text" box, which accepts up to 20,000 characters.
Press "Review message" (or "Load example" first); the pattern rules, link inspection and Unicode checks all run in the page, and "Clear" empties the box.
Read the "Signal score" out of 100 next to the "Evidence groups" and "Links found" counts, check the "Observed evidence" cards quoting each matched phrase, then take the "Safer next steps" list with "Copy checklist".
Each finding quotes the matched phrase with surrounding context, so you can see why it fired and judge it yourself.
It flags punycode labels, numeric-IP hosts, userinfo before the host, and words mixing Latin with Cyrillic or Greek that render identically on screen.
Credential and personal-data rules check the preceding 16 characters for negation, so a genuine bank notice saying 'never share your OTP' is not scored against you.
It is the summed weight of the patterns that matched, capped at 100 — not a probability that the message is a scam. Below 25 is flagged as a few caution signals, 25 to 54 as several, and 55 or above as multiple strong signals; combinations add extra weight, such as +10 when a credential request appears alongside a link.
No. The rules, URL inspection and Unicode checks all run in the page on your device, and nothing is transmitted or stored on a server. That is deliberate, since the messages people most want checked are the ones containing their own account numbers and personal details.
No, and the tool says so explicitly. It matches a fixed list of known warning patterns, so a well-written scam using none of those phrases will score zero. Treat a clean result as 'nothing obvious found', and still verify any request for money or credentials through a number or app you sourced yourself.
Contact your bank or the relevant provider immediately through their official app or a number you already had, not one from the message, and change any password or PIN you disclosed. Speed matters most with hard-to-reverse methods such as gift cards, crypto and wire transfers, and reporting to your national cybercrime or fraud line is the next step.