What Your Cautellus Risk Score Actually Means
Free: How to Keep Yourself Safe From Scammers
9 chapters. Reporting checklist. 30-second protection checklist. Read on the site.
What Your Cautellus Risk Score Actually Means
You paste a text into the scanner because something about it felt off. Two seconds later, a number comes back — say, 22 — under a word that reads "safe." Relief, then a shrug. Okay. So it's fine.
Except "safe" is doing more work in that sentence than it should, and I'd rather you know exactly what it's carrying before you act on it. A risk score is a read on a message against everything Cautellus currently knows. It is not a background check on the human who sent it. Those are different questions, and mixing them up is exactly the gap I want to close here.
The three bands, and what each one is actually checking
Every scan runs the same three-part read: does this match something already reported as a scam, does the link resemble a real brand's domain closely enough to be a typosquat, and does the language itself lean on urgency, authority, or emotional pressure the way scams reliably do. That's threat-database matching, typosquat detection, and behavioral pattern analysis, stacked together into one number from 0 to 100.
Under 30 — "Looks safe." Nothing in the message or link tripped a known bad signal. No match against the confirmed-scam record, no typosquat pattern, no stacked manipulation language.
30 to the high 50s — "Suspicious." Mixed signals. Something's off enough to flag, not clean enough to wave through. This is the band that actually needs you to read why, not just the color.
60 and up — "High risk." A strong signal fired — a direct match against something already reported, a close typosquat of a real brand's domain, or language stacked with the pressure tactics scams reliably use.
The database behind that first check is Cautellus's own: over 10,000 confirmed scam entities pulled from six Reddit scam-tracking communities, FBI IC3, FTC alerts, and three global phishing databases tracking 770,000+ known-malicious domains, refreshed every six hours. The typosquat check runs against 25+ major brand domains. None of that is a model guessing at vibes — it's a lookup against a record that gets updated constantly, layered with pattern analysis built to catch manipulation regardless of how clean the grammar is, which matters now that most phishing reads perfectly.
Not sure if your message is real? Paste it into Cautellus and get a risk score before you reply.
Scan it free →Or: Get the Chrome extension to scan pages without leaving your browser.
What "safe" doesn't mean
This is the part that actually matters, so I'll say it plainly: a safe score means nothing tripped a known bad signal yet. It does not mean the person texting you is who they say they are.
Say a number you don't recognize texts you asking for a code, or a "landlord" you've never met sends a payment link. If nothing in the message matches a reported pattern — no flagged domain, no known scam infrastructure, no textbook pressure language — it can come back safe. That's an accurate read of the record. It is not proof the stranger on the other end is trustworthy. Brand-new scam infrastructure that hasn't been reported yet, or a scam running through channels nothing tracks (a request made entirely by voice, for instance, with no link or domain to check at all) can both clear a scan and still be exactly what you were worried about.
So the actual rule: a safe score lowers your risk on the artifact — the link, the text, the message itself. It doesn't replace verifying the person, especially the moment money, a password, or a one-time code enters the conversation. For anything involving a family member's voice specifically, a pre-agreed safe word does a job the scanner structurally can't — it checks identity, not content, and no AI voice clone can guess a phrase your family invented.
What "suspicious" is actually telling you
A suspicious score isn't a maybe. It's a specific claim: something concrete about this message resembles patterns that show up in real scams, but not enough of them stacked together to call it confirmed. Maybe the domain is close to a real brand's without being an exact typosquat match. Maybe the language leans on urgency without any of the other usual tells. Maybe it's a legitimate business that just writes sloppy, high-pressure marketing copy — that happens more than you'd think.
The number alone won't tell you which. The flags underneath it will — each scan returns the specific reasons behind the score, not just the color. Read those before you decide what to do next. A suspicious score on a message asking you to click something is a different situation than a suspicious score on an email that's just badly written.
What "high risk" means — and what it doesn't guarantee
A score in the 60s or above means a real signal fired: a direct hit against something already reported, a domain built to look like a bank's or retailer's, or language stacked with the kind of pressure tactics that show up over and over in how these detection systems actually work. Treat it as exactly that — a strong, specific reason to stop.
What it isn't is a guarantee, in either direction. No scanner, Cautellus included, catches every scam or is right every time. That's not a hedge — it's the honest shape of what pattern-matching against a threat record can and can't promise. The record only knows what's been reported. Something can score high risk and turn out to be a false alarm on a legitimate but poorly-run business. Both directions of error are possible, which is exactly why the score is a strong second opinion and not the whole decision.
Why the number isn't the verdict
Every band is answering the same underlying question: does this match something already known to be bad? None of them are answering "is this specific person telling me the truth," because that's not a question a pattern-matching system can settle from a screenshot. The honest version of a scam checker says that part out loud instead of implying more certainty than it has — I'd rather you trust the tool because it told you its limits than because it oversold itself.
How to actually use the score
Read the flags, not just the color — the reasons behind a suspicious or high-risk result usually tell you more than the number does. Treat a safe score as "nothing known-bad here," not as identity confirmation, especially once money or a code is involved. And if a request is coming by voice — a call that sounds like your kid, your bank, your boss — a scanner isn't even the right tool; that's what a callback to a number you already have is for. Scan the actual message text when you have it, not just a bare link — the behavioral signals live in the words, and stripping them out for just the URL throws away half of what the check is looking at.
If you want to try it on something sitting in your messages right now, Cautellus's scanner runs that same three-part check — threat-database match, typosquat detection, behavioral analysis — on a text, link, email, or screenshot. The first scan's free, once every 30 days, no card needed.
Got something like this in your inbox? Drop it into the scanner — it takes 5 seconds and could save you thousands.
Check it now →Already been scammed? See where and how to report it.
FAQ
Does a "safe" score mean the message is 100% legitimate? No. It means nothing in the message matched a known bad pattern at scan time. That's a real, useful signal — it's just not the same as confirming who sent it or that they're telling the truth.
Why did I get "suspicious" instead of a clear yes or no? Because the message had some, but not all, of the traits that show up in confirmed scams — a near-match domain, or urgent language without a database hit, for example. Suspicious means "read the specific flags," not "wait for a cleaner answer."
Can the score be wrong? Yes, in both directions. A score reflects what's currently known and reported — it can miss something brand new that hasn't been flagged yet, and it can flag something legitimate that happens to share surface traits with scam patterns. Treat it as a strong second opinion, not a final ruling.
Is the score just an AI model guessing? No — the language-pattern piece is one layer of three. The score also checks the message against a database of 10,000+ confirmed scam reports and runs a typosquat check against major brand domains. Those are lookups against records, not guesses about tone.
If something scores "high risk," do I still need to verify separately? For anything with money, a password, or a one-time code attached — yes. A high-risk score is a strong reason to stop, but the follow-up move is still a callback through a number or channel you already trust, not the one in the message.
How often does the data behind the score update? Every six hours. Scam infrastructure moves fast — domains spin up and get abandoned within days — so a score from this morning can be more current than one from yesterday afternoon.
The score isn't there to make the decision for you. It's there so you're not making it blind.
Think you've been targeted? Paste any text, link, email, or screenshot into Cautellus for instant AI analysis.
Scan something free →Want unlimited scans + the Chrome extension? See pricing.
Courtney
Founder, Cautellus · 20+ years in financial services
Two decades in financial compliance, digital security, and fraud prevention. Built Cautellus because the scam detection tools that exist were made for IT departments, not for real people getting weird texts.
Learn moreKeep reading
Support Our Mission
Cautellus is built to protect people from online fraud. Your contribution helps us keep building security tools and resources.