How Hunch checks a message

How Hunch checks a message

Hunch reads the words of a message and flags the patterns scammers reuse, a look-alike domain, a password or payment ask, manufactured urgency. It is a signal, not a verdict on a person.

It runs on your device

The checker analyzes your message right here in the browser, the same detection engine that ships inside the Hunch extension. Detection runs 100% locally on your device, which is also why it works for a text on your phone.

Signals, not accusations

When Hunch names a brand, it is describing scammers who impersonate that brand, never the real company. A verdict is an automated risk signal to help you slow down and verify, not proof of fraud or legal advice.

What it catches well

Look-alike and unexpected domains, credential and payment asks, high-pressure deadlines, fake-recruiter templates, and common impersonation of banks, tax authorities, delivery and big tech brands, across English, Hebrew, Spanish and Portuguese.

What it can miss

A brand-new scam with no known pattern, a screenshot with little text, or a highly personal message can score low. No warning is not a guarantee a message is safe, when a request is unexpected, verify it through a channel you already trust.

Two tiers: a red “Scam” reads high confidence (a fake domain with pressure and an ask, or a known impersonation); an amber “Suspicious” means worth a closer look. A message a friend could plausibly have sent stays amber on purpose.