Our checks look only at what anyone on the Internet can already see — which is exactly what an attacker looks at first. No account, nothing to install, and nothing is forced: the checks are non-intrusive.
The first links in the message are followed to their real destination. We look at how each link is built (shorteners, look-alike characters, misleading words), whether it imitates one of 47 brands — tax office, health insurance, banks, carriers, PayPal, Amazon, Microsoft… — how old the domain is, whether it is on a list of known malicious sites, and what the landing page asks for: a password, a card number, a recovery phrase.
For an email, we also read the sender checks recorded by the receiving server (SPF, DKIM, DMARC), a reply-to address that differs from the sender, and the attachments — never opened or run: disguised file names, programs hidden behind a document, macros, PDFs that launch actions.
The verdict has 4 levels (OK, suspicious, dangerous, very dangerous) and is set by the worst signal found. When a link really leads to the brand's official site, minor signals are ignored, to avoid false alarms.
About 138 checks (204 rules) in 19 categories measure whether the site and its email follow good practice and legal obligations: domain and DNS, email authentication and delivery, certificate and encryption, security headers and cookies, software past its end of support, hosting country and jurisdiction, legal notice, GDPR. 90 and above is solid; below 50 is very serious.
It starts at 100 and loses points for each abuse scenario we find — 15 in all, plus 3 complements: secrets left online (.env files, .git repositories, backups), a database open to the Internet, an abandoned subdomain that someone else could take over, a domain about to expire, exposed admin panels, outdated software, weak encryption, an open redirect… The higher the score, the better the site resists.
Estimated coverage: 60 to 80%. This is not a penetration test: no brute force, no exploit, no injection.
No password is ever tried and no attack is simulated. Old software is judged on the vendors' end-of-support dates. The deepest checks (more ports and sensitive paths) are run only once you have proven that you own the domain.
The report cites the French legal notice obligations (LCEN), the GDPR and the US CLOUD Act. Our checks also help you meet parts of GDPR article 32, the CNIL cookie recommendations, NIS2 article 21, the Gmail and Yahoo sender requirements and PCI DSS 4.0 — they help, they do not certify compliance.