How Scanning Works
The checks that run behind every scan and the data sources they use.
When you submit a URL, Snyfer runs a multi-stage pipeline. Some checks depend on page capture or external sources. A failed or unavailable check can leave gaps in the result.
The scan pipeline
- Reachability. Resolve DNS and confirm the site responds, with fallback to public resolvers when needed.
- Page capture. Render the page in a real browser, take a screenshot and capture the DOM, headers and network requests.
- Reputation checks. Query antivirus engines, Google Safe Browsing, Cloudflare phishing detection and community blocklists.
- Regulatory check. Match the domain against warning lists from financial regulators worldwide.
- Infrastructure. Collect WHOIS, SSL certificate, hosting, ASN and the technology stack.
- Scoring & summary. Combine every signal into the Trust Score and generate a plain-language summary.
Data sources
| Category | Source |
|---|---|
| Antivirus | engines via VirusTotal |
| Safe browsing | Google Safe Browsing, Cloudflare |
| Community feeds | MetaMask, ScamSniffer, Phishing.Database, Crypto Scam Intel |
| Regulators | Financial authorities (AMF, FCA, CNMV, CMVM, BCSC, ...) |
| Infrastructure | WHOIS / RDAP, SSL, IP geolocation, ASN |
Why results can change
A domain's score is a snapshot. Sites get re-listed, certificates expire and new warnings get published. Check the dates shown for each source. Requesting a new scan refreshes the analysis subject to queue capacity and source availability; opening an existing page does not guarantee a new scan.
The checks, applied
For these checks run against a live case, read how shared tracking identifiers connect a group of broker sites: it names every member domain, and every one of them can be put through the scanner.