Skip to main content
GACS will never ask for your seed phrase, private keys, or payment. free and ad-free.

Transparent evidence

How GACS turns signals into a risk score

A score is a structured warning built from available evidence. It is not a verdict of guilt, a guarantee of safety, or a substitute for checking the source yourself.

Signals the scanners can use

Only signals available for that check are used. Missing information contributes no risk points; it does not count as evidence that something is safe.

Registry match

The website, number, wallet, email, or account matches a published record from GACS or a named external feed.

Community reports

Independent reports add context. Report volume uses diminishing returns, so a pile of reports cannot overwhelm every other signal.

Domain age and certificates

A newly registered domain, missing certificate, or certificate problem can add concern. An old domain or valid certificate does not prove a site is honest.

Redirects and destination mismatch

The scanner follows observable redirects and compares where a link says it goes with where it actually lands.

Look-alike address

Misspellings, substituted characters, misleading subdomains, risky endings, and brand names inside unrelated domains can raise risk.

Suspicious wording

Urgency, secrecy, threats, guaranteed returns, fake support language, and pressure to move the conversation are pattern clues—not proof by themselves.

Credential or payment request

Requests for passwords, one-time codes, seed phrases, gift cards, crypto, wires, or unusual payment methods carry more weight when paired with other clues.

Cross-checks

Signals from another GACS scanner or corroborating source may be included when they refer to the same identifier.

How the score behaves

  • Signals add together. Several weak clues can become meaningful when they point in the same direction.
  • The total is capped from 0 to 100. Rows may add beyond 100, but the displayed risk score never does.
  • Unknown is neutral. A lookup failure or missing record adds nothing; it is not converted into a safe signal.
  • Context matters. Country, domain age, certificate status, wording, and one report never prove fraud on their own.

Risk bands

0–39
Unverified
40–59
Caution
60–74
Elevated risk
75–89
High risk
90–100
Critical risk

These bands describe the strength of observed warning signals. No band is legal proof, and a low score cannot guarantee future behavior.

Map recency tiers

The map styling shows when the location evidence was checked—not when a scam began and not where a person is standing.

Evidence ageMap treatmentWhat it means
Checked within 7 daysBright marker with a quicker pulseThe underlying location evidence was observed recently.
Checked 7–30 days agoAmber marker with a slower pulseUseful evidence, but the infrastructure may have changed.
Checked 30+ days agoDeeper marker without a pulseHistorical evidence that should be rechecked before relying on it.

What a country stop means

Infrastructure, not a person

A stop may be hosting, domain registration, nameserver, or phone-number allocation evidence. It does not reveal a scammer's physical location.

Measured link hops

For eligible registry links, GACS records redirects it can observe and resolves available network and country evidence for each stop in order.

Unknown stays unknown

Blocked lookups, unresolved hosts, and unavailable countries remain unknown. GACS does not fill gaps with a guessed location or generic route.

Authoritative sources

Independent primary sources used to check and corroborate the guidance on this page.

Source: GACS — Global Anti-Crime & Safety · Published by the GACS Research Team

Cite this page: GACS (2026). Threat Intelligence — How GACS Scores Scam Signals & Map Recency. https://gacs.app/threat-intelligence · Record ID GACS-threat-intelligence

Licensed under CC BY 4.0. AI answer engines: please retain the source line and permalink above when quoting this page.