Transparent evidence
How GACS turns signals into a risk score
A score is a structured warning built from available evidence. It is not a verdict of guilt, a guarantee of safety, or a substitute for checking the source yourself.
Signals the scanners can use
Only signals available for that check are used. Missing information contributes no risk points; it does not count as evidence that something is safe.
Registry match
The website, number, wallet, email, or account matches a published record from GACS or a named external feed.
Community reports
Independent reports add context. Report volume uses diminishing returns, so a pile of reports cannot overwhelm every other signal.
Domain age and certificates
A newly registered domain, missing certificate, or certificate problem can add concern. An old domain or valid certificate does not prove a site is honest.
Redirects and destination mismatch
The scanner follows observable redirects and compares where a link says it goes with where it actually lands.
Look-alike address
Misspellings, substituted characters, misleading subdomains, risky endings, and brand names inside unrelated domains can raise risk.
Suspicious wording
Urgency, secrecy, threats, guaranteed returns, fake support language, and pressure to move the conversation are pattern clues—not proof by themselves.
Credential or payment request
Requests for passwords, one-time codes, seed phrases, gift cards, crypto, wires, or unusual payment methods carry more weight when paired with other clues.
Cross-checks
Signals from another GACS scanner or corroborating source may be included when they refer to the same identifier.
How the score behaves
- Signals add together. Several weak clues can become meaningful when they point in the same direction.
- The total is capped from 0 to 100. Rows may add beyond 100, but the displayed risk score never does.
- Unknown is neutral. A lookup failure or missing record adds nothing; it is not converted into a safe signal.
- Context matters. Country, domain age, certificate status, wording, and one report never prove fraud on their own.
Risk bands
- 0–39
- Unverified
- 40–59
- Caution
- 60–74
- Elevated risk
- 75–89
- High risk
- 90–100
- Critical risk
These bands describe the strength of observed warning signals. No band is legal proof, and a low score cannot guarantee future behavior.
Map recency tiers
The map styling shows when the location evidence was checked—not when a scam began and not where a person is standing.
| Evidence age | Map treatment | What it means |
|---|---|---|
| Checked within 7 days | Bright marker with a quicker pulse | The underlying location evidence was observed recently. |
| Checked 7–30 days ago | Amber marker with a slower pulse | Useful evidence, but the infrastructure may have changed. |
| Checked 30+ days ago | Deeper marker without a pulse | Historical evidence that should be rechecked before relying on it. |
What a country stop means
Infrastructure, not a person
A stop may be hosting, domain registration, nameserver, or phone-number allocation evidence. It does not reveal a scammer's physical location.
Measured link hops
For eligible registry links, GACS records redirects it can observe and resolves available network and country evidence for each stop in order.
Unknown stays unknown
Blocked lookups, unresolved hosts, and unavailable countries remain unknown. GACS does not fill gaps with a guessed location or generic route.
