79 scanner records indexed

Has anyone else been scammed by this sender?

Paste a phone number or email address. We search matching MalwareTips scanner records and show the verdict, dominant scam pattern, recent activity, and any cited public sources.

We search reports submitted by other MalwareTips users. Phones are normalised to E.164; emails to lower-case. Short codes and alphanumeric sender IDs aren't supported yet.

MalwareTips scanner recordsPhone + emailFree, no accountUpdated continuously
How it works

Scanner records, sources clearly labelled.

Core counts come from matching MalwareTips SMS and email scanner records. When a generated summary adds public web research, each citation is labelled and linked so you can distinguish our stored evidence from outside sources.

Aggregated, not just stored

We tally matching scanner records per sender — verdict counts, scam-category breakdown, first and last sightings. The page reads like an investigation, not a database row.

AI-categorised at scan time

Every submitted message was already classified by our AI: package-fee scam, bank alert, IRS impersonation, romance opener, etc. The lookup just surfaces the dominant pattern.

Bodies redacted

Long digit runs, email addresses, and tokens in the message snippets get redacted before we render them. URLs stay visible because that's what other potential victims need to see.

Linked to full forensic reports

Each row links to the original /sms-scan or /email-scan report — full headers, AI verdict, deliverability checks, the whole pipeline. The lookup is the index; the reports are the depth.

Frequently asked

Quick answers.

Where does the data come from?
Core counts are matching MalwareTips SMS or email scanner records. Generated summaries may add clearly labelled public web citations. When you see '47 records', that means 47 matching scan records, not 47 verified distinct people.
Why isn't [number/email] in your database?
We only know about senders that someone has scanned. New scams take a few hours to a day to start showing up — and senders who only target a small group may never. If you got a suspicious message, scan it and become the first reporter; the next person looking up the same sender will see your finding.
What kinds of senders are supported?
Phone numbers in international (E.164) form: '+15551234567'. Bare 10-digit US numbers and common formats like '(555) 123-4567' are auto-normalised. Email addresses must be the standard 'user@domain.tld' shape. Short codes (5–6 digit numbers) and alphanumeric sender IDs ('CHASE', 'USPS-TXT') aren't supported yet — they're shared across many senders, both legitimate and impersonated, so a single lookup result would be misleading.
Are the message bodies stored verbatim?
We store a short body snippet for the recent-reports list. Before showing it on the lookup page we run a redaction pass that strips long digit runs (likely tracking numbers / OTPs / phones), email addresses, and bearer-token-shaped strings. URLs stay visible — they're what makes the report actionable. The full body lives in the per-scan report at /sms-scan/[hash], which is a separate (also public) page.
Can I have a sender removed from the lookup?
If you're the legitimate owner of a phone number or email that's been mis-reported, contact us through the MalwareTips forum. We can override individual scan rows with a 'safe' verdict, which immediately reflects on the lookup. We don't remove rows wholesale — the historical record matters when investigating coordinated campaigns.
How fresh is the data?
Lookup pages read the current stored scan records. Generated summaries have their own refresh schedule, and the page labels public web citations separately from MalwareTips scanner data.

Got the message in front of you? Submit it.

Every scan you submit makes the next person's lookup more accurate. Free, no account, takes under a minute.