Messages and email
The engine looks for sender and reply address differences, misleading links, executable attachment names, changed payment instructions, credential requests and pressure to act. Exported authentication headers are displayed with an unverified status. A trusted receiving mail system is needed to validate those results.
Domains and websites
DNS and available registry data provide technical context. Standalone URL checks inspect a bounded response and redirects through a restricted worker. Private and reserved network addresses are blocked. A website responding successfully does not establish that its operator is trustworthy.
Files and images
Supported uploads receive a SHA256 fingerprint and a local malware signature scan. Text is extracted from supported documents. The image reader can extract text and decode QR content. Extraction can miss information or misread characters, so the result lets you review the text.
Assessments
High risk and Concerning identify warning signals requiring attention. No clear threat found means the completed checks found no strong signal in the available content. Unable to assess means the input did not provide enough usable information. None of these labels certifies a person, business or payment.
Data coverage
The report lists completed, unavailable and unverified checks. No external commercial threat reputation feed is connected. Owner reviewed warnings can contribute a finding and expire after 30 days. New threats, missing records and compromised legitimate accounts can escape automated detection.
Corrections
Use Report an incorrect result on the result screen to explain a concern. DSDillon’s owner workspace records review decisions and their history. The advisor does not automatically delete mail, send external reports, or recover funds.

