paypal.statement-verify.clickOwner: statement-verify.click
Most URL checkers score a domain. PrivateCue reads the link against what the person claimed two lines above it, and caps weak evidence.
chase-secure-verify.topA domain checker scores the address. It cannot see that the person wrote “this is Chase” and then sent a link belonging to somebody else — the claim two lines above is exactly what a URL-only checker misses. How the module works.
A strange link cannot accuse on its own. With no fraud script matched, structural findings add at most four points to a hundred. Nothing is fetched, nothing is checked against a blocklist, and no real domain is ever called fraudulent.
Most people stop at the brand name. The registrable domain identifies the owner—and it often sits farther to the right.
paypal.statement-verify.clickOwner: statement-verify.click
chase-secure-verify.topOwner: chase-secure-verify.top
login.microsoftonline.com.attacker.netOwner: attacker.net
secure-bank.com@10.0.0.4/loginDestination: 10.0.0.4
Shorteners, campaign parameters, machine-generated hosting names and unfamiliar country-code domains all occur in legitimate traffic. Treating them as verdicts would create noise, not safety.
PrivateCue gives real weight to contextual mismatch: an institution is named, but the address belongs elsewhere; a link arrives directly after a money demand; the claim and destination do not agree.
short.link/8q2short.link/8q2Nothing is fetched, resolved, WHOIS-queried or sent to a reputation database. The analysis stays in your browser, works offline and reveals nothing about what you are investigating.
The module describes the shape of an address and any mismatch with the surrounding claim. It can never assert that a named real domain is fraudulent. You receive the reasoning and keep the judgement.
address + conversationLinks are read in context, so the useful check is the whole thread rather than one URL pasted into a box.