Methodology & accuracy

It is easy for a security tool to say "safe". We never say it. Instead, this page shows what each verdict rests on, where we looked from, and how often we turned out to be wrong when we measured it.

Last measured 2026-10-10

Principles

  • We never call anything "safe". The best possible result is "no warning signs found".
  • Every warning shows its reasons. Verdicts we cannot explain (such as an AI model deciding alone) are not used.
  • The tool and lookup path determine which vantage points are used. Paths with both edge and Seoul responses compare them; not every lookup runs from both places.
  • Only public information is looked at. Messages you paste are never stored.
  • We never single out an organisation. Statistics are published as sector-level shares only.

Where we observe from

Global edge (Cloudflare)

Most lookups start here. Responses can vary with the target, resolver and observation location.

Seoul vantage point

Korean sites that drop foreign connections (many public-sector sites) are re-checked from Seoul. Phishing links are followed from Seoul as a Korean phone would; when the destination differs from what a visitor abroad gets, it is flagged as possible cloaking.

Phishing & smishing link check 647 legitimate · 416 phishing sites

0 / 647legitimate sites wrongly called "danger"
1.9%legitimate free-hosting sites called "suspicious"
28–92%real phishing sites warned from the link alone (by source, site level)

We ran legitimate sites and real phishing links through the same rules and counted. Feed listings were switched off (matching the feed would prove nothing) and only the link (URL) was given.

SampleSizeWarned (danger + suspicious)Danger
Legitimate: Korean institutions and major brands22300
Legitimate: popular sites on free hosting (Tranco top 1M)3206 (1.9%)0
Legitimate: real login pages (Korean banks, cards, shops, government; global services)10400
Phishing: a public suspicious-phishing list (phishunt, CC0), held-out, list match off150 sites127 (85%)104
Phishing: a differently collected list (TweetFeed, CC0 — researcher posts), held-out174 sites49 (28%) · 38% of reachable18
Phishing: a fresh phishunt sample (final 11 October rules, no site shared with earlier samples)92 sites85 (92%)70
  • Of 647 legitimate sites (104 of them real login pages), none was judged "danger". When you see "danger", the reasons are clear-cut.
  • From the link alone (list match off), 85% of 150 real phishing sites held out from rule-writing drew a warning (69% on the same sample with the rules before 10 October; 83% on two earlier held-out samples). Lists carry one campaign's many sub-addresses, so we count sites. The live service also warns ("suspicious") on addresses on that list. On a differently collected list (TweetFeed — links posted by researchers) it was only 28% (38% of reachable sites); phishing aimed at Japan that shows a blank page to visitors abroad is the weak spot. Results vary a lot by source, so both lists are re-measured monthly on fresh samples. With the final 11 October rules, a fresh phishunt sample of 92 sites sharing no site with earlier samples came out at 92%.
  • The page is first read as text (512KB of HTML and up to five of the site's own scripts); links that leaves undecided are opened in a headless browser in Seoul to see what the scripts draw (nothing is clicked or typed). Links that look aimed at Japan are opened once more as a Japanese phone from Tokyo, and a link that shows Korean and Japanese phones different sites is flagged as cloaking. Pages shown only to one carrier's mobile IPs can still be missed.
  • A link once judged "danger" is remembered for good: the same link, and other links on the same attacker-made address, keep the warning even after the page goes down or turns blank.
  • When you paste the whole message, the combination of a lure ("delivery", "refund", "account locked") and the link is read too. That path is not measured yet: there is no public sample of real messages.
  • A free-hosting address alone is not a warning — plenty of personal blogs and projects live there. We warn only with evidence: a login form, a lure word, a brand name.
  • Pages shown only to certain phones or regions can be missed.

Phishing Link Check →

Exposed admin page check 61 Korean institutions · 27 risky screens

23 / 27risky classifications that were right (85%)
4wrong — all decided from the hostname alone
—missed exposures (recall) cannot be measured
  • From the records of 61 Korean institutions, a person checked each of the 27 screens classified as risky. 23 (85%) were right.
  • All 4 misses were classified from the hostname alone (a business-customer service taken for an internal system, groupware for remote access). Hostnames alone no longer decide: the page itself has to show it.
  • Admin screens, developer tools and directory listings did not occur in this sample, so their accuracy is not measured yet.
  • Missed exposures (recall) cannot be measured: hosts that never appear in certificate records and the like are not seen at all.

Exposed Admin Pages →

Security hygiene index

  • A fixed list of public websites per sector is observed weekly with the same tools. The monthly index counts each site's latest observation of the month only.
  • A metric is not published for a sector with fewer than 10 measured sites. Site names are never published.
  • When a rule changes, its version goes up, and observations under different versions are never compared as a "change".

Measurement log

DateWhat changed
2026-10-05First published measurement — numbers after fixing what the measurement itself exposed (a government domain mistaken for a lookalike, brands' own short links, blanket warnings on free hosting, hostname-only exposure classes).
2026-10-10Re-measured after the rule update: wider page reading (512KB and the site's own scripts, host block screens, Telegram-bot exfiltration, brand-dressed logins, brand misspellings and more) and 104 real login pages added to the legitimate sample. On a sample not used to write the rules: 83% of phishing sites warned (69% before), still no legitimate site of 647 called "danger". After checking the lists' terms the same day, figures measured on a list whose terms do not allow commercial use were removed from this page.
2026-10-11Studied the misses on a list we may use commercially (phishunt, CC0) and tightened the rules (an "@" disguise bug fixed, brand labels, misspellings, suspended hosting and more). 85% of 150 held-out sites warned; still no legitimate site of 647 called "danger".
2026-10-11Added a second render as a Japanese phone from Tokyo for links aimed at Japan, a cloaking-by-country signal, and fixed evidence lost when two views were merged. A fresh phishunt sample of 92 sites sharing no site with earlier samples: 92% warned; legitimate 647: no "danger" (6 free-hosting sites "suspicious", 1.9%).

Samples: a public suspicious-phishing list (phishunt, CC0), the Tranco popular-sites list, public institution and company homepages and login pages. Measured 2026-10-10.