Before you tap
Check in the courier's or bank's official app, or call their main number, instead of the link.
Paste the message as you got it. Short links are followed to the end, and the final address, domain age, brand impersonation and app (APK) downloads are checked.
Check in the courier's or bank's official app, or call their main number, instead of the link.
If you entered anything, contact that company or bank right away. What to do →
In Korea: 118 (KISA spam center), 24 hours, free. Police cybercrime: ecrm.police.go.kr
Checks run from our servers. Pages that show phishing only to certain phones or regions, or that move on with JavaScript, can look clean here. Methodology & accuracy
Message types and how to tell
Smishing texts hide their real destination behind short links and borrow the names of couriers, banks, government offices — and, after a data breach, the breached company itself. Paste the message and DechoNet finds every link, follows shorteners to the final address, and checks what can be observed from outside: when the domain was registered, whether it imitates a Korean brand, whether it makes you download an Android app, and whether it already appears on public phishing feeds or in our brand-impersonation tracking.
Redirects are followed by their headers, then the first 64 KB of the final page's HTML is read — scripts never run. On every page we look for a fake "verify you are human" check that tells you to paste a command into Win+R or PowerShell (ClickFix); on free-hosting addresses also for a login form or a brand name. The text you paste is not stored. Every verdict shows its reasons, and the best possible result is "no warning signs found", never "safe".
Yes. The text is not stored. Each link is opened from our servers to see where it leads (the start of the page is read, scripts never run), and only the first link's domain is kept for statistics. Names or addresses in the message are not kept anywhere.
Not necessarily. New phishing sites appear every hour and some show phishing only to certain phones. Never enter passwords, card numbers or verification codes from a link in a text — open the official app instead.
118 (KISA illegal spam response centre, 24 hours) or the police cyber crime portal (ecrm.police.go.kr). If you already entered financial details, contact your bank or card company first.