NextAct

What NextAct cannot do

A tool that overstates its reach is worse than no tool at all, because it converts your caution into misplaced confidence. So here are the limits, stated plainly.

The short version

For anything irreversible — a bank transfer, your password, a one-time code, remote access to your device — verify independently before you act, whatever NextAct told you. Contact the organisation using a number or address you already had, not one from the message.

NextAct can be wrong in both directions

It can miss a real fraud, and it can raise concerns about something entirely legitimate. Both happen. Neither is rare enough to ignore.

A missed fraud is the more costly error, so the system is built to say "I could not verify this" rather than to guess reassuringly. That means you will sometimes get an inconclusive result on a message that turns out to be fine.

No result means something is safe

The strongest statement NextAct makes is that no material risk was observed and that specific facts were independently verified. That is not the same as safe, and we will never word it as though it were.

Absence of evidence of fraud is not evidence of legitimacy. A brand-new scam has no history anywhere.

We do not consult any threat-intelligence database

Not currently. The commercial licensing terms of the available feeds have not been verified, and we will not build on a source whose terms we have not read.

This matters for how you read a result: when NextAct does not flag a link, that means our own analysis found nothing — not that the link is absent from any blocklist. We will say "no threat-intelligence source was consulted" rather than implying a clean result we did not obtain.

We never visit the links you submit

NextAct examines a link’s structure, its domain registration, its DNS records and its certificate. It does not load the page.

That is a deliberate security decision, and it has a cost: we cannot tell you where a shortened link finally lands, and we cannot compare a page’s appearance to the brand it claims. A link that survives our checks may still lead somewhere hostile.

A new domain is not proof of fraud

Criminals register domains days before using them, which makes domain age a genuinely useful signal. But real businesses also launch, rebrand and move.

NextAct treats registration age as one input among several, never as a verdict on its own. If a result rests mostly on domain age, the assessment will say so.

A valid certificate means almost nothing about honesty

Certificates are free and automatic. A phishing page has the same padlock your bank does. It proves the connection is encrypted, not that the operator is who they claim.

If you have ever been told to "check for the padlock", that advice is out of date.

Email authentication proves delivery, not intent

SPF, DKIM and DMARC tell you a message really came from the domain it claims. They tell you nothing about whether the sender is trustworthy.

A criminal who registers their own domain passes all three. So does a legitimate company whose account has been taken over.

NextAct cannot read text out of an image

There is no text recognition in this version. From a screenshot or a photo, NextAct decodes QR codes and nothing else — if the wording is only in the picture, it has not been analysed.

Paste the message as text if you want the wording checked. NextAct says so on the result rather than quietly assessing an image it could not read.

When text recognition is added it will be imperfect in its own ways — misreadings on low-quality images, unusual fonts and handwriting — and NextAct will show you what it extracted so you can correct it.

Criminals impersonate real organisations

Confirming that a company exists, that its website is genuine, or that its phone number is real tells you nothing about whether the message in front of you came from them.

This is why our recommendations always route you through a channel you already trust, never through a contact detail contained in the suspicious message itself.

The language analysis can be manipulated

Documents and messages sometimes contain text designed to manipulate automated checkers — instructions telling the system to report the content as legitimate.

No language model is connected in this version. Where you see an AI explanation marked as simulated, it was produced by a test stand-in, not a model.

NextAct is built so that this cannot lower a risk assessment. The assessment comes from rules. When an automated reading is switched on, what it proposes must quote the exact text it relies on, can only make the result more cautious and only by a limited amount, and anything it says about a risk level is thrown away. Where we detect such an attempt, we say so. It tells you what the text contains, not on its own who sent it or why.

Why there is no accuracy figure

You will not find a percentage anywhere on this site. Publishing one would require a labelled test set that fairly represents the messages real people receive, and an honest account of what that set contains.

Until that exists and can be published alongside the number, any figure we quoted would be marketing rather than measurement.