USE LEGITTAP RIGHT HERE

Think it might be a scam? Check it here.

Choose what you have. LEGITTAP can check a suspicious message, phone number, link, or screenshot right on this website.

No app required. Use LEGITTAP in your browser. Your checks use the same protected LEGITTAP system as the mobile app.

CHECK IT NOW

What do you want LEGITTAP to check?

Use LEGITTAP right here. Choose Message, Phone, Link, or Screenshot below. Sign in with your LEGITTAP account to run the check and save it to the same history as the app.

Sign in to scan Use your LEGITTAP email and password, or create an account here.

Up to 20,000 characters. History keeps a privacy-safe preview instead of the full message.

SAME ACCOUNT, SAME HISTORY

Recent checks

FOUR WAYS TO CHECK

Put the suspicious thing in front of LEGITTAP.

Each check explains what evidence was found, what remains uncertain, and what a safer next step looks like.

ALREADY CLICKED, PAID, OR SHARED SOMETHING?

LEGITTAP can help you start cleaning it up.

Pick what happened. Start with the urgent steps, then use official recovery and reporting resources. Do not pay anyone who contacts you promising to recover lost money for an upfront fee.

$I sent moneyCard, bank transfer, payment app, wire, gift card, or crypto
  1. Contact the bank, card issuer, payment app, wire company, gift-card issuer, or crypto provider immediately.
  2. Tell them the payment was caused by fraud and ask whether it can be stopped, reversed, disputed, or refunded.
  3. Save receipts, transaction IDs, messages, phone numbers, and screenshots.
FTC recovery steps →
🔑I shared a password or security codeEmail, banking, social media, or another account
  1. Change the compromised password from a device you trust.
  2. Sign out other sessions or devices if the account offers that option.
  3. Turn on two-factor authentication and change the password anywhere else you reused it.
FTC account-recovery guidance →
IDI shared personal informationSSN, identity documents, account numbers, or other sensitive data
  1. Document exactly what information was exposed.
  2. Use IdentityTheft.gov to build a recovery plan for your situation.
  3. Watch affected financial and online accounts closely for unauthorized activity.
Start at IdentityTheft.gov →
⚠I gave access to my phone or computerRemote-control app, screen sharing, software install, or unknown file
  1. End the remote session and disconnect the affected device from the network if someone may still have access.
  2. Remove remote-access software you did not intend to keep and run a trusted security scan.
  3. From a clean device, change passwords for important accounts that may have been exposed.
FTC device-access guidance →

OFFICIAL HELP

Report it and create a recovery trail.

These are government resources, not paid recovery companies.

HOW IT WORKS

A verification chain, not a magic green light.

1

Submit the clue

Message, number, link, or image. LEGITTAP starts with the evidence you actually have.

2

See why it was flagged

Results separate risk signals, reassuring indicators, uncertainty, confidence, and recommended actions.

3

Take the next best check

Verify the sender, compare an official domain, or review history instead of treating one signal as the whole answer.

BUILT AROUND CAUTION

Useful confidence without fake certainty.

✓An “unable to verify” result does not get a fake 0/100 risk score.
✓A threat-list miss is not presented as proof that a website is safe.
✓A valid phone format is not presented as proof of who owns or controls the number.
✓Results show uncertainty and give an independent verification step.
LEGITTAP is designed to help you decide what deserves verification. It does not make legal findings, verify identities, or replace professional advice.
PHONE CHECK RESULT
Unable to verify

The number can have a valid format while the caller’s identity remains unproven. Caller ID can also be spoofed.

RISK SCORENot assigned
NEXT STEPCompare official contact

PRIVACY BY DESIGN

History is useful without becoming a vault of raw suspicious content.

Text history uses a privacy-safe preview. URL history retains the hostname rather than the full submitted URL. Phone history is designed to retain only a masked preview ending in the last four digits. Successful image analysis removes raw uploaded evidence.

Read the full privacy policy

QUESTIONS

Clear boundaries make a better safety tool.

Does low risk prove something is legitimate?

No. LEGITTAP evaluates the evidence available to the scan. A low-risk result is not identity verification or a guarantee.

Can LEGITTAP tell me who owns a phone number?

Not in the current beta. The phone check evaluates supported structural clues and tells you what still requires independent verification.

Does LEGITTAP open suspicious links?

The current URL design analyzes the submitted URL and configured threat intelligence without using the backend to fetch arbitrary submitted webpage content.

What happens to screenshots?

Raw screenshot/image evidence is stored privately for analysis and is designed to be deleted after successful analysis. Abandoned uploads expire and are cleaned on a schedule.

PRIVATE BETA

LEGITTAP is being tested on real devices now.

The current beta is focused on reliable scans, privacy-safe history, native sharing, accessibility, and clear decision support before wider release.

Beta support