Transparency report
How ORTSLAB works
This page explains exactly what the forensic engine analyzes, what it currently cannot guarantee, and what improvements are planned. We believe trust is built through honesty, not marketing claims.
What ORTSLAB analyzes
📧Emails (.eml files or pasted content)
📱SMS and WhatsApp messages
🔗URLs and links found in messages
📎Attachments (PDF, Office, images with QR codes)
🪧Physical or digital posters (URL/QR only)
🌐Domain lookup tool (independent check)
Signals the engine checks
Behind every verdict, the engine runs dozens of forensic checks. These are the main categories:
SPF / DKIM / DMARC
Domain age (RDAP)
URL reputation (VirusTotal)
Unicode homoglyphs
Hidden redirects
Malicious QR codes
Suspicious PDF/Office attachments
Brand impersonation
Official body impersonation
Social engineering patterns
International number cross-check
BEC / CEO Fraud
Global spam reputation
What it cannot guarantee
No automated tool can guarantee 100% detection of every threat.
Cybercriminals constantly evolve and develop new techniques specifically designed to evade detection systems. ORTSLAB is a support tool, not an infallible verdict.
Specifically, today the engine does not yet cover:
🖼️Images without readable text (memes, unclear screenshots)
🎙️Voice calls or voice notes
📨Forwarding chains with more than one nested level
🎭Deepfakes or manipulated audio/video
What improvements are planned
ORTSLAB is in constant evolution. Some advanced capabilities are currently in development or evaluation:
Advanced image analysis — visual context beyond OCR text extraction
Nested forwarding chains — recursive analysis of multi-level forwarded threads
New official bodies by country — expanding beyond Spain and Mexico
Improved contextual analysis — better differentiation between editorial content and active fraud
Project philosophy
ORTSLAB does not aim to replace human judgment or professional advice.
Its goal is to help citizens, professionals and institutions identify technological risks and improve prevention against cyberfraud. The verdict it provides is a forensic indicator built from technical evidence — always use it alongside common sense and, when something is unclear, direct verification with the institution involved.