Night Study/Tools/Scam message checker
Is this message from my exchange, or a scam? Four questions
The verdict usually lands on the fourth question, because what a message asks for is more revealing than where it appears to come from.
Start with the first question
Answer as many as apply. The verdict updates each time, and some answers settle it on their own.
About this tool — what it is checking and why
The four questions, in full
(1) How did it arrive — email, text message, phone call, or a social platform or chat app? (2) Who made contact first: they contacted you, you opened a support case, or it replied to something you posted publicly? (3) Is your anti-phishing code in it — correct code, no code at all, or you have not set one? (4) What does it want you to do: give a code, password or recovery phrase; move funds to a safer address; pay a fee, tax or deposit; click a link and sign in; install something or share your screen; or nothing at all. Any request in the first, second, third or fifth group is a scam regardless of how the other three were answered.
What problem this solves
Deciding whether a message is genuine while it is actively trying to make you hurry. The tool is deliberately slow and asks about structure rather than wording, because wording is the part the sender controls.
Why the fourth question usually decides it
A convincing sender address can be forged, a display name is free text, and a caller can know real details about you. What cannot be disguised is the request. Any message that needs a verification code, a password, a transfer to a new address or a payment is asking for something no legitimate process asks for.
Why it asks who made contact first
Some exchanges say in writing that they will never call you; Binance.US is one. Others word it differently, so the tool does not rely on any company's promise. It relies on the fact that a conversation you did not start cannot be checked from inside it, while anything genuine about your account can be checked inside the account. Direction of first contact is available before you read a word of the content, which is why it is asked second.
About the anti-phishing code question
Binance, for one, says that once you set a code it appears in all its genuine emails and texts. A message without it is not one to act on; a message with it is not proven genuine. A genuine notification about a withdrawal you did not request will carry the correct code, and at that point the code is the least interesting thing in the message. The full explanation is here.
What to do with the verdict
Every path ends the same way: check the claim from inside your account, reached by typing the address or using a bookmark. That habit makes the entire category of message-based attacks largely irrelevant, which is why it appears in every result this tool produces.
What it cannot do
It does not read your message, scan any link, or connect to anything. It cannot tell you whether a specific domain is legitimate. For that, the manual four-check procedure covers reading sender addresses and link destinations.