UncovAI's Updated URL Phishing Detection Model
Phishing pages don't look broken anymore. AI writes the copy, clones the layout, and hides the real destination behind a chain of redirects. Here's what changed in UncovAI's detection model to keep up.
The updated model follows full redirect chains, scores pages for AI-generated scam markers on top of domain signals, and returns a verdict in under three seconds โ as a free web check, a browser extension, a Telegram bot, or a REST API on the Microsoft Azure Marketplace.
Why the old approach stopped being enough
A phishing link used to give itself away. Bad grammar, a mismatched domain, a login page that looked five years out of date. That checklist doesn't hold anymore. Generative AI lets scammers build a convincing checkout page or support chat script in minutes, then route it through shortened links and redirect chains so static blocklists never see the real destination.
Microsoft's own threat intelligence team has tracked phishing campaigns that use AI-generated code specifically to disguise malicious payloads and slip past traditional filters. That's not a one-off. It's the direction the whole category is moving, and it's why a scam and deepfake detector built for AI-era threats needs to check more than a domain's reputation history.
What changed in the model
Full redirect-chain analysis
The model follows shortened and multi-hop redirects to score the actual landing page, not just the first link you paste in.
AI-content markers
Landing pages are checked for structural and linguistic signals common to AI-drafted scam copy, alongside standard domain checks.
Zero-reputation coverage
Newly registered domains get scored on signal, not history โ so brand-new phishing infrastructure doesn't get a free pass.
Configurable thresholds
API deployments can tune sensitivity per use case, trading false positives against coverage depending on where it's deployed.
Quick facts
How a check works
Submit a link through the web analyzer, the browser extension, or the API. The model unwraps any redirects to find the real destination, scores domain and registration signals alongside page content for phishing and AI-generation patterns, then returns a risk verdict. It's built as a first-pass filter โ an advisory result, not a final judgment. New or low-traffic domains can still get flagged even when they're legitimate, so treat a "safe" result as no major warning detected at scan time, not a guarantee.
Where to use it
Web analyzer
Paste a link at uncovai.com for a one-off check. No account required.
Browser extension
Right-click any link on the page you're viewing and scan it on the spot.
Telegram bot
Forward a suspicious link to @UncovAI_Bot and get a result inline, free.
Azure Marketplace API
Wire detection into an email gateway or SOC tool with a REST endpoint.
Frequently asked questions
What does the updated model actually detect?
Phishing links, scam pages, AI-generated content farms, and links that hide their real destination behind redirects.
Can it catch shortened or redirected malicious links?
Yes. It follows the full redirect chain and scores the real destination, not just the link you paste in.
Does UncovAI store the URLs you submit?
No. Submitted URLs aren't stored, so checks stay private by design.
Can a legitimate site still get flagged?
Occasionally. New domains or unusual configurations can raise a risk score even for legitimate sites โ treat results as advisory.
Is the API suitable for enterprise security tooling?
Yes. It's a REST API with JSON responses, sub-3-second response times, no GPU requirement, and configurable confidence thresholds, built to slot into email gateways or endpoint protection.
Check a link before you trust it
Run a free scan on the web, in your browser, or in Telegram โ or wire the detection engine into your own stack via the Azure Marketplace API.
Get Started Free โ
