Editorial Standards

Last updated: 28 July 2026

ScanTotal publishes guidance about scams and online safety. People act on that guidance, sometimes while they are frightened and under pressure from someone trying to steal from them. These are the rules we hold ourselves to, so that what we publish can be trusted.

Who writes this

Articles are written and reviewed by Kumari Rajapaksha, founder of ScanTotal, based in Melbourne, Australia. ScanTotal is a small independent project, not a company with a security research department, and we do not publish under invented team names or pseudonyms.

Kumari is a business consultant and technology strategist. She is not a licensed security researcher, financial adviser or lawyer, and we do not claim otherwise. Where an article touches money, law or personal safety, it points to the body that can actually help: your bank, the RBI, CERT-In, Scamwatch, IDCARE or the police.

What "editorial review" means here

An Editorial review line on an article means the page was checked for accuracy, clarity and currency by the author. It does not mean a specialist security or payments professional signed it off. If we obtain specialist review in future, we will name the reviewer and their credentials rather than implying them.

Examples in our articles are illustrative

The scam messages, emails and websites shown in our articles are constructed examples. They are assembled from the structure of scams documented in public advisories from bodies such as CERT-In, the RBI, NPCI, Scamwatch, the ACCC and the FBI IC3.

They are not copies of messages sent to us by users. We never store the content anyone submits to our scanners, so we could not reproduce a real submission even if we wanted to. If an article appears to claim otherwise, that is an error and we want to hear about it.

Every example domain we publish uses the reserved .example suffix, which nobody can register. That means no real business is ever named as a scam operator in our examples, including by accident if somebody registers a lookalike domain years from now.

Personal accounts

Where an article uses the first person, describing something that happened to the author or to someone she knows, that is a genuine account. It is published with the agreement of anyone involved and with identifying details removed. We do not invent personal stories to make a point land harder.

Sources and figures

Specific statistics, helpline numbers, regulatory rules and procedural claims are linked to the body that published them. Where we cannot find a primary source for a figure, we remove the figure rather than attribute it vaguely to "reports". General descriptions of how a scam works do not carry a citation, because they describe a widely documented pattern rather than a specific finding.

Naming brands

We name real companies, banks and government services when scammers impersonate them, because naming the impersonated brand is how a reader recognises the scam. It is never a statement that the brand did anything wrong, and we do not publish claims about a company's own security unless it is a matter of public record.

Describing communities

Some scams concentrate in particular countries or regions. When we explain why, we describe the structural reason: how payments work locally, whether medical costs are paid upfront, families separated across time zones. We do not describe any national, ethnic or religious group as more gullible or more worth targeting, and we do not attribute scam operations to a nationality unless a named authority has done so.

What our scanners can and cannot tell you

Our tools report what they actually checked. A result saying no known indicators were found means our specific checks matched nothing. It is not a guarantee that something is safe. If a check does not complete, we say so rather than reporting a pass. We would rather tell you we do not know than tell you something is fine when we have not established that.

Corrections

When we get something wrong, we correct the page and say what changed rather than quietly editing it. Where a correction affects published figures, the original claim stays visible alongside the correction so the record is honest.

To report an error, an outdated fact, or content you believe is harmful, use our report abuse page or email contact@scantotal.net.

Use of AI tools

We use AI assistance for drafting, editing and code, as many small publishers now do. Every published article is reviewed by a person before it goes live, and the factual claims, sources and recommendations are the author's responsibility regardless of which tool helped produce a draft.