McAfee Scam Detector Review: What It Checks Automatically—and What You Must Verify Yourself
Scam Detector is a useful second opinion across messages, email, QR codes and videos. It isn't sender authentication, a payment guarantee or permission to stop thinking.
Quick answer: McAfee Scam Detector is worth enabling when it's included in a current McAfee plan, especially for a household that benefits from automatic SMS and email warnings plus manual checks of DMs, screenshots, links and QR codes. Coverage isn't uniform: Android can analyze SMS automatically, third-party chats may need manual checks, iOS has separate SMS/iMessage limits, email behavior varies by provider, and deepfake detection primarily analyzes AI-generated audio on compatible hardware. McAfee advertises very high accuracy, but the public claims don't reveal enough test-set and false-positive detail to treat a quiet result as authentication. The September 2025 AV-Comparatives review is useful for platform behavior and alert quality, yet it was commissioned by McAfee and used a small unspecified set of known samples. Enable the feature, keep Balanced sensitivity first, verify money/login/emergency requests through a second trusted channel, and respond according to what you already clicked, shared or paid.
Verdict: a useful pause button, not a truth machine
McAfee Scam Detector is one of the better reasons to enable a current McAfee subscription because it operates where ordinary people make hurried decisions: texts, inboxes, social chats, QR codes and videos. It can surface risk before a click, explain why a message looks suspicious and give a second opinion on content that would otherwise be guessed at. That intervention is valuable even when the underlying model is imperfect.
The central limitation is easy to miss: detection isn't authentication. A quiet result doesn't prove that a bank sent the message, a QR sticker belongs on the meter, a seller will deliver or a voice belongs to a relative. Our overall McAfee review covers the security suite; this page judges Scam Detector by channel coverage, evidence quality, privacy cost and what the alert lets a person do next.
Detection, authentication and blocking are three different jobs
Detection estimates whether content resembles known fraud patterns, malicious links or AI-generated audio. Authentication establishes who controls the sender, account, website or voice. Blocking stops a risky destination, attachment or transaction. McAfee combines parts of detection and web blocking, but the user still needs an independent channel to authenticate a money, login or emergency request.
This distinction explains apparently contradictory outcomes. A legitimate bank alert can look suspicious because it's urgent, while a novel investment pitch can pass a classifier and still be fraudulent. Safe Browsing may block a known malicious page after a click, yet it can't stop a wire transfer sent to a scammer through a genuine payment app. Use each signal for the decision it can actually support.
Current US plans include Scam Detector, with new QR and social checks in 2026
McAfee's live US Scam Detector page says every plan includes automatic alerts for text, email and video scams plus on-demand QR checks. The feature also appears across the current Essential, Premium, Advanced and Ultimate comparisons. That makes upgrading solely for scam detection hard to justify; choose the tier for device count, privacy and identity features instead.
The original 2025 release named the US, UK and Australia. McAfee's January 2026 QR and social-message update announced broader rollout, while the newsroom release named 11 geographies for spring. Country, language, app version, platform and hardware still control the actual entitlement, so confirm the feature tiles after activation instead of treating “all plans” as “all functions on all devices.”
What is automatic depends on the device and communication channel
The useful question isn't whether the bundle contains Scam Detector; it's whether the specific message reaches an automatic sensor. Android SMS can be analyzed as it arrives, while third-party chats may need a manual check. iOS separates SMS filtering from iMessage restrictions. Email integrates with selected providers, and video analysis adds a hardware gate that ordinary antivirus protection doesn't have.

McAfee's marketing sometimes groups iMessage, WhatsApp, Messenger and other apps under broad detection language. The September 2025 platform test found more specific boundaries, and 2026 introduced screenshot-based social checks. We use the narrower operational description where evidence differs, then tell readers to test the current build because mobile permissions and platform policies change.
Android provides the strongest automatic text workflow—with a permission cost
On Android, McAfee says SMS messages can be analyzed as they arrive and flagged before the user opens them. The September 2025 AV-Comparatives review observed automatic SMS detection and clear notifications. That's a meaningful speed advantage for toll, delivery, bank and account-alert lures that pressure a user to tap immediately.
The same review found that full functionality could request text-message, contact and usage access plus screen-recording and display-over-other-apps permissions. Those capabilities enable cross-app warnings, but they broaden what the security app can observe. Grant them one at a time, read Android's explanation, test the channel and remove permissions for functionality you choose not to use.
iPhone SMS filtering doesn't equal automatic iMessage scanning
McAfee says suspicious SMS can be filtered on iPhone and a manual scam check is available. AV-Comparatives didn't test iOS directly, but recorded McAfee's explanation that Apple's restrictions prevent automatic scanning or movement of iMessages. Users instead copy or forward the message into the McAfee app through the supported share route.
That boundary matters because many family and impersonation scams arrive through iMessage rather than carrier SMS. Check whether the conversation is blue or green, learn the current manual route and don't assume an untouched conversation was cleared. Our upcoming iPhone-specific McAfee spoke will cover the full iOS permission model; this page keeps the detector verdict tied to the evidence available now.
Email protection supports selected providers and presents alerts differently
McAfee's 2025 launch description named Gmail, Outlook and Yahoo and advertised up to ten email addresses. AV-Comparatives tested Gmail, Microsoft accounts including Hotmail, Live, MSN and Outlook, plus Yahoo. At that time Gmail received a McAfee Alert label, Outlook received a label and dedicated folder, and Yahoo used a dedicated folder.
Provider behavior can change, and a folder move isn't the same as deletion or quarantine by an antivirus engine. Review the linked mailbox, recovery address and granted access before connecting a primary account. If an alert concerns a real invoice or account, open the vendor through its saved app or typed address; don't restore the message and use its link merely because you want to “test” it.
Manual Scam Check is the bridge for screenshots, messages and links
McAfee says users can upload a screenshot, paste a message or submit a link for analysis and receive an explanation. This is particularly useful for linkless DMs, image-only invoice emails and content from an unsupported messaging app. It's also a safer habit than opening the destination, provided the link is copied without activating it and the screenshot is redacted.
The September 2025 review found manual checks in the mobile app, while Windows relied on automatic detection for the tested email workflow. Don't assume the same button exists on every desktop. If the on-device app lacks it, use a supported mobile share flow or one of McAfee's current AI-assistant integrations, while accounting for the different privacy path described below.
QR scanning reveals a destination, not whether the physical code belongs there
McAfee's 2026 update added instant QR safety checks intended to assess a code before the user taps through. That can catch a known malicious or suspicious URL hidden behind an opaque square. The FBI's warning about QR codes in unsolicited packages shows why the layer matters: a code can lead to credential theft, financial fraud or malware.
A URL reputation result can't prove a sticker was placed by the parking operator, restaurant or event organizer. Check for a pasted-over label, compare the printed domain with the official service and open the payment app independently when possible. Newly created sites and legitimate compromised domains can evade a reputation list, so “no threat found” remains a reason to inspect—not permission to enter a card or wallet seed phrase.
Deepfake Detector primarily looks for AI-generated or manipulated audio in video
McAfee's Deepfake Detector page describes transformer-based neural models that analyze audio within video and warn when it's likely generated or manipulated by AI. The company says alerts can arrive within seconds and that supported processing occurs on the device. That's a narrower and more defensible description than “detects every fake video.”
An audio detector doesn't authenticate the person, verify a quotation, inspect every visual edit or prove a video is fraudulent. Authentic audio can be placed in a misleading edit, and synthetic content can be harmless. Treat an alert as evidence that the media deserves verification; treat the claim itself—investment, emergency, endorsement or news—as a separate fact-check through the named person's or organization's official channels.
Video detection has a much higher hardware bar than ordinary McAfee protection
McAfee's current system-requirements page lists broad support for current Windows, macOS, Android, iOS and ChromeOS products, then points to separate requirements for video scam protection. The September 2025 review tested modern Windows 11 hardware and listed compatible AI-capable Windows systems plus selected Samsung Galaxy S21-or-later and Google Pixel 7-or-later devices at that time.
Compatibility lists move faster than an evergreen review, so we don't promise those 2025 boundaries remain exhaustive. Open the current support page and verify the Deepfake Detector tile on the exact device. A McAfee subscription working normally for antivirus, VPN and web protection doesn't prove that its CPU, memory, graphics, security chip or mobile model supports video inference.
“On-device wherever possible” is helpful, but not a universal privacy guarantee
McAfee says deepfake audio processing is on-device and that it doesn't store the analyzed audio or browsing history. Its Scam Detector launch article says on-device AI is used wherever possible, a phrase that leaves room for channel-specific cloud services. Automatic email integration, manual screenshot uploads and AI-assistant connectors necessarily involve different data flows from local video inference.
Android's SMS, contact, usage, screen-capture and overlay permissions create the largest visible tradeoff. Link only the mailboxes you need, redact manual specimens and review permissions after app updates. A privacy claim for one detector should never be silently extended to every input route; consult McAfee's current privacy and legal terms for the service actually enabled.
McAfee's 99%, 96% and “15x better” claims need methodology before they need applause
McAfee says the initial text model exceeded 99% accuracy and its 2025 release said deepfake detection reached 96%. The current product page also claims the detector is 15 times better than most competitors because it reads full message context. Those numbers may describe real internal evaluations, but the public pages don't provide enough class balance, sample composition, decision threshold, false-positive rate or competitor protocol to reproduce them.
Accuracy can mean overall correct classifications, recall on scams, precision of alerts or another measure. A model can exceed 99% overall accuracy on a set dominated by legitimate messages while missing a meaningful share of rare scams. We therefore quote the numbers only as vendor claims and judge the consumer feature through observable coverage, explanations, permissions and the response workflow.
Rare-event detection makes false alarms and missed scams inevitable
McAfee said roughly 1.5% of analyzed texts and 1.8% of analyzed emails were flagged in its early rollout. When suspicious content is a small share of everything scanned, even a strong classifier can generate false alerts, and a low alert count can reflect unsupported channels or conservative sensitivity. The percentage flagged isn't the same as the percentage of all scams caught.
Use a warning to slow down and verify rather than to accuse a real sender. Use no warning as “no risk detected in the observed content,” not “genuine.” Keep the business rule simple: any request involving money, credentials, one-time codes, remote access, seed phrases or an emergency gets an independent check regardless of the model's result.
The AV-Comparatives review is most useful for platform behavior and alert design
AV-Comparatives tested McAfee Total Protection 1.32 and Mobile Security 9.8 in September 2025 across Windows 11 and Android 15. It exercised known examples of text, email and deepfake scams, observed timely and contextual alerts, documented the email-provider differences and saw consistent Windows deepfake warnings. The report also records setup, permissions and hardware details that vendor overview pages compress.
Its conclusion was positive, but not unqualified: Android deepfake results were less predictable because of a cooldown, warning wording could confuse users, messaging-app scams needed manual checks, iMessages had an Apple-policy boundary, email providers were limited and compatible hardware was required. Those operational limits are more useful to a buyer than a single star score would be.
The test was commissioned by McAfee and used a small unspecified sample
The report labels itself “Commissioned by McAfee” and says a few known samples across three categories were used. It doesn't publish a large confusion matrix, false-positive corpus or blind population sample. That means it supports the claim that the tested features worked in those scenarios and explains the user experience; it doesn't independently validate the vendor's universal 99% or 96% marketing figures.
This distinction protects both the reader and the lab. A commissioned review can still be technically useful when sponsorship and method are explicit. We use its direct observations, preserve its caveats and refuse to invent a detection rate. Future large, reproducible anti-scam benchmarks should replace these boundaries when they exist.
Start with Balanced sensitivity, then tune with evidence
McAfee describes High, Balanced and Low modes: High prioritizes caution with more alerts, Balanced is the default, and Low flags only clearer threats. Balanced is the sensible starting point for most adults because it lets the household observe both protection and interruption. High can suit a vulnerable family member or an active scam campaign, while Low risks hiding exactly the ambiguous approaches that need a pause.
Track false positives by channel and consequence rather than lowering sensitivity after one annoying alert. If legitimate bank notifications repeatedly trigger, keep the detector and use the bank app directly instead of allowlisting an entire message pattern. Test whether permissions, battery controls and notification settings—not the model threshold—caused a missed warning before changing the mode.
Interpret results as suspicious, no known risk, or not meaningfully checked
A suspicious result means the content or destination crossed a detection threshold; stop and inspect the explanation. A no-risk result means the available detector didn't find enough evidence, not that the sender is authentic. Unsupported provider, absent permission, manual-only channel, incompatible hardware or too little audio can make the check incomplete even when the interface appears quiet.
For every result, ask what was actually analyzed: the words, the URL, the QR destination, the screenshot or the video's audio. Then ask what remains outside that evidence. A valid domain can host a fraudulent seller, authentic video can contain a bad investment claim, and a genuine relative's compromised account can send a scam request.
Verify consequential requests through a separate trusted channel
The FTC's phishing guidance tells consumers to contact the company using a phone number or website known to be real—not the information in the message. Use the number on the bank card, the official app, a saved bookmark or a contact already stored before the emergency. For a relative, call a second family member or use a private code word.
Don't verify a suspicious email by replying, a QR payment by asking the linked site, or a deepfake call by using the number supplied during the call. Independence breaks the scammer's control of the conversation. If the request is real, a legitimate sender can tolerate a short delay while you authenticate it.
McAfee now offers manual checks inside ChatGPT and Claude
McAfee's May 2026 ChatGPT integration article says anyone can submit links, messages and screenshots to the McAfee app inside ChatGPT without a McAfee subscription. A July 2026 Claude connector guide describes a similar route and explicitly tells users to grant review permissions. These are current on-demand options, not automatic protection of the device or inbox.
The convenience comes with a different privacy path: you deliberately upload content into an AI conversation and invoke the McAfee integration. Redact names, account numbers, health details, private conversations and one-time codes; check both platforms' data controls and the connector permissions. Never paste a live password, seed phrase, full card number or illegal/intimate material into any chatbot for classification.
Scammers impersonate McAfee, so a McAfee-looking warning proves nothing
Fake renewal invoices, expired-subscription notices and browser virus warnings remain common. A February 2026 r/McAfee discussion describes invoice lures that push recipients to call a number rather than click. That community evidence shows the format users encounter, not the prevalence of the campaign or McAfee's detection rate.
Open the installed app or account bookmark and compare the subscription there. Don't call a number in the invoice, allow remote support from a popup or buy a cleanup product through an alert. Our dedicated fake McAfee popup guide identifies browser notifications, in-page overlays, operating-system toasts and genuine app alerts by source.
Check a suspicious specimen without activating it or oversharing
Take a screenshot that includes the sender, request and visible destination, then crop unrelated conversation and blur sensitive identifiers. Copy a URL as plain text without opening it; on mobile, use a long-press preview only if the operating system exposes the destination without loading it. Don't download an attachment merely to submit it, and never forward a malicious file to another person for a second opinion.
Preserve the original message if money, account takeover, extortion or law enforcement may be involved. Record date, sender, displayed number, platform and transaction details, but don't keep malware on an everyday device. Forward phishing texts to 7726 where supported and use the platform, business, FTC or IC3 reporting route appropriate to the event.
The correct response depends on what already happened
A detector verdict is only the start of incident triage. Someone who merely saw a message needs verification and reporting; someone who entered a password needs account containment; someone who sent money needs an immediate bank response. Treating every case as “run antivirus” wastes the first minutes of financial fraud and ignores stolen credentials that never installed malware.

The FTC's current post-scam guide likewise separates payment, personal information and device access. Preserve evidence while moving quickly. A McAfee warning can explain the lure, but the bank, account provider and official recovery system control reversals, session revocation and identity remediation.
If you only viewed the message, don't engage
Don't reply, call, tap, scan or open an attachment. Verify the claim independently, then report it through the messaging provider, email service, carrier or impersonated company and delete it after preserving any needed evidence. Viewing plain text normally doesn't mean the scammer controls the device, so avoid panic-driven downloads or paid “support.”
If the message threatens an immediate consequence, use that urgency as a warning signal. Open the real account separately and inspect alerts or transactions. Marking a message as junk helps the provider, while a reply confirms the address or number is active and gives the scammer another chance to build trust.
If you clicked but entered nothing, close, inspect and scan
Close the page, don't accept downloads or notifications and don't enter credentials. Check browser downloads, installed apps, extensions and device-management prompts, then update the operating system, browser and McAfee signatures and run an appropriate scan. Our scan and quarantine guide explains quick versus full scans and how to review a detection safely.
A click can also expose IP, browser and device details without installing malware. Change a password only if it was entered, auto-filled or reused on the destination, not as a ritual that distracts from the affected account. The FTC's June 2026 fake CAPTCHA warning adds an urgent case: if a page made you run commands, disconnect and treat the device as potentially compromised.
If you entered a password or code, contain the account from a clean device
Open the provider's official app or typed site on a trusted device, change the password, revoke active sessions and remove unfamiliar recovery methods, forwarding rules, passkeys and connected apps. Enable phishing-resistant MFA where available. If the same password was reused, change every affected account, starting with email, banking and password management.
One-time codes, push approvals and recovery codes can authorize a takeover even when the password stays secret. Tell the account provider exactly what was shared and ask it to review recent changes. Use the McAfee identity guide when SSNs, financial identifiers or new-credit activity are involved; message detection doesn't reverse identity misuse.
If you sent money, contact the financial institution immediately
Call the bank, card issuer, payment app, wire service or crypto platform through its verified route and ask whether the transfer can be stopped, reversed or flagged. Preserve the message, recipient, transaction ID, amount and time. Don't pay a “recovery agent” who promises to retrieve funds for another fee; recovery scams deliberately target recent victims.
Report through ReportFraud.ftc.gov and IC3 when appropriate, and follow the institution's dispute deadlines. McAfee's identity or restoration features may organize next steps, but they don't control the payment rail. A detector that warns after funds moved is evidence for the incident, not a replacement for the bank call.
If you granted remote access, disconnect before the scammer finishes
Disconnect the device from the network, end the remote session and use another trusted device to contact banks and change critical credentials. Record the remote tool, time and actions without reconnecting merely to inspect it. If the scammer instructed you to move money, tell the bank that remote access and social engineering were involved.
Update and scan the affected computer, remove remote-access software and persistence, inspect new users and browser extensions, and consider professional recovery or a clean reinstall when sensitive accounts were exposed. Our McAfee repair guide is for product failures; a known attacker session is an incident, not ordinary troubleshooting.
If you acted on a deepfake, respond to the action—not only the media
If a fake executive, celebrity or relative persuaded you to transfer money, follow the financial response immediately. If you disclosed credentials, contain the account. If you reposted misinformation, preserve the source, correct the post and notify affected people. Arguing over whether every frame is synthetic can wait until the preventable consequence is contained.
Verify the speaker through an official channel and look for the original event or statement. A McAfee “AI audio” warning is a useful clue, while no warning can reflect unsupported hardware, insufficient audio, a novel model or authentic audio used deceptively. Never use the detector as the sole basis for a public accusation that someone fabricated evidence.
Enable one channel at a time and prove that alerts can reach you
Install McAfee through the authenticated account or official app store using our installation guide, update it, open Scam Detector and review the exact features available. Connect one test mailbox, enable the intended SMS protection, choose Balanced sensitivity and inspect every permission. Confirm notification delivery without submitting a real password or sending yourself a live malicious URL.
Use a harmless sample screenshot or McAfee's built-in demonstration if available, then verify that the explanation identifies the channel and recommended action. Check battery optimization, notification categories and browser extension status if alerts fail. The WebAdvisor review covers the separate web-warning layer that can block a risky destination after a click.
Scam Detector is most valuable for mixed-device households and frequent manual checks
Enable it for relatives who receive many toll, delivery, bank or account lures and can understand the distinction between warning and proof. It's also useful for a household using several supported email providers, QR payments and social platforms, because manual screenshot checks create a consistent pause. The feature is already in current plans, so the incremental cost may be zero for an existing subscriber.
Keep the broader security stack aligned: Secure VPN protects network transport, Personal Data Cleanup reduces broker exposure, and identity monitoring watches separate signals. None authenticates a payment message. The value comes from connected layers with clear boundaries, not from calling every McAfee tile “scam protection.”
Limit or skip channels when access outweighs the benefit
Don't grant SMS, contact, screen or mailbox access by default on a device where those channels aren't used. Manual on-demand checks may be enough for a privacy-sensitive user with strong provider spam filtering and disciplined independent verification. Deepfake protection adds little on unsupported hardware or for someone who rarely watches untrusted video.
Skip a paid McAfee plan solely for manual analysis if the free ChatGPT or Claude McAfee integrations meet the need and their privacy path is acceptable. Conversely, those assistants don't replace automatic warnings or link blocking. If the suite's renewal economics no longer work, use the plan guide and cancellation guide rather than turning off protection impulsively.
Measure whether the detector changes decisions, not how many alerts it produces
Track the channel, automatic or manual route, explanation quality, false positive, missed case and the action taken. A useful alert arrives before interaction, identifies the risky request and sends the person to an independent verification path. A dashboard full of low-value warnings can train users to ignore the one that matters.
Review linked mailboxes, permissions, supported hardware, sensitivity and notification delivery every quarter and after app updates. Ask whether the household avoided a click, recognized a fake invoice or stopped a transfer because of the tool. Those outcomes justify the permission and attention cost far better than a vendor accuracy headline.
Bottom line: let McAfee create the pause, then verify outside the message
McAfee Scam Detector has credible practical value across automatic SMS and selected email flows, manual DM and screenshot checks, 2026 QR analysis and compatible-hardware deepfake detection. The AV-Comparatives review supports the observed user experience and platform limits, not a universal detection percentage. Android offers the richest automatic coverage, while iMessage, social apps, providers and video hardware create meaningful gaps.
Start with Balanced sensitivity, grant only needed permissions and teach every user that “no alert” means no known risk was detected—not that the request is authentic. Verify money, login, code and emergency requests through a separate trusted route. If interaction already occurred, respond to the consequence immediately: contain credentials, call the bank or disconnect remote access before debating the detector's verdict.
For adjacent device issues, use the McAfee performance guide or firewall guide. Those pages keep operational fixes separate from fraud response, which is exactly how the McAfee hub avoids becoming one giant page that answers every question badly.
McAfee Scam Detector FAQ
Is McAfee Scam Detector worth using?
Yes when it's already included in your McAfee plan and you'll grant only the permissions needed for the channels you want protected. Automatic SMS and email warnings, manual screenshot/link checks and QR analysis are useful layers. The tool is less valuable if your accounts and device are unsupported or if you treat a quiet result as proof that a sender or payment request is genuine.
Is Scam Detector included in every McAfee plan?
McAfee's current US Scam Detector page says all plans include automatic alerts for text, email and video scams plus on-demand QR checks. Features still depend on country, language, device, hardware, app version and rollout. Confirm the tiles and permissions inside your own account rather than assuming every device receives every detector.
Does McAfee read my text messages?
Android automatic SMS detection needs access that allows the app to analyze incoming messages and show warnings; the independently written but McAfee-commissioned AV-Comparatives review also recorded contacts, usage, screen-recording and overlay permissions for full Android functionality. Social chats may be checked manually. Review each permission and disable any feature whose benefit doesn't justify its access.
Does McAfee Scam Detector work on iPhone and iMessage?
McAfee says suspicious SMS can be filtered on iPhone, but Apple's restrictions prevent the same automatic handling of iMessage. In the September 2025 AV-Comparatives review, iMessages needed to be copied or forwarded into the manual Check for scams route. Test the current app because Apple behavior and McAfee features can change.
Which email accounts does McAfee Scam Detector support?
The September 2025 test covered Gmail, Microsoft mail services such as Outlook, Hotmail, Live and MSN, and Yahoo. McAfee advertised up to ten addresses. Gmail received a McAfee Alert label, Outlook received a label and folder, and Yahoo used a folder in that test. Verify current provider support before linking a primary mailbox.
Can McAfee check QR codes before I open the link?
McAfee added on-demand QR safety checks in its 2026 Scam Detector update and says the destination can be assessed before you tap. That checks the encoded destination and threat signals; it can't prove a sticker belongs on a parking meter, that a merchant owns the page, or that a previously clean destination will stay safe. Inspect the physical code and verify the service independently.
Does McAfee Deepfake Detector detect every fake video?
No. McAfee describes the feature as detecting likely AI-generated or manipulated audio within video, using on-device processing on compatible hardware. It doesn't authenticate the speaker, fact-check the claim or guarantee detection of every visual edit, voice clone or live call. Treat an alert as a reason to stop and verify, and treat no alert as unknown rather than genuine.
What should I do if I clicked or gave information to a scam?
If you only clicked, close the page, enter nothing, inspect downloads and run an updated security scan. If you entered a password or code, use a clean device to change it, revoke sessions, enable strong MFA and contact the provider. If you sent money or granted remote access, call the bank immediately, try to stop payment, disconnect the device, preserve evidence and report the fraud.
WhatsApp, Instagram, Messenger and Telegram often need an on-demand check
The 2025 test found that WhatsApp messages on Android weren't scanned automatically and could instead be submitted through Check for scams. McAfee's 2026 update added clearer analysis for suspicious social messages and DMs, including linkless openers; its article tells users to take a screenshot and submit it. A vague “Hey” can therefore be analyzed, but coverage shouldn't be confused with invisible universal monitoring of every private chat.
Manual screenshot analysis is useful because romance, job, investment and sextortion scams often establish trust before sending a link. Capture enough conversation to show the request and context, but crop unrelated people, names, account numbers and intimate material. Never upload illegal content or a sensitive image merely to obtain a generic fraud opinion; preserve evidence through the appropriate platform or law-enforcement route.