Anti-phishing statement
Last updated 2026-08-14
Kytelink has been used to run phishing pages. Not as an edge case — at volume, for a long stretch of the product's first version. This page is our public account of it: what went wrong, what we rebuilt, and exactly how every page published on kytelink.com is reviewed today. It describes the system that is actually running, in the detail needed to check the claim.
Section 01
What went wrong
The first version of Kytelink gave anyone a free, instantly public page on a domain that had built up real reputation. That combination is attractive to scammers, and they took it. The recurring pattern was impersonation: a page dressed up as a telecom provider, an internet provider, a bank, a delivery service, or a crypto exchange — usually posing as its support desk, login screen, account-verification step, or recovery flow — with links pointing at credential-harvesting sites.
The underlying failure was structural, not accidental. Moderation in the first version was reactive: a page went live the moment it was published and stayed live until a human happened to report it. Nothing was checked at publish time, and nothing re-checked a page that was published clean and then quietly edited into a phishing page afterwards. That second gap is the one most abuse actually walked through.
We are stating this plainly rather than quietly patching it, because anyone deciding whether to trust a kytelink.com link deserves to know both what happened and what specifically changed.
Section 02
What changed
Kytelink has been rebuilt from the ground up. The rewrite touched everything — the editor, the publishing pipeline, the infrastructure — and the anti-phishing review layer is part of the publish path itself, not a scanner bolted on afterwards.
Three things are different in kind, not degree. Every publish is reviewed, not just the first one, which closes the publish-clean-then-edit hole. Automated checks are deliberately tuned to under-block — no pattern match can suspend a page on its own, and a machine's decision is provisional. And every suspension is reviewed by a person, who is the only one who can uphold it or lift it.
Before the rewrite opened to the public, every profile carried over from the old version was re-reviewed by the same pipeline. Known phishing entered launch day already suspended rather than waiting to be reported.
Section 03
How a review works, end to end
A review runs on every publish — manual, scheduled, or triggered by an admin re-review. It moves through a content fingerprint, a set of free deterministic checks, an AI pass over whatever survives them, and then, for anything suspended, a human.
Review pipeline
How every Kytelink page is reviewed before and after it goes live
- 1Trigger
A page is published
Every publish starts a review — the first one and every one after it, whether it was published by hand, released on a schedule, or re-checked by an admin.
- 2Fingerprint
The content is fingerprinted
A hash of the username, display name, bio, every link title and URL, icon URLs, avatar, and redirect target. Reviewing is cheap enough to do on every publish because identical content is never re-reviewed.
Fingerprint unchanged and already reviewed → the stored verdict is reused. A reused verdict can never lift a suspension.
- 3Automated · stage one
Deterministic checks flag, they never suspend
Two pattern checks that cost nothing and run in milliseconds, both about where a page sends people. Naming a company is not one of them, and none of them can take a page down.
- IP-logger blocklist
- Brand lookalike & punycode domains
- Big-company support claim
Match → mandatory AI review on the stronger model, never served from cache, with the evidence attached: which check fired, the exact URLs, the brand, the decoded punycode.
- 4Automated · stage two
AI review — the only thing that can suspend a page
A multimodal call returns a structured verdict — approve or suspend, plus categories, a confidence score, a written reason, and exactly which signals fired. It suspends for two things: big-company support impersonation, and explicit content. Flagged pages arrive with the evidence and the brand's official domains, and the model has to confirm the flag rather than defer to it.
- Profile text
- Every link URL
- Redirect target
- Avatar image
- Flagged evidence
- Official brand domains
Ambiguous, under the confidence threshold, or the provider errored → approved and logged for a human. Every suspension clears that threshold; there is no exemption for a pattern hit.
Verdict
Approved
The page stays live. The verdict, its confidence, and every signal that was evaluated are recorded against that exact version of the content.
Suspended
The public page is replaced by a notice and de-indexed, images are pulled off the CDN, the page goes read-only, pending schedules are held, and the owner is emailed the reason and the appeal link. Nothing is deleted.
- 5Human gate
A person reviews every suspension
Each suspension opens a case carrying the verdict, the confidence, the written reason, and the signals that fired. A reviewer restores the page or upholds the suspension. Nothing is automated here.
A suspension stays until a person reviews it. It is never lifted automatically, and never by the owner re-publishing.
- 6Appeal
You can always reach a human
The suspended page, the editor banner, and the email all carry the same appeal path: the form at kytelink.com/appeal. No account needed. If we got it wrong, the page is restored with its content intact.
Section 04
Step one: the content fingerprint
Each review starts by fingerprinting the published content — a hash over the username, display name, bio, every link title and URL, icon URLs, the avatar, and the redirect target. If that fingerprint is unchanged from a version already reviewed, the stored verdict is reused instead of re-running the checks.
This exists so that reviewing every single publish stays affordable. It is deliberately narrow: any edit to any reviewed field produces a new fingerprint and a fresh review, and a reused verdict can never lift a suspension.
Verdicts also carry the publish they reviewed. If a newer publish lands while a review is in flight, the older verdict is discarded rather than applied — a verdict is never enforced against content it did not actually see.
Section 05
Step two: deterministic checks, which flag but never suspend
Before any model is involved, the content runs through pattern checks that cost nothing and complete in milliseconds. Not one of them can take a page down. No page on Kytelink is suspended by a pattern match — every suspension is a model's verdict, above a confidence threshold, and these checks decide which pages that model has to look at hardest.
Two of them fire, and both are about where a page sends people rather than what it calls itself:
- A link or redirect target on the blocklist of known IP-logger and visitor-grabber services.
- A lookalike of a major brand's domain in any link or redirect: punycode and internationalized labels are decoded before matching, then homoglyph substitutions (zero for the letter o, one for l, rn collapsed to m, Cyrillic characters that render as Latin ones), one-character typosquats, and a brand name glued to a capture word — claiming to be Apple while linking to apple-support.com rather than apple.com. A brand's own domains never match, on any country ending or subdomain.
Section 06
What a flag actually does
A flagged page — either of the checks above, or a page presenting itself as a major company's support, account-recovery, billing, or refunds desk — is sent for mandatory AI review. That review is skipped for nothing: not for a cached verdict, not for content that was reviewed before. It runs on the stronger of our two models, and the evidence goes with it: which check fired, the exact URLs, the brand the domain reads as, and what the punycode decoded to.
The model's instruction on that evidence is to verify it, not to rubber-stamp it. These patterns usually do mean fraud, and it should confirm and suspend when they do. But if the page explains them — a security researcher documenting the very scam that fired the check, a link quoted as an example, an ordinary site the pattern misread — it approves and says why. That is the whole reason no pattern is allowed to ban anyone: we would rather leave the last word with something that can read the page than with a string match.
For brand claims the question is authenticity, not vocabulary. Big companies are welcome on Kytelink, some of them are here, and automatically banning a real one because it wrote its own name would be the worst mistake this system could make. The model is given that brand's official domains: if every link and the redirect resolve to them, the page is approved. If the page claims to be that company's support desk while routing people off those domains — to a login or payment page on another host, a number to call, a chat handle to message — that is the fraud shape, and it is suspended. Naming a brand for an ordinary reason, reselling, repairing, reviewing, having worked there, is approved.
Section 07
What never gets a page flagged at all
A link shortener. An unusual top-level domain. A free consumer mail address as the contact or support address. The word support on a page. A big company's name mentioned in passing. Each of those used to be able to suspend a page outright, and none of them can now.
They are kept as advisory context instead: attached to the review, shown to the model, and visible to a human reviewer, but never sufficient on their own and never additive into a suspension. Most pages on Kytelink belong to founders, small businesses, clinics, schools, and creators, and those signals fire on them constantly. Treating them as evidence took real businesses offline, which is a worse outcome than the abuse it caught.
Section 08
Step three: the AI review
Every page reaches a multimodal model call on the hosted service — the flagged ones and the ordinary ones alike, because this is the only step that can suspend anything. It receives the profile text, every link URL, the redirect target, the avatar image, and whatever the checks flagged, and must return a structured verdict: approve or suspend, plus categories, a confidence score, a written reason, and which specific signals fired. The response is schema-enforced, so a verdict is always machine-checkable and always logged with its reasoning.
Two models sit behind this. Routine reviews run on the smaller one. The stronger one takes every flagged page — pattern hits and brand claims — and any suspend the smaller model returned without enough confidence, in which case the stronger model's verdict is the one that counts. The model that decided a review is recorded on it.
The policy it applies is short. Two things are suspendable: impersonating a large company — telecom providers most of all, then banks, payment providers, delivery companies, and crypto exchanges — by posing as its support, account-recovery, billing, or verification channel and routing people somewhere to be captured; and pornography in the open, meaning hardcore material on the page itself, links that land directly on explicit content anyone can view without a login, or pages that exist only to aggregate porn links. Everything else approves. The company itself approves. A real business running its own support page under its own name approves. Suggestive-but-not-explicit content approves. A crypto link on its own approves. Any lawful business approves, however unusual it looks.
Its calibration is the part worth stating explicitly: ambiguity approves. A suspend verdict is only applied if the model's own confidence clears a set threshold — with no exemptions, including for pages a pattern check flagged; below it the page stays up and the verdict, its reasoning, and its signals are still recorded for a person to see. We would rather miss a bad page and catch it through human review or a report than take down a legitimate one, so the model is instructed not to be trigger-happy and to approve whenever it is unsure.
If the provider fails, the call is retried and then fails open — the page is approved, flagged for follow-up, and an internal alert is raised. An outage at a vendor must not silently freeze publishing for everyone, and those pages land in the human queue regardless.
Section 09
Step four: the human gate
Automation can suspend a page. It cannot do anything more than that. Every suspension — whether it came from a deterministic hit, the model, a sweep, or a report — opens a case for a person, carrying the verdict, the confidence, the written reason, and the exact signals that fired.
A reviewer then restores the page or upholds the suspension. Suspension is the only enforcement outcome there is: nothing is deleted, nothing is permanent by default, and a suspension stays in place until a person has looked at it. It is never lifted automatically either — not by a cache hit, not by re-publishing, not by any action the page's owner can take on their own. A suspension lifts in exactly two ways, both started by a person: a reviewer restores the page, or a reviewer re-runs the review from the admin tools and it comes back clean. Every decision is written to an audit log with the reviewer and their stated reason.
Admins can also open a case by hand on any page, with a note, without waiting for automation or a report.
Section 10
What a suspension actually does
A suspension is immediate and comprehensive. The public page is replaced by a plain notice and marked no-index, no-follow so it drops out of search. Uploaded images and the avatar are quarantined off the CDN, so the assets stop being reachable even by direct link. The page becomes read-only for everyone on the account — no edits, publishes, uploads, or new preview links — and any scheduled publishes are held.
Suspensions come at three scopes: a single page, an organization (which takes every page in it offline), or an account (which suspends every organization that account owns). The wider scopes are for repeat or account-level abuse rather than one bad page.
A suspended account can still sign in. It is read-only, not locked out — the whole point is that the person can still read their own data, see the recorded reason, and appeal. Nothing is deleted, and no suspension expires on its own: it stays until a person reviews it, and restoring brings everything back exactly as it was.
The owners of the account are emailed with the reason and a link to the appeal form.
Section 11
Appeals
There is one appeal path, and it is the same in every place a suspension appears — the public notice, the banner in the editor, and the email: the form at kytelink.com/appeal. No account needed, it works for a page, an organization, or an account, and a person reads every one. We answer them fast, because a wrongly suspended page is our mistake to fix, not yours to wait out.
We accept that under-blocking means some legitimate pages will still be caught. When that happens the fix is a restore, and the page returns with its content, links, and analytics intact.
And if you would rather not depend on our judgement at all, you don't have to. Kytelink is open source under the MIT License — running your own copy is always an option, and nothing on this page applies to it.
Section 12
Reporting a page
Anyone can report a Kytelink page at kytelink.com/report, without an account. Tell us the username and what you saw.
Reports never automatically suspend anything, and that is deliberate — an auto-suspending report button just hands the takedown control to whoever files the most reports. A report opens a case in the same human review queue, where it is treated as a request to suspend and decided by a reviewer.
The form always responds the same way regardless of what you submit. It will not confirm whether a username exists, so it cannot be used to probe the platform.
Section 13
What this statement does not cover
This describes the hosted service at kytelink.com. That is the only domain it covers.
Kytelink is open-source software under the MIT License, and anyone can run their own copy. Self-hosted instances ship with the review provider turned off by default and are operated entirely by whoever runs them — we do not review, monitor, or have any control over pages on someone else's deployment. A page is only covered by this statement if it is served from kytelink.com.
The code that performs everything described here is in the public repository, including the keyword lists, the lookalike-domain detection, the review pipeline, and the exact policy given to the model. You do not have to take this page's word for any of it.
Section 14
Limits we will state plainly
No review layer catches everything, and one tuned to avoid wrongful takedowns catches less than a maximally aggressive one would. Some phishing will get through the automated pass. Reports and human review are how it gets caught, and that is the intended design rather than a gap in it.
Reviews evaluate link destinations as they are at publish time; we do not continuously crawl the sites a page links to. A destination that is clean when reviewed can be changed on the other end afterwards. If you see that, report the page and a person will look at it.
We will keep publishing changes to this system here. If the review pipeline changes materially, this page and its date change with it.
Section 15
Contact
Report a page at kytelink.com/report. Appeal a suspension at kytelink.com/appeal.
For anything else about this statement, including security disclosures and press enquiries, email [email protected].
Frequently asked questions
- Is Kytelink safe to click?
- Every page published on kytelink.com is reviewed on every publish — not only the first one. A short set of deterministic phishing checks runs first and flags what it finds, then an AI review of the profile text, every link, the redirect target, and the avatar decides the verdict; nothing is suspended by a pattern match alone. Any suspension is then reviewed by a person. Treat a link the way you would any link on the open web: Kytelink never asks for your password, banking details, or account-recovery codes, and a Kytelink page that does is phishing — report it.
- Did Kytelink have a phishing problem?
- Yes. The first version of Kytelink was abused at volume for phishing, mostly pages impersonating telecom providers, internet providers, banks, delivery companies, and crypto exchanges. Moderation was reactive: pages went live unchecked and stayed live until reported, and nothing re-checked a page that was edited into a phishing page after publishing. The product has since been rebuilt from the ground up with review built into the publish path.
- How does Kytelink detect phishing pages?
- In two automated stages plus a human one. Stage one is deterministic and flags rather than decides — a link pointing at a known IP-logger service, a lookalike of a major brand's domain (punycode decoded, homoglyph substitutions, one-character typosquats, or a brand name glued to a capture word, like apple-support.com standing in for apple.com), or a page presenting itself as a big company's support desk. A flag never suspends anything: it forces the page into stage two, on the stronger of our two models, never served from cache, with the evidence attached for the model to verify rather than assume. Stage two is that multimodal AI review of the profile text, every link, the redirect target, and the avatar, returning a schema-enforced verdict with categories, confidence, a written reason, and the signals that fired — and a suspension only applies if the confidence clears a threshold, with no exemption for a flagged page, so an unsure verdict approves and is logged instead. Stage three is a person, who reviews every suspension.
- What if my company's real support page gets flagged?
- It gets verified, not banned. No automated check suspends a page at all, and certainly not for naming a company — big companies are welcome here, and some of them use Kytelink. A page presenting itself as a large company's support or account-recovery desk is flagged for a mandatory AI review that cannot be skipped or served from cache, runs on the stronger of our two models, and is handed that brand's official domains to compare against. If your links resolve to your own domains, you are approved. What gets suspended is the opposite shape: a page claiming to be a company while sending visitors off to a login, payment, or verification page that company does not own, a number to call, or a chat handle to message.
- What will not get a Kytelink page suspended?
- Ordinary business pages, which is nearly all of them: clinics, dental and medical practices, schools, local trades, agencies, restaurants, and startups running their own support page under their own name. A crypto wallet address or token link on its own. A Gmail or other free-mail address as your contact or support address. A link shortener, an unusual domain ending, a one-link page, a non-English page, affiliate marketing, or a big brand's name — mentioned because you resell, repair, or review it, or because the brand is you. Those are context a reviewer can see, never grounds for an automatic suspension on their own. The automated layer suspends for two things only, and only ever on a confident AI verdict: impersonating a large company's support or account-recovery channel, and explicit sexual content.
- Can a page be taken down permanently and automatically?
- No. Suspension is the only enforcement outcome, it is reversible, and it preserves all data. Automation can suspend a page; only a human reviewer decides whether the suspension stands, and only a human reviewer can lift it — never a cache hit, a re-publish, or any action the page owner takes on their own. It lifts in exactly two ways, both started by a person: a reviewer restores the page, or a reviewer re-runs the review from the admin tools and it comes back clean. A suspended account can still sign in; it is read-only, not locked out.
- How do I appeal a suspended Kytelink page?
- Use the form at kytelink.com/appeal — no account needed, and it covers a suspended page, organization, or account. It is the same appeal path shown on the suspended page, in the editor banner, and in the suspension email, a person reads every one, and we answer fast. If the suspension was wrong, the page is restored with its content, links, and analytics intact.
- How do I report a phishing or scam Kytelink page?
- Report it at kytelink.com/report — no account needed. Reports never automatically suspend a page; they open a case in the same human review queue where a reviewer decides. The form gives the same neutral response no matter what you submit and will not confirm whether a username exists.
- Does this apply to self-hosted Kytelink instances?
- No. This statement covers the hosted service at kytelink.com only. Kytelink is MIT-licensed open source, and self-hosted copies ship with the review provider off by default and are operated entirely by whoever runs them.