A second opinion without signing in
Baker says the checker will be available in My security centre and from the app’s sign-in screen. People can paste a link or text, or submit an image, then read a result and an explanation. His examples include a green ‘Safe to continue’ result for a genuine South African Revenue Service link and a red ‘Do not continue’ warning for a fake courier link.
Putting the check before sign-in is a sensible choice. Someone worried about a message should not have to enter their banking account just to ask about it. Keeping it free also avoids making a basic safety check another subscription decision.
Those are design judgments, not evidence that the tool has prevented losses. The announcement describes the product and its internal testing; it does not provide a detection rate, a test-set denominator or an independent evaluation. We have not tested the app.
A real website can sit inside a dishonest conversation
The green SARS example has a narrow meaning: the link points to the genuine site. As Baker explains, it does not verify the sender, the surrounding story or what the person wants you to do next.
Imagine someone sending a real bank homepage to make a conversation look legitimate, then asking you to read out a one-time code. The website did not become fake. The request is still dangerous. That is an illustrative example, not a reported failure of Capitec’s checker.
Baker also names investment schemes as a harder problem: a polished site and persuasive story can hide the danger in the promised returns rather than in an obviously malicious link. He says the checker gives guidance, does not block actions and is not a guarantee or financial advice.
The words ‘Safe to continue’ deserve caution here. A person may hear permission to proceed with the whole conversation. The useful interpretation is smaller: read what was checked, and do not let the colour answer questions the explanation leaves open.
Leave the suspicious conversation to verify it
The US Federal Trade Commission’s existing phishing guidance recommends contacting a company through a phone number or website you already know is real, rather than the details supplied in the message. That advice concerns phishing generally, not this South African product, but it gives a practical next step when an AI result leaves you uncertain.
Open the bank app yourself, or use a contact route you have independently verified. Do not follow a supposed support link because the sender says it is where the scam checker lives. Capitec’s announcement likewise advises contacting the bank through its app or official channels, and never sharing PINs, passwords or one-time codes.
If someone says a payment must happen immediately, a green link result is no reason to accept the deadline. Verify the request separately before paying. If you have already shared credentials or sent money, contact your bank promptly through its official channel; another round of chatbot questions should not delay that call.
Teach the pause alongside the feature
For a family member trying the checker for the first time, show where it lives in the app and explain the green result before an urgent message arrives. The point is to make asking for help ordinary. Nobody should need to feel foolish for stopping to check.
Banks have a responsibility here too. If the result identifies a genuine domain, that limited finding should be easy to understand on the result screen, not only in a launch article. Support staff need to be ready for the customer who says, ‘It was green, so I thought it was okay.’ That sentence describes a foreseeable misunderstanding, not an observed complaint.
A free check at the moment of doubt is worth offering. The habit it should reinforce is taking a breath and verifying the request—not letting a colour finish the decision.