Where to check
When a strange message arrives, the question is always the same: is this real? This page collects the places where you can actually check, with one line explaining what each is for. They are all official sources or public tools, and none of them asks you to install anything.
One warning first: none of these sites will ever contact you out of the blue. If you get a message claiming to be from the police, from a national CERT or from your bank, asking you to click something, that message is already the scam.
Something suspicious just arrived
CERT-AGID, this week’s campaigns publishes a weekly list of the lures circulating in Italy, along with the brands being impersonated. If your text message mentions a refund, a fine or a parcel, chances are it is on that list. Italian only.
Commissariato di P.S. online is the Italian postal police website. Its news section carries plain-language warnings about current scams.
Report it online is where you flag what you received. Reporting is not the same as filing a criminal complaint: it is far quicker, and it is how ongoing campaigns come to light.
Check before you click
VirusTotal scans a link or a file with dozens of antivirus engines at once. Paste the suspicious link without opening it and see what they make of it. Never paste links that contain your own data, because the analyses stay public.
Google Safe Browsing site status tells you whether a site has been flagged as dangerous. It is the same check Chrome runs before showing you the red warning page.
Have I Been Pwned tells you whether your email address has appeared in a data breach. If it has, change that service’s password, and change any password you reused elsewhere.
Calls and messages you never asked for
Registro pubblico delle opposizioni is the Italian opt-out register for telemarketing, for landlines and mobiles alike. It is free and it is the official one. The ministry page explains how it works.
Italian Data Protection Authority is where you go when someone uses your personal data without permission and will not stop.
For those who want the raw data
This part is more technical and mostly useful to people who work in the field. In short: a CVE is the identifier given to a single security flaw in a piece of software, such as CVE-2026-1234. It exists so that everyone in the world refers to the same flaw by the same name.
CVE Program is the registry where flaws get their names. The source, without commentary.
National Vulnerability Database takes those CVEs and adds severity, affected versions and references. This is the archive people actually consult.
Known Exploited Vulnerabilities Catalog, run by the US agency CISA, lists only the flaws someone is already exploiting. Of all the lists, it is the most useful: it tells you what to fix first.
European Vulnerability Database is the European database run by ENISA, created so that Europe does not depend on a single source.
CSIRT Italia, part of Italy’s national cybersecurity agency, publishes advisories for the country and monthly reports on the state of the threat in Italy.
URLhaus collects the addresses currently distributing malware. For looking at, not for visiting.
If something is broken
We check these links, but sites move without warning. If you find a dead one, or you know a source that is missing here, write to us and we will add it.