NordLabs Launches NordBot: An AI Scam Checker That Lives in Your DMs
NordBot checks suspicious texts, links and images from inside WhatsApp, Telegram, Instagram, Messenger and X, free and without a subscription. The placement is smarter than the AI — and there's a reason to be careful with a “Safe” verdict.

Table of contents
NordLabs, NordVPN's experimental projects arm, has released NordBot — a free AI checker you message on the platforms where suspicious things actually reach you. Forward it a text, a link, or an image, and it replies with a verdict. No subscription required.
The AI isn't the interesting part. The placement is.
How it works
You send NordBot the content you're unsure about, on one of the platforms it supports:
- WhatsApp, Telegram, Instagram, Facebook Messenger — message the bot directly.
- X — tag AskNordLabs in a reply to the post you want checked.
It analyses text messages, URLs and images, and comes back with one of four signals: Safe, Suspicious, Dangerous, or AI generated. It only looks at what you actively send it — it isn't monitoring your inbox. Reddit support is reportedly on the way.
Why the delivery method matters more than the model
Every security guide, including ours, tells people to check a suspicious link before clicking it. Almost nobody does, and the reason is friction, not ignorance. Checking a link has meant leaving the app, finding a scanner you trust, copying a URL out of a message without accidentally tapping it, pasting it in, and interpreting a result page written for security professionals. That's six steps standing between a moment of doubt and an answer, and doubt doesn't last six steps.
NordBot collapses that to forwarding a message — an action people already perform reflexively, usually to a friend or a family group chat asking "is this real?" Replacing that group chat with something that answers in seconds, in the same app, is a real behavioural insight. Scams arrive in DMs; the checker now lives in DMs.
That's also why it's free and subscription-free. A tool that only works if you're already a customer can't intervene at the moment that matters.
The problem with a "Safe" verdict
Here's the part to be careful about, and NordLabs is upfront that the tool is experimental and can be wrong.
A scanner that returns Dangerous and is wrong costs you an inconvenience. A scanner that returns Safe and is wrong costs you the thing the scam was after — because you didn't just fail to catch it, you replaced your own caution with a machine's confidence. The person who checks a link and is told it's fine clicks it more readily than the person who never checked at all.
That asymmetry is why the framing "second opinion, not a replacement for good habits" is doing real work rather than legal throat-clearing. Treat Dangerous and Suspicious as reasons to stop. Do not treat Safe as permission to proceed. A brand-new phishing domain registered an hour ago is clean by every reputation-based measure precisely because nobody has reported it yet — and freshly-registered domains are the norm in phishing, not the exception.
We've made the same argument about what security tools genuinely cover in VPN myths: what a VPN cannot protect you from and can a VPN protect you from password leaks?.
"AI generated" is not a threat level
The four signals are worth a second look, because one of them isn't like the others. Safe, Suspicious and Dangerous describe risk. AI generated describes provenance — and the two don't map onto each other.
An AI-generated image can be a harmless meme your aunt forwarded. It can also be the profile photo anchoring a months-long romance scam, or a fake screenshot of a bank transfer. Same label, opposite implications. Getting "AI generated" back tells you where an image came from, not whether the message around it is trying to take your money — and on a four-point scale that otherwise reads as a severity ladder, that's easy to misread as "mildly suspect."
Worth knowing too: reporting suggests the image analysis leans partly on extracting and reading text inside the image. That's a sensible approach for the scam formats that actually circulate — fake invoices, fake delivery notices, doctored screenshots — but it is not general-purpose image forensics, and detecting synthetic imagery from pixels alone remains genuinely unreliable across the whole industry. Calibrate expectations accordingly.
Before you forward something to it
- Consider what's in the message. You're sending content to a third-party service for analysis. If the suspicious text contains a one-time code, an account number, medical details or someone else's private information, forwarding it is its own small disclosure. Screenshot and crop where it makes sense.
- The bot lives on platforms with their own accounts. Messaging it on WhatsApp or Instagram means the interaction exists in that platform's ecosystem too. Our overview of how privacy tools fit together covers where these boundaries sit.
- Verify impersonated senders out of band. If a message claims to be your bank, the answer isn't a scanner — it's calling the number on your card. No AI verdict beats a channel the attacker doesn't control.
- It's a checker, not protection. It doesn't block anything, it doesn't run in the background, and it doesn't replace antivirus or a password manager. It answers a question you thought to ask.
Where it fits
NordBot sits alongside the tooling in NordVPN's paid plans rather than replacing any of it — see our NordVPN review for what the subscription actually includes, and VPNs and AI privacy for the broader question of feeding your data to AI services.
Bottom line
NordBot is a small, smart product decision: put the safety check where the scam lands, make it free, make it work by forwarding a message. That removes the real barrier, which was never that people didn't know to check.
Use it the way it's meant to be used. A "Dangerous" verdict is a good reason to stop. A "Safe" verdict is not a good reason to continue — it's one input, from an experimental tool, into a decision you're still making yourself.


