NordBot by NordVPN: Does the free AI checker work?

NordBot is a free, experimental AI agent developed by NordLabs that checks suspicious texts, URLs, and images for scams directly within your existing social media apps. It serves as a frictionless verification utility for everyday users and provides a simple way to protect less tech-savvy relatives. NordBot is entirely free to use and requires zero additional app installations on your device.

In this complete guide, we will show you exactly how to set up the bot on your favorite messaging platforms, share our real-world test results, and uncover its technical blind spots.

Key takeaways:

  • NordBot is 100% free to use and does not require a paid NordVPN subscription or a separate native app download.
  • NordBot operates entirely within 5 supported platforms (WhatsApp, Telegram, X, Instagram, and Facebook Messenger) with Reddit support coming soon.
  • NordBot categorizes scanned content into distinct safety signals (such as Safe, Suspicious, Dangerous, and AI-generated).
  • In our hands-on testing, NordBot successfully detected zero-day phishing links and AI images, returning verdicts in under 1 minute.

Privacy warning: Because NordBot processes data via third-party social platforms like Meta and X servers, users should avoid sending plain-text passwords or highly sensitive personal documents.

1. What is NordBot?

NordBot is an experimental AI-powered verification agent developed by NordLabs. NordBot acts as a multimodal security scanner capable of analyzing incoming text messages, web URLs, and images for potential threats. NordBot’s primary function is to provide an objective second opinion on suspicious digital content before you interact with it.

There is no standalone application or executable file to download. NordBot lives entirely inside your existing chat applications as a specialized contact.

This design eliminates installation friction and makes the checking process immediate. You simply forward a questionable message directly into the chat thread for rapid analysis.

NordBot is completely free for everyone to access. You do not need to create an account, provide payment details, or hold an active NordVPN subscription to utilize NordBot’s core scanning features.

2. Understanding NordBot’s common safety signals

When you forward content to the chat interface, NordBot processes the data and categorizes it into one of four core safety signals. Depending on whether you send a text, a link, or an image, you might notice the bot using slightly different chat phrases (like returning “Looks real” instead of “Safe”, or “Likely scam” instead of “Dangerous”).

However, these are simply contextual variations that all map back to the four main threat levels outlined below.

Core Safety SignalMeaning & Threat LevelTypical Triggers & Variations
🟢 SafeThe content does not show clear signs of danger.Triggered by standard link shares or authentic photos. (Often outputs as “Looks Safe” or “Looks real”).
🟡 SuspiciousThe content contains conversational elements that deserve caution.Triggered by urgent language or panic-inducing text (FOMO), even if the attached URL is clean.
🔴 DangerousThe content is actively deceptive or contains malware.Triggered by phishing pages, fake delivery notices, or malware. (Often outputs as “Likely scam” or “Likely dangerous”).
🔴 AI GeneratedThe visual content shows strong markers of artificial generation.Triggered by deepfake images or highly manipulated digital media. (Outputs as “Likely AI”).

The Safe signal confirms that the content does not exhibit explicit scam markers. During our testing, NordBot accurately applied this categorization to routine password-reset emails, standard news article links, and authentic, unedited photos.

Conversely, the Suspicious signal indicates that the content operates in a gray area. NordBot triggers this specific warning when a message utilizes pressure-heavy warnings (like a Rickroll trap) or panic-style bargain pitches, even if the destination URL is completely legitimate.

For more severe threats, NordBot returns a Dangerous signal. You will usually see this manifest as a “Likely scam” warning for deceptive attempts to steal information (like remote job scams or fake USPS texts). However, if you feed it a known malware signature, it upgrades the warning to a strict “Likely dangerous” alert, advising you not to run the file.

Finally, the AI-generated signal appears when a visual file shows clear signs of artificial creation.

However, you should treat NordBot as an objective second opinion before clicking, rather than a flawless lie detector.

3. How to access NordBot on every platform (step-by-step guide)

Connecting to NordBot requires slightly different steps depending on the social platform you prefer to use. You can use the master reference table below to find the correct contact information, and then follow the specific configuration steps for your chosen application.

PlatformOfficial Handle / Phone NumberAccess Method
WhatsApp+1 940-616-6302Add as a new contact and start a Direct Message.
Telegram@asknordbotSearch handle and start a Direct Message.
X (Twitter)@asknordlabsSend a Direct Message OR tag the handle in a public reply. 
Instagram@asknordlabsSend a Direct Message.
Facebook MessengerAsk NordVPNSend a Direct Message.

3.1. WhatsApp: Setting up the +1 940-616-6302 contact

Adding NordBot to WhatsApp functions exactly like adding a standard personal contact. To begin your setup:

  1. Open WhatsApp on your mobile device or desktop.
  2. Tap the New Chat icon located on the main screen.
  3. Select the New Contact option.
  4. Enter +1 940-616-6302 into the phone number field.
  5. Save the contact exactly as “NordBot”.
  6. Paste the suspicious text or link directly into the chat to receive a safety verdict.
How to access NordBot on WhatsApp
How to access NordBot on WhatsApp

3.2. Telegram & X: Summoning @asknordbot and @asknordlabs

To configure Telegram, follow these steps:

  1. Open the Telegram app.
  2. Search for @asknordbot in the main search bar at the top of the screen.
  3. Tap Start to initiate the conversation with NordBot.
How to access NordBot on Telegram
How to access NordBot on Telegram

For X (formerly Twitter), the integration provides two flexible options depending on whether you want a private check or a public warning for others.

To scan content on X, choose one of these methods:

  • Method 1 (Private Check): Search for @asknordlabs and send the suspicious link, text, or image directly to the bot via a Direct Message (DM).
  • Method 2 (Public Tag): If you see a questionable post on your timeline, simply reply to that public tweet and tag @asknordlabs. NordBot will evaluate the content and reply with an automated public safety verdict for everyone to see.
How to access NordBot on X
How to access NordBot on X

3.3. Instagram & Facebook Messenger integration

For the remaining Meta platforms, the setup relies on a direct search. Follow these steps:

  1. Open the respective Messenger application (Instagram or Facebook Messenger).
  2. Search for @asknordlabs on Instagram, or search for Ask NordVPN on Facebook Messenger.
  3. Open the direct message thread.
  4. Forward the suspicious meme, image, or link directly into the chat for a rapid scan.
How to access NordBot on Facebook Messenger
How to access NordBot on Facebook Messenger

4. Field test: Putting NordBot’s scam detection to the test

To evaluate NordBot’s actual utility, we tested NordBot directly across multiple messaging platforms. Across all tested platforms, NordBot successfully returned a verdict in under 1 minute.

This extremely fast response time enables an ideal “Parental Shield” workaround. You can set NordBot up on the phones of elderly parents and instruct them to forward links instead of clicking them.

NordBot provides a safety verdict directly in the chat, keeping the user from accidentally opening a harmful web page.

4.1. Test 1: The SMS delivery phishing link

For our first scenario, we wanted to see how NordBot handles classic package delivery scams, so we forwarded a fake USPS redelivery SMS containing a masked URL directly to the chat.

The message we forwarded:
"[USPS-Notice] Your package cannot be delivered due to an incomplete shipping address. Please update your address within 24 hours to avoid package return: https://usps.redelivery-notice-hub.com/track Please reply Y then exit text and reopen the link."
NordBot's reply:
"🔴 Likely scam. A fake delivery notice is pushing a deadline and a lookalike shipping link to harvest personal information. Stop — don't open that link or reply; verify the delivery only through the official carrier app or site."
Test 1: The SMS delivery phishing link
Test 1: The SMS delivery phishing link

By forwarding the message directly into the chat, you create a safe buffer. NordBot analyzes the look-alike URL alongside the urgent context of the text, returning a ‘Dangerous’ verdict.

This allows you to identify the phishing attempt immediately without ever clicking the link and exposing your browser to potential malware.

4.2. Test 2: The “urgent” account verification text

We next tested a classic social engineering attack by submitting a fake PayPal login prompt.

The message we forwarded:
"URGENT: We have detected unusual login activity on your PayPal account. To prevent permanent suspension, please confirm your account details immediately by logging in here: http://www.secure-paypal-update-247.com/login. If you do not verify within 24 hours, your account will be locked."
NordBot's reply:
"🔴 Likely scam. A fake account-alert message uses urgency and a look-alike login link to steal credentials. Stop — don't open that link or enter any details; check your account only through the official app or site."
Test 2: The "urgent" account verification text
Test 2: The “urgent” account verification text

NordBot accurately evaluated the deceptive link and the high-pressure text. NordBot returned a Likely scam verdict and advised the user to check their official application instead of trusting the message.

4.3. Test 3: The malware signature (EICAR test)

We evaluated how NordBot handles direct malware triggers by feeding NordBot the standard EICAR antivirus test string.

The message we forwarded:
"X5O!P%@AP[4\PZX54(P^)7CC)7}$EICAR-STANDARD-ANTIVIRUS-TEST-FILE!$H+H*"
NordBot's reply:
"🔴 Likely dangerous. The post contains the antivirus test string, which is a malware-detection trigger rather than harmless chat. Stop — don’t open or run it; treat it as a malware test file."
Test 3: The malware signature (EICAR test)
Test 3: The malware signature (EICAR test)

Instead of issuing a generic scam warning, NordBot successfully recognized the exact test string and returned the specific Likely dangerous label, clearly advising us to treat the input as a direct threat. 

4.4. Test 4: AI-generated deepfake images

Our final test involved uploading an AI-generated photo directly to NordBot.

The visual file we uploaded:
[ Uploaded an AI-generated portrait ]
NordBot's reply:
"🔴 Likely AI. The only strong signal is that image #1 is AI-made, while the text on it is clean and too little to change that. Stop — don’t treat this image as authentic proof."
Test 4: AI-generated deepfake images
Test 4: AI-generated deepfake images

NordBot successfully processed the visual file and provided a clear warning, demonstrating its capability to assess standalone images.

However, because the AI heavily analyzes the text embedded inside an image, it excels at flagging fake giveaway memes but may struggle to perfectly identify a purely visual, pixel-level deepfake photograph of a person. Do not treat it as a flawless deepfake lie detector.

5. NordBot’s blind spots: False positives & privacy realities

While NordBot’s core detection engine is robust, relying on a Large Language Model (LLM) for text analysis creates specific friction points. NordBot is prone to hyper-sensitive context triggers.

NordBot sometimes flags safe URLs as dangerous because NordBot misinterprets classic conversational motifs or sensationalized language.

Beyond detection flaws, users must also consider the inherent privacy trade-offs. Using a cloud-based AI on social media platforms means your queries do not remain entirely private.

5.1. The problem with clickbait and shortened links

During our evaluation, we discovered that NordBot can be easily tricked by extreme clickbait keywords. NordBot often equates sensationalized language with actual malware.

For example, we tested a legitimate entertainment article link (http://trib.al/jEpQ9n) but accompanied it with highly sensationalized “bait” text. 

The message we forwarded:
"OMG LEAKED VIDEO 😱 Z- just got caught doing the unthinkable backstage! HBO is trying to scrub this from the internet. Watch the uncensored footage before it gets taken down permanently!!! 🔞👇 http://trib.al/jEpQ9n"
NordBot's reply:
NordBot returned a 🔴 Likely scam verdict, incorrectly classifying the post as a "fake celebrity-leak post".
NordBot falsely flags a safe link due to clickbait text
NordBot falsely flags a safe link due to clickbait text

Instead of recognizing the safe destination link and returning a Suspicious signal just for the clickbait text, NordBot falsely labeled the entire post as a scam.

We observed a similar error when sending a basic curiosity text using a standard URL shortener.

The message we forwarded:
"Hey, is this you in this picture? Someone just sent it to the group chat. https://bit.ly/3y8FkO0"
NordBot's reply:
"🔴 Likely scam. The post uses a curiosity-bait message with a shortened link that scam analysis flags as phishing. Stop — don’t click that link; verify the sender through a separate trusted channel."
NordBot labels a safe link as a scam
NordBot labels a safe link as a scam

In both cases, NordBot immediately returned a Likely scam verdict. NordBot relied entirely on recognizing the classic phishing sentence structures (curiosity and panic) and failed to actually unpack the shortened links to verify the destinations.

What you should do: Users must manually cross-reference overly sensational messages rather than treating NordBot as an absolute malware scanner in these edge cases. When you receive a red flag on a bit.ly or trib.al link accompanied by clickbait text, do not panic. Instead, you should copy the link and paste it into third-party tools like ExpandURL, WhereGoes, or CheckShortURL to objectively inspect the final destination link yourself. 

  • ExpandURL: https://www.expandurl.net/
  • WhereGoes: https://wheregoes.com/
  • CheckShortURL: https://checkshorturl.com/

5.2. Privacy friction: Sending DMs to an AI

A prominent concern within the privacy community is NordBot’s integration method. Many users state they would prefer a native application instead of interacting via social platforms.

The reality of NordBot is that you are transmitting data through third-party servers owned by Meta and X.

Because of this infrastructure, you must strictly control what you submit to NordBot. Never forward plain-text passwords, one-time passcodes (OTPs), or highly sensitive personal documents to NordBot.

NordBot is designed strictly to verify untrusted external content, not to audit your personal data.

6. FAQs about NordBot

Is NordBot completely free to use?

Yes, NordBot is 100% free to use on all platforms. You do not need to provide a credit card or create a user account to access NordBot’s scanning features.

Do I need a NordVPN subscription to use NordBot?

No, NordBot operates entirely independently of the paid NordVPN ecosystem. You can utilize NordBot without purchasing a VPN plan.

What is the official NordBot WhatsApp number?

The official, verified business number for NordBot on WhatsApp is +1 940-616-6302. You simply save this number to your contacts to start forwarding messages.

Is there a standalone NordBot app or software?

No, there is no separate executable file or mobile application to download. NordBot is purely an API integration living inside social messaging apps to reduce setup friction.

Can NordBot detect deepfakes perfectly?

No, no artificial intelligence tool is infallible. NordBot acts as a helpful second opinion for spotting AI-generated content, but you should not treat NordBot as a flawless lie detector.

7. Conclusion

NordBot serves as a highly effective, zero-cost triage tool for checking daily phishing attempts and fake SMS deliveries. By evaluating links and text on the backend, NordBot prevents you from risking a misclick in a vulnerable web browser.

However, while NordBot is excellent as a primary filter, you still need to apply manual human judgment. This is especially true when dealing with alarming messages from seemingly trusted contacts or obvious clickbait that frequently triggers false positives.

NordBot’s greatest strength is its zero-install nature. This frictionless design makes NordBot the perfect cybersecurity shield to set up on the phones of less tech-savvy relatives.

We recommend opening WhatsApp right now, adding NordBot’s official number (+1 940-616-6302), and saving it to your contacts so NordBot is ready the next time a suspicious message arrives. 

While NordBot is a helpful free tool for checking suspicious links, it only scans what you manually forward to it. If you are interested in broader privacy features like connection encryption or automatic malicious website filtering, read our full NordVPN review to understand what the main application actually offers.

To build a comprehensive digital safety foundation beyond just using NordBot, explore our in-depth guides in the Privacy & Security Basics hub and visit the Safelyo homepage today.

  1. Meet NordBot: NordLabs’ AI agent for checking suspicious content

    https://nordvpn.com/blog/nordbot-suspicious-content-checker/

Leave your comment

There are no reviews yet. Be the first one to write one.

Related Posts You Should Read

What is DNS spoofing?

What is DNS spoofing: how it works and prevention

Imagine typing your banking website perfectly into your browser but landing on an identical phishing page. This kind of silent redirection can happen without an...

What is ChaCha20

What is ChaCha20? A guide to fast VPN encryption

Every time you connect to a VPN, browse an HTTPS website, or send a secure message, your device must encrypt data instantly. If this mathematical...

What is IPv6?

What is IPv6: Meaning, benefits, and why it matters

Have you ever heard the alarming news that the internet has officially run out of addresses? This is not a tech myth; it is a...

Don't miss anything! Sign up for our newsletter

Always up to date with the latest news, promotions and reviews.

We respect your privacy. Your information is safe and you can easily unsubscribe at any time.