How to Check a USDT Address Before You Accept Funds
A practical pre-payment workflow for screening a USDT counterparty: confirm the chain, preserve the report, and route uncertain results to review.
Before accepting USDT, confirm the network and screen the sender's public address while you can still pause the transfer. Record the result with its source and retrieval time, then apply your own review policy. A low risk result is evidence from one screening method; it does not guarantee that an exchange will accept the deposit.
USDT is issued on several networks. An EVM-looking address does not identify the network. Ask for the exact chain and token standard, such as ERC20 or TRC20, before you copy an address into a checker. BestChange's public checker separates the crypto address, asset choice, analyzer, and email fields, and its asset choices distinguish network-specific USDT variants. That is a useful model for the first control.
The pre-payment workflow
1. Write down the transfer you intend to receive
Capture the sender's address, the chain, the asset, the expected amount, and the counterparty's stated purpose. If the transfer already has a transaction hash, save it as a separate identifier. Confirming the chain first prevents a report about one ledger from being mistaken for evidence about another. The address format alone is insufficient; compare the address you received with the original conversation or invoice, and ask the sender to confirm the network in writing.
Screening a public address does not require a private key, seed phrase, wallet login, or transaction signature. Keep those credentials out of a screening form; requesting them is outside this workflow.
2. Run one check and preserve the evidence
Use a screening source that accepts the chosen chain and asset. Choosing the matching network keeps the screening input tied to the transfer you are actually considering. The Spawn's initial AML path is a manual request: use Request check, select the job, network, and expected volume, and add a Telegram username. Keep the address and any report for the follow-up; an operator confirms availability, scope, and price on Telegram before you share it. It is a request for a check, not a promise that an automated report or a completed result is already available.
When a report arrives, save its URL or identifier, provider name, version if shown, chain, asset, address, transaction hash if relevant, and retrieval timestamp. GetBlock advertises wallet and transaction screening through a dashboard and REST API, with a PDF export. Those are published product claims, not a test result from The Spawn. A marketplace can have different terms: BestChange asks for an address, asset, analyzer, and email, and shows its own listed analyzer prices. Treat a reseller's price and flow as separate from a direct API contract.
3. Read flags as separate facts
Read each warning by its category instead of collapsing everything into one word such as “dirty.” A sanctions match, a token blacklist entry, and exposure to a risky counterparty answer different questions. Read the direction, confidence or match explanation, and coverage period when the report provides them. A direct match needs a different review from indirect exposure several hops away.
Missing coverage and timeouts are unknown states, so neither is a pass. Keeping that state visible prevents an incomplete query from becoming an accidental acceptance. If a report shows a high-risk flag, pause the transfer and send the case to the person or policy that handles these reviews. A route change intended to alter the score would undermine the review; leave the transfer unchanged and never ask a provider to “clean” a result.
Evidence to keep with the transfer
| Field | Record | Why it matters |
|---|---|---|
| Network and asset | Chain, token standard, and USDT variant | The same address shape can exist on different networks |
| Counterparty | Public address and stated purpose | Gives the reviewer the identity context you actually received |
| Screening input | Address or transaction hash, plus query time | Makes the check reproducible at that point in time |
| Output | Categories, explanations, score scale, and unknowns | Keeps evidence separate from an internal decision |
| Decision | Accept, pause, or review, with policy owner | Shows what happened after the report |
Download the AML screening checklist CSV and attach it to your transfer record. It is designed for a single review, so a later reviewer can see what was checked and what still needs an answer.
What a “clear” result can and cannot tell you
Blockchain screening depends on the provider's data, attribution, list updates, and lookback rules. A report may be useful without being complete. Sanctions controls also depend on the relevant jurisdiction and facts of the transaction. OFAC's virtual currency guidance, published October 15, 2021, describes tailored, risk-based sanctions compliance guidance. It does not create a universal score threshold for every wallet or business.
Read how to interpret an AML risk score for report evidence, or continue to the crypto AML API selection guide when choosing a repeatable integration; both explain where a manual check ends and an internal review or engineering contract begins.
Sources
- BestChange cryptocurrency address AML check (public input fields, networks, and marketplace terms checked September 16, 2026)
- GetBlock Crypto AML (published screening surfaces and report/export claims checked September 16, 2026)
- OFAC virtual currency sanctions guidance announcement (risk-based guidance, October 15, 2021)
