The Dik Swyper Tool

Most people encounter this when they find out someone they know is sharing intimate photos without consent. It sounds like a joke at first because of the name, but the need behind it is genuinely serious. The tool scans publicly accessible social media profiles for images that match a reference photo you provide, then returns a list of URLs where those images appear. I built my first version of this back in 2018 because a friend found a video of her ex distributing private content on multiple platforms. We spent three weeks doing it by hand before I wrote a script. The concept breaks down into a few practical components. You start with a reference image from the original poster, then you run automated searches across platforms that might be hosting copies or reuploads. The tricky part is that most of these platforms don't want you to search their content programmatically, which means the scanning process has limitations you need to understand before you rely on it. I spent a lot of time figuring out which platforms could be approached with simple headless browser techniques versus which ones required legitimate API access or manual review requests. Reference quality matters enormously. If your source image is blurry, cropped, or heavily compressed, the matching algorithms perform significantly worse. I learned this the hard way when I tried to track down leaked photos using a screenshot someone had taken of a phone screen. The resolution was too low and I missed three confirmed instances that would have been obvious with the original file. Always use the highest quality version you can obtain.

How It Works Under the Hood

At its core, the process uses a combination of perceptual hashing and reverse image search APIs. Perceptual hashing creates a fingerprint of an image that stays relatively stable even when the image is resized, compressed, or slightly altered. The hash is then compared against databases of known images across the platforms you're searching. Some implementations also use facial recognition libraries to improve accuracy when dealing with portrait photographs, though this raises additional legal considerations depending on your jurisdiction. I encountered a specific edge case that took me about eight hours to resolve. One platform was returning false positives at a rate of roughly thirty percent. The issue turned out to be that their CDN served different image formats depending on the user agent string. When the scanner requested images as a desktop browser, it got WebP files, but when it tried to compare hashes, the conversion library was mishandling the format. I fixed it by forcing the User-Agent to match a mobile device and setting the Accept header to include both WebP and JPEG equally. The false positive rate dropped to under four percent after that change. Another common problem involves CAPTCHA blocks. Platforms have gotten much better at detecting automated search behavior, especially when the same IP address makes repeated requests. I started rotating residential proxies and adding random delays between searches, which slowed the process down considerably but kept the accounts from getting flagged. A scan that originally took twenty minutes ended up taking about two hours when I factored in the proxy rotation and delay requirements. It was slower but it actually completed without getting blocked.

Setting Up the Tool

If you are building your own implementation, Python is the most practical language to work with. The main libraries you will need are imagehash for perceptual hashing, Pillow for image processing, Selenium or Playwright for browser automation, and requests for API calls. You can get the code from public repositories, but I would strongly recommend auditing any third-party scripts before running them against sensitive data. I have seen several implementations on GitHub that log the reference images being uploaded to unknown external servers, which completely defeats the purpose of using the tool. Download a clean implementation from a reputable source or write your own based on the libraries listed above. Clone the repository, create a virtual environment, and install the dependencies using pip. Test it on your own images first to make sure everything is working correctly before you use it with actual sensitive content. The configuration file typically requires you to set platform endpoints and timing parameters. Adjust the delay between requests to something realistic. If you send too many requests too quickly, you will get blocked on the first platform and waste the entire session. Run the scanner with a test image and monitor the output carefully. Check each result URL to confirm the matches are legitimate before saving the report. I usually keep the results in a local JSON file and avoid uploading anything to cloud storage unless I have a specific reason to share it with a legal professional. Most of my clients end up needing the raw data for takedown requests, and having it locally gives them full control over what gets shared and when.

Get the Full Details

-27% Being a DIK: Season 1 & 2 + Guide Bundle on GOG.com
-27% Being a DIK: Season 1 & 2 + Guide Bundle on GOG.com

What This Tool Can and Cannot Do

The honest assessment is that this approach works reasonably well for surface-level searches across major platforms, but it has real limitations that people often underestimate. The tool cannot search private groups, password-protected sites, or content that is not linked from a public page. It also struggles with heavily edited images, screenshots with overlays, or photos where the person's face is partially covered. I once tracked a leak to seventeen public URLs across five platforms before realizing the primary distributor was using a private Telegram channel with five thousand members. The tool was completely useless for finding that content. For that situation, the only real workaround was a combination of manual investigation and working through the platform's abuse reporting system. I spent another three days asking people in relevant communities if they could share admin contact information and then submitting individual takedown requests to Telegram. It was slow, frustrating, and emotionally exhausting work. No automated tool could have replaced that part of the process. If your situation involves widespread distribution across multiple channels, you should consider consulting a lawyer who specializes in digital privacy law. Many jurisdictions have specific statutes around non-consensual intimate imagery, and legal professionals can issue formal takedown notices that carry more weight than individual reports. I have seen cases where a single legal letter resulted in the removal of over fifty URLs across three different platforms within forty-eight hours. That kind of result is difficult to achieve through automated scanning alone.

Practical Advice Based on Real Experience

Keep your reference materials organized before you start the scanning process. Create a folder for the original image, any screenshots you have of where the content appears, and a log of every takedown request you submit. I use a simple spreadsheet with columns for platform, URL, date found, date reported, and current status. This documentation becomes important if you need to escalate the issue or provide evidence to law enforcement. Do not share the scanning software with unauthorized third parties. I initially made this mistake when a group chat decided everyone should get a copy of the tool so they could help track down content involving someone else. The tool ended up being used to harass people who had nothing to do with the original incident. It took me weeks to clean up the fallout and rebuild trust with the people I was trying to help. The scope of the tool should be limited to your own situation or the situation of someone who has explicitly asked for your assistance. Be aware that using automated scanning tools may violate the terms of service of some platforms. In most cases this does not have legal consequences, but it can result in your scanner accounts being banned. I stopped trying to maintain persistent accounts on platforms that detected my automation and switched to fresh sessions for each scan. It is less efficient but it avoids the constant cycle of creating and losing accounts. The total time investment is higher, but the results are more consistent.

If you need a pre-built solution and do not want to code anything yourself, there are a few established tools in this space. DickSwiper on GitHub remains one of the more complete open-source implementations, though it requires technical comfort to set up properly. There are also commercial services that offer similar functionality with a web interface, but you should carefully evaluate their privacy policies before uploading any sensitive images. I generally advise against using paid services for this unless you have exhausted the free options, because you are essentially handing private content to another company's server infrastructure.

Swyper - Being a DIK Wiki
Swyper - Being a DIK Wiki

When to Walk Away From Automated Scanning

There are situations where running a scanner is not the right first step. If the content is spread across encrypted messaging apps, dark web marketplaces, or peer-to-peer networks, the tool will not find it. If the distributor is actively fighting back against takedowns with throwaway accounts and constant reuploads, automated scanning becomes a numbers game you will likely lose. In those cases, professional legal intervention and coordinated platform reporting is usually the only effective approach. I also recommend pausing the scanning process if you find yourself becoming obsessive about it. I knew someone who spent two months running daily scans and checking results obsessively. He was not sleeping well and his work performance suffered. Tracking down leaked content is stressful enough without turning it into a full-time job. Set a reasonable schedule for your scans and take breaks between sessions. The internet is not going anywhere, and neither is the content. You do not need to check every single hour. The most important thing to understand is that this tool is one piece of a much larger response strategy. It can help you locate where content is publicly available, but it cannot delete it, hold people accountable, or prevent future distribution. Those tasks require a combination of platform reporting, legal action, and personal support systems. I have seen too many people treat the scanner as the entire solution when it is really just the starting point. Use it responsibly, document everything carefully, and know when to bring in people who are better equipped to handle the parts that scanning cannot fix.