IPQS False Positives: How a New Domain Got a 95 Risk Score
DEV Community

IPQS False Positives: How a New Domain Got a 95 Risk Score

A little over two months ago, I registered a new domain for personal use. The idea was simple. I wanted a permanent, professional email address based on my last name, something like f****@lastname.me . I registered the domain for ten years because I wasn’t building a disposable project, launching a marketing funnel, or testing some short-lived startup idea. I wanted an email identity I could keep for the long haul. I configured the domain properly. It has valid DNS. SPF is enabled. DMARC is enabled. It isn’t parked for sale. It isn’t sending spam. It isn’t distributing malware. It isn’t impersonating a bank, crypto exchange, social network, government agency, or anyone else. Then I checked it with IPQualityScore, also known as IPQS. The result was absurd: - Phishing: true - Suspicious: true - Risk score: 95 - Spamming: false - Malware: false - SPF enabled: true - DMARC enabled: true - DNS valid: true - Parked domain: false - Hosted content: false - Category: N/A - Domain rank: 0 - Risky TLD: true In other words, IPQS acknowledged that the domain had valid DNS and email authentication, found no spam, found no malware, found no hosted content, assigned it no content category, and still labeled it as phishing with a risk score of 95 out of 100. I submitted a correction request about a month ago. I received no explanation. No evidence. No request for verification. No ticket update. No human response. As of August 29, 2026, the status is still unchanged. That isn’t a harmless technical oddity. IPQualityScore sells reputation and fraud-risk data that businesses can use to block users, reject signups, review transactions, investigate security alerts, and decide whether a domain, email address, IP address, phone number, or device should be trusted. If you’re going to sell suspicion as a service, you need to be accountable when your suspicion is wrong. IPQS, in my case, has been neither accurate nor accountable. A score of 95 is not a gentle warning IPQualityScore’s documentation describes its URL risk score as an estimate of confidence in malicious URL detection. It says scores of 85 or higher represent high risk and that these domains are likely to have a poor reputation or be malicious. Its phishing field indicates that a URL is associated with malicious phishing behavior.1 That matters because a score of 95 is not presented as “we don’t know enough about this domain yet.” It is presented as a very strong finding. To be precise, a score of 95 does not necessarily mean there is a mathematically valid 95 percent probability that a domain is malicious. IPQS calls it a confidence score, and its internal formula is proprietary. But an ordinary user, security analyst, fraud team, or automated system will naturally read 95 as nearly certain danger. IPQS provides examples showing how customers can flag a URL when phishing is true, malware is true, or the risk score is above 85. The company also says organizations can use its domain reputation products to screen domains during signups, transactions, and email submissions.2 These are not decorative numbers. They are designed to influence decisions. A “phishing: true” result paired with a risk score of 95 can become a rejected signup, a blocked message, a security alert, a denied registration, a failed transaction, or a demand for additional verification. IPQualityScore may argue that its customer makes the final decision. Technically, that is true. But IPQS sells the signal with the expectation that customers will act on it. It cannot take credit when its data prevents fraud and then pretend to be a passive bystander when the same data harms an innocent user. The IPQS report contradicts itself The individual findings in my report make the final verdict even harder to defend. It says there is no malware. It says there is no spam. It says the domain is not parked. It says there is no hosted content. It says DNS is valid. It confirms SPF and DMARC. It has no content category. It has no traffic rank. Then, somehow, the IPQualityScore system jumps to “phishing: true” and a risk score of 95. What was the actual phishing indicator? Was there a cloned login page? A credential collection form? A fake brand? A suspicious JavaScript payload? A phishing email linked to the domain? A malicious redirect chain? A complaint from an IPQS customer? A match against a third-party blacklist? A machine-learning pattern based on the domain name? An association inherited from shared infrastructure? The public result doesn’t say. That is the heart of the problem. IPQS presents a highly specific and potentially damaging conclusion while hiding the evidence behind it. When a system says “insufficient reputation,” that is a reasonable description of a new domain. When it says “phishing: true,” that is an allegation of malicious behavior. Those are not remotely the same thing. One means there isn’t enough information. The other claims that the domain is connected to an actual form of cybercrime. IPQualityScore should not blur that distinction just because its scoring model finds uncertainty inconvenient. Apparently, .me is a “risky TLD” The IPQS result also marked the .me extension itself as risky. IPQualityScore defines risky_tld as a signal that a domain belongs to a top-level domain frequently associated with malware, scams, abuse, or phishing. Its public documentation does not explain which TLDs are on that list, what period is measured, what abuse rate triggers the label, how frequently the list changes, or how heavily this factor affects the final risk score.3 I’m not arguing that TLD-level abuse statistics are completely useless. Security researchers do measure differences in abuse rates among top-level domains. Spamhaus, for example, explains that a TLD can develop a poor reputation because of a high ratio of abusive domains or a large total volume of abuse. It also acknowledges that such measurements involve judgment calls and do not cover the entire domain population.4 That is exactly why TLD reputation should be a weak contextual signal, not a shortcut to guilt. A .me domain is an entirely natural choice for a personal website or personal email address. Treating the extension as categorically risky, without explaining the underlying abuse rate or how that rate influenced a score of 95, is crude profiling. It amounts to guilt by neighborhood. A ZIP code may have a higher-than-average fraud rate, but that does not make every resident a fraudster. A phone carrier may have more spam reports, but that does not make every customer suspicious. A hosting company may have abusive customers, but that does not prove every website using its infrastructure is malicious. Those facts may be useful signals for deciding where to look more carefully. They are not evidence that a particular domain committed fraud. If .me materially influenced the risk score, IPQualityScore should explain how. If it did not materially influence the score, displaying “Risky TLD: true” without context seems designed mainly to make the report look more alarming. New is not the same as malicious Yes, criminals use newly registered domains. That is real. Domain age can be relevant when it is combined with a fake login page, brand impersonation, suspicious scripts, credential harvesting, malicious email activity, or verified abuse reports. But “new” is not a synonym for “phishing.” Every legitimate domain was new once. Every family domain, portfolio, local business, nonprofit, open-source project, personal blog, custom email domain, and startup begins with no traffic rank and no long history of positive behavior. The absence of reputation is not a negative reputation. IPQualityScore itself says that not every newly created or unusual site is malicious and that individual signals rarely confirm abuse on their own.5 That is sensible language. The trouble is that the output I received did not say: This domain is new, unranked, and does not yet have enough history for us to evaluate confidently. It said: Phishing: true. Those are radically different messages. A low-confidence, unknown, unclassified, or unrated result would have been fair. A warning that the domain lacked sufficient history would have been understandable. A phishing label with a score of 95 was not. If IPQS has direct evidence of phishing, it should identify the type and date of that evidence. If it only knows that a domain is two months old, has no traffic rank, uses .me , and redirects somewhere, then it does not know that the domain is phishing. It is guessing. Worse, it is presenting that guess as a near-certain security verdict. A normal redirect is not phishing The IPQualityScore report also marked the domain as redirected. That may sound ominous to someone who doesn’t work with websites, but redirects are everywhere. Domains routinely redirect from HTTP to HTTPS, from a root domain to www , from one landing page to another, from an old page to a new one, or from a personal domain to a hosted profile. Redirects are a basic part of how the web works. Redirect chains can be part of phishing campaigns, of course. They can hide the final destination or route victims through compromised infrastructure. But a redirect by itself proves nothing. IPQS defines the field as indicating whether a URL redirects to another domain. Its documentation does not say that every redirect is inherently malicious.6 If the redirect contributed to the score, IPQualityScore should explain what was suspicious about the destination or redirect chain. Was the destination on a verified threat feed? Did it contain a fake login page? Was the redirect obfuscated? Was it conditional based on browser, device, or location? Without that context, “Redirected: true” is just a fact about how a website behaves. It is not evidence of phishing. The Cloudflare IP tells us almost nothing about the owner The report also displayed a Cloudflare IP address. Cloudflare explains that proxied hostnames use shared IP ra

Read on DEV Community ↗ ← Back to News

Comments

No comments yet. Start the discussion.