Resources  / The risk score

How the risk score works

Every detected name carries a score from nought to a hundred. It answers one question: how ready is this name to be used against your customers?

It is not a measure of how much the name resembles yours. A name one character from yours that answers nothing is not a threat yet; a name three characters away that was registered on Tuesday and can capture a reply is.

Most of what we find is never dangerous

This is worth saying plainly, because it decides the shape of everything below. A permutation set finds thousands of registered names. Nearly all of them are parked, or somebody else's business, or a registration a brand made to defend itself, and they stay that way for ever.

Ranking those names is not the product. The product is the day one of them changes — the day a site appears on it, the day somebody configures mail, the day it leaves the parking service. So the score does two things: it says what a name can do now, and it watches for the day that answer changes.

What the score is

Five questions. Each answer is a number between nought and one, and the five multiply.

score = 100 × deception × capability × freshness × reputation × discounts

They multiply rather than add for a reason. A name that cannot do anything is not dangerous however much it looks like yours, and a name that is eight years old and unchanged is somebody's business. Adding points and cutting the total at a hundred loses both of those, and it counts one fact twice whenever two signals describe the same thing.

How convincing is the name?

How much the name itself is built to fool somebody. It is the only part that never changes: the name is the name.

deception, from 0.25 to almost 1

SignalEffectWhat it means
brand_token+0.60Your name is inside it, spelled correctly, with more around it. A common word as a name counts for a quarter of this.
looks_identical+0.60The characters look the same as yours at the size an address is printed.
one_character_apart+0.40One character differs from your name.
two_characters_apart+0.20Two characters differ from your name.
phishing_word+0.30It carries a word such as "secure" or "login" that makes an address read as official.
suffix_in_label+0.25Your suffix is pulled into the name, so the address ends the way yours does.
abused_suffix+0.15The suffix carries a lot of abuse for its size.

What can it do today, over the web or over mail?

What the name can do today, over the web or over mail. These are separate channels, and we take the larger. A name with a live site and no mail is fully able to hurt somebody, and the missing mail takes nothing off it.

capability, from 0.05 to 1

SignalEffectWhat it means
site_address0.80It publishes an address record, so it can serve a page.
site_answers0.90A page on it answers.
site_copies_seed1.00The page copies yours.
reply_capture0.75It publishes a mail host, so it can receive a reply somebody meant to send to you.
mailbox_provider0.85Its mail is carried by a mail provider, so somebody holds a mailbox on it and can answer inside a thread.
sending_configured+0.10It authorizes a service to send mail as itself.
mail_discarded0.10Its mail host is the loopback address or the root, so mail sent to it goes nowhere.

Is it new, or did it just change?

Whether the name is new, or has just changed. A name registered this week matters. So does an eight-year-old name that gained a mail host on Tuesday. A quiet name gets quieter the longer we watch it do nothing.

freshness, from 0.12 to 1

SignalEffectWhat it means
registered_this_week1.00The name was registered in the last seven days.
registered_this_month0.90The name was registered in the last thirty days.
registered_this_quarter0.75The name was registered in the last ninety days.
registered_this_year0.60The name was registered in the last year.
registered_years_ago0.40The name was registered more than a year ago.
registered_long_ago0.25Registered over five years ago.
change0.85It did something: started answering, gained a mail host, moved nameservers, changed registrar or changed registrant. A change overrides the age and then fades over ninety days.
dwell0.50 to 0.85We have watched it and it has done nothing. The longer we watch a quiet name, the lower it goes.

Who registered it, and who serves it?

Who registered it and who serves it. This is the one part that can push a score up as well as down.

reputation, from 0.85 to 1.25

SignalEffectWhat it means
bulk_abuse_pattern1.25Three or four of: a registrar we see abuse at, the shared nameservers of a retail service, a hidden registrant, and answering within hours of being registered.
cheap_registration1.10Two of those four.
clean_registrar0.85We have seen little abuse at this registrar across the names we watch.

What says a real operator owns it?

What says a real operator owns it, rather than somebody imitating you.

discounts, from 0.05 to 1.00

SignalEffectWhat it means
settled_operator0.50It has held the same mailbox and the same service verification record for over a year. That is what an ordinary business looks like. Half this reduction until we have watched it for a year ourselves.
independently_popular0.05 to 0.50People reach it on purpose. A name registered to imitate yours has no traffic of its own.
parked0.30It shows a holding page that its owner did not write.
corporate_registrar0.40It is held at a registrar that sells to companies defending brands, not to somebody buying one name.
brand_protection_dns0.60Its nameservers belong to a brand protection service, so somebody is already defending it.

Two names, worked through

These are the two that made us rebuild the model. The old version scored them 52 and 40 — twelve points between a live phishing name and what is probably somebody's company.

apple7.cc 85

Four days old. Live on a bulk registrar, hidden registrant, already reported.

deception
0.82
your name spelled correctly with a digit after it, on an abused suffix
capability
0.80
it publishes an address record, so it can serve a page
freshness
1.00
registered four days ago
reputation
1.10
a hidden registrant on shared retail nameservers
discounts
1.00
nothing says a real operator owns it

100 × 0.82 × 0.80 × 1.00 × 1.10 = 72, then held at 85 by the blocklist floor

appley.co 9

Eight years old. Stable Google Workspace, a site verification record, no website.

deception
0.82
one character from your name
capability
0.86
a mailbox at a mail provider can capture a reply
freshness
0.25
registered eight years ago and unchanged since
reputation
1.00
nothing either way
discounts
0.50
a settled operator: the same mailbox and verification record for years

100 × 0.82 × 0.86 × 0.25 × 1.00 × 0.50 = 9

How the score moves

A score that reads only the present state says the same thing on the first day and on the four hundredth. These are the rules that make it change.

A quiet name sinks on its own

The longer we watch a name do nothing, the lower it goes. After ninety days it keeps two-thirds of its score, and after a year half. Nobody has to dismiss four thousand parked names to make the list usable — they sink. Dismissal is a decision somebody has to make. A decay is not.

A name that is weaponized rises at once

These are the changes we watch for. Each one is something the name could not do before and can do now, and each one is a line on your page the morning it happens.

EventWhat happened
site_appearedA site appeared on a name that served nothing.
site_answeredIt now serves a page that answers.
content_matchedThe page on it now copies yours.
mail_appearedA mail host appeared, so it can now receive a reply.
mailbox_provider_addedA mailbox was set up on it at a mail provider. This is how business email compromise starts.
sending_configuredIt now authorizes a service to send mail as itself.
left_parkingIt left the parking service it was held at. Somebody took it off the shelf.
changed_handsIts registrar or its registrant changed.
listedIt appeared on a blocklist.

And it does not fall back quickly

A phishing site is taken down after the campaign, or the host suspends it, or whoever bought the name parks it and waits. A name that was weaponized last week and is quiet this morning is more dangerous than one that was never weaponized, so the score falls from the highest reading the name ever had rather than following it down. That fall stops at half after ninety days, and a name we watched become able to carry an attack never returns below 35.

The floors

These are applied last, so that nothing can bury them.

FloorHolds atWhy
blocklisted85Somebody already reported it. What it can do today does not matter, and no reduction can bury it.
was_weaponized35We watched it become able to carry an attack. A site taken down after a campaign is not a name that became safe.
registered_this_week50% of the restBought in the last seven days. An empty name is the normal first state of an attack.
registered_this_month35% of the restBought in the last thirty days.

How fast we would see it

Every name under a seed is read on the same schedule, whatever its score. There is no ladder that reads the interesting names often and the quiet ones rarely. A backoff like that spends the query budget where a change is likely, and the whole promise is about the names where a change is unlikely and expensive — a name that has sat still for two years is exactly the one nobody else is watching.

What we do not do

This page is built from the service, at /api/public/risk-model, so the figures here are the figures the scorer uses. Model version 2.

See the scores on the hundred names we watch in the open →