Multi-Source Intelligence
Aggregate commercial, open-source, and research feeds with source attribution.
How this check works · illustration
Check any domain against configured intelligence sources in milliseconds. Get a clear reputation score, phishing and malware categories, WHOIS context, DNS history, and SOC-ready evidence for allow/block decisions.
curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant50 free requests/month · instant API key · no signup form
Illustration dated 2026-09-01. Indicators, providers, scores and observations are fictional. This is not a current result for these addresses.
example.com
Registration
Email DNS records
A missing DMARC record is an email configuration observation. It does not by itself establish malicious activity.
Sources flagging
3of 4 sources
Confidence
80 %
The score and confidence are illustrative values. Confidence describes support for the assessment; it is not a percentage of sources or a probability of compromise.
Example categories
Example source observations
| Source | Observation |
|---|---|
| Example feed A | Flagged |
| Example feed B | Flagged |
| Example feed C | Flagged |
| Example feed D | Not listed |
“Not listed” means this source has no listing in the example. It is not a clean bill of health.
How to interpret it
Compare source observations, dates and technical context before taking action. This example makes no attribution to a threat actor.
Real reports depend on the indicator, available sources and access level. Missing data is shown explicitly. These panels illustrate how to read the data; they are not an API response schema.
19M+
Domains
725
Threat Sources
<100ms
Cached Lookup
Connect the signals, then examine the context.
Aggregate commercial, open-source, and research feeds with source attribution.
Get instant risk scores with detailed breakdown of threat indicators and confidence levels.
Identify specific threat types: malware, phishing, spam, C2, cryptomining, and more.
Enrich results with domain registration data, age, and ownership information.
Access reputation history to see how a domain's risk profile has changed over time.
Check thousands of domains at once with our high-throughput bulk API.
Check sender domains and URLs in real-time to block phishing attempts.
Prevent users from accessing malicious websites by checking domains at the proxy level.
Enrich security alerts with domain reputation data for faster triage.
Identify suspicious domains during account registration and transactions.
Domain reputation is a security scoring system that evaluates the trustworthiness and safety of domain names based on historical behavior, associations, and threat intelligence data. A domain's reputation score reflects whether it has been involved in malicious activities such as malware distribution, phishing campaigns, spam operations, or command-and-control communications. Security teams use domain reputation to make real-time decisions about blocking or allowing network traffic, filtering emails, and protecting users from web-based threats.
Our domain reputation system aggregates data from multiple threat intelligence sources, including commercial feeds, open-source blocklists, honeypot networks, and proprietary detection systems. When you query a domain, we cross-reference it against known indicators of compromise (IOCs), analyze its DNS history, check registration patterns, and evaluate its hosting infrastructure. Machine learning models process these signals to generate a comprehensive risk score with confidence levels, allowing you to fine-tune your security policies based on your organization's risk tolerance.
Malicious domains come in many forms: phishing domains impersonate legitimate brands to steal credentials, malware distribution domains host exploit kits and drive-by downloads, spam domains send bulk unsolicited email, C2 (command-and-control) domains coordinate botnet operations, cryptojacking domains mine cryptocurrency using visitors' resources, and typosquatting domains exploit common typing errors to deceive users. Our detection system identifies and categorizes each threat type, providing specific intelligence for your security stack.
Newly registered domains (NRDs) present elevated security risks because attackers frequently register fresh domains to evade blocklists and reputation systems. Research shows that over 70% of malicious domains are used within 30 days of registration. Our system flags NRDs automatically and provides domain age information, allowing you to implement policies that scrutinize or block communications with recently registered domains until they establish a legitimate track record.
New to the term? Read the glossary definition.
Check IP address risk scores
Scan full URLs for threats
Domain registration data
Read the address, check the domain and the business behind it, and pay only in a way you can dispute.
Call the supplier on a number you already had before paying any new bank details.
Join thousands of security teams using isMalicious to protect their infrastructure.
No credit card required · Free API key