Skip to main content

Domain Reputation Real-time malicious domain checker and threat score

Try it now
Examples

Enter a domain to review its reputation, registration and infrastructure.

Output

How this check works · illustration

Check any domain against configured intelligence sources in milliseconds. Get a clear reputation score, phishing and malware categories, WHOIS context, DNS history, and SOC-ready evidence for allow/block decisions.

curl -d "email=you@example.com" https://ismalicious.com/api/keys/instant

50 free requests/month · instant API key · no signup form

Fictional example

Read an example domain report.

Illustration dated 2026-09-01. Indicators, providers, scores and observations are fictional. This is not a current result for these addresses.

Example requestGET /api/check?query=example.com

example.com

DomainHigh risk

Registration

Registered2026-08-20
Updated2026-08-21
Expires2027-08-20
RegistrarExample registrar
Age12 days

Email DNS records

SPFPresent
DMARCNot observed
DKIMNot checked

A missing DMARC record is an email configuration observation. It does not by itself establish malicious activity.

Sources flagging

3of 4 sources

Confidence

80 %

The score and confidence are illustrative values. Confidence describes support for the assessment; it is not a percentage of sources or a probability of compromise.

Example categories

PhishingMalware

Example source observations

Example source observations
SourceObservation
Example feed AFlagged
Example feed BFlagged
Example feed CFlagged
Example feed DNot listed

“Not listed” means this source has no listing in the example. It is not a clean bill of health.

How to interpret it

Compare source observations, dates and technical context before taking action. This example makes no attribution to a threat actor.

Fictional example3 sources flag the indicatorConfidence: 80 %No live lookup

Real reports depend on the indicator, available sources and access level. Missing data is shown explicitly. These panels illustrate how to read the data; they are not an API response schema.

19M+

Domains

725

Threat Sources

<100ms

Cached Lookup

Capabilities

Signals for your investigation.

Connect the signals, then examine the context.

Multi-Source Intelligence

Aggregate commercial, open-source, and research feeds with source attribution.

Real-Time Scoring

Get instant risk scores with detailed breakdown of threat indicators and confidence levels.

Threat Categories

Identify specific threat types: malware, phishing, spam, C2, cryptomining, and more.

WHOIS Integration

Enrich results with domain registration data, age, and ownership information.

Historical Data

Access reputation history to see how a domain's risk profile has changed over time.

Bulk Lookups

Check thousands of domains at once with our high-throughput bulk API.

Applications

Use cases. How security teams use this tool.

Email Security Gateways

Check sender domains and URLs in real-time to block phishing attempts.

Web Proxy Filtering

Prevent users from accessing malicious websites by checking domains at the proxy level.

SIEM Enrichment

Enrich security alerts with domain reputation data for faster triage.

Fraud Prevention

Identify suspicious domains during account registration and transactions.

What is Domain Reputation?

Domain reputation is a security scoring system that evaluates the trustworthiness and safety of domain names based on historical behavior, associations, and threat intelligence data. A domain's reputation score reflects whether it has been involved in malicious activities such as malware distribution, phishing campaigns, spam operations, or command-and-control communications. Security teams use domain reputation to make real-time decisions about blocking or allowing network traffic, filtering emails, and protecting users from web-based threats.

How Domain Threat Detection Works

Our domain reputation system aggregates data from multiple threat intelligence sources, including commercial feeds, open-source blocklists, honeypot networks, and proprietary detection systems. When you query a domain, we cross-reference it against known indicators of compromise (IOCs), analyze its DNS history, check registration patterns, and evaluate its hosting infrastructure. Machine learning models process these signals to generate a comprehensive risk score with confidence levels, allowing you to fine-tune your security policies based on your organization's risk tolerance.

Types of Malicious Domains

Malicious domains come in many forms: phishing domains impersonate legitimate brands to steal credentials, malware distribution domains host exploit kits and drive-by downloads, spam domains send bulk unsolicited email, C2 (command-and-control) domains coordinate botnet operations, cryptojacking domains mine cryptocurrency using visitors' resources, and typosquatting domains exploit common typing errors to deceive users. Our detection system identifies and categorizes each threat type, providing specific intelligence for your security stack.

Newly Registered Domain Risk

Newly registered domains (NRDs) present elevated security risks because attackers frequently register fresh domains to evade blocklists and reputation systems. Research shows that over 70% of malicious domains are used within 30 days of registration. Our system flags NRDs automatically and provides domain age information, allowing you to implement policies that scrutinize or block communications with recently registered domains until they establish a legitimate track record.

Support

Frequently asked questions.

How often is domain reputation data updated?

Our threat intelligence feeds are updated continuously, with most sources refreshing every 5-15 minutes. Critical threats are propagated within seconds.

What sources do you use for domain reputation?

We aggregate data from configured sources including commercial threat feeds, open-source blocklists, honeypots, and proprietary detection systems.

Can I check newly registered domains?

Yes! We flag newly registered domains (NRDs) as higher risk by default and provide domain age information in our responses.

What's the rate limit for the free tier?

Free accounts can make up to 50 API requests per month, in batches of up to 10 indicators, and monitor 5 entities. Pro raises that to 10,000 reputation checks a month and adds larger batches, more monitored entities and webhooks.

New to the term? Read the glossary definition.

Get Started

Ready to get started?

Join thousands of security teams using isMalicious to protect their infrastructure.

No credit card required · Free API key