Skip to main content
DFIRLab
Research
Intel BriefingsThreat Actors
File AnalyzerPhishing CheckDomain LookupExposure ScannerPrivacy Check
WikiAbout
PlatformNew
DFIRLab
Privacy Policy/RSS Feed/Sitemap

Security research, threat intelligence, and detection engineering.

© 2026 DFIR Lab. All rights reserved.

Wiki/Threat Intelligence

Domain Reputation

A score or classification assigned to a domain based on historical behavior, threat intelligence associations, and observed malicious activity.

Definition

Domain reputation is an assessment of how trustworthy or malicious a domain is, derived from aggregated threat intelligence signals. Reputation systems draw on multiple data sources: detection history across antivirus engines, presence in blocklists (Spamhaus, SURBL, PhishTank), DNS behavior patterns, WHOIS registration anomalies, certificate issuance history, passive DNS data, and association with known malicious infrastructure. The output is typically a categorical classification (clean, suspicious, malicious, phishing, spam, malware) or a numerical risk score.

Why It Matters

Domain reputation is a core triage signal during incident response. A domain referenced in an email header, network log, or malware sample can be rapidly assessed to determine whether it warrants escalation. Reputation data helps analysts distinguish opportunistic commodity threats from targeted campaigns, identify infrastructure reuse across threat actors, and prioritize investigative effort. It is also operationalized in security controls — DNS firewalls, secure web gateways, and email security platforms use reputation feeds to block or quarantine traffic in real time.

How It Works

Reputation engines aggregate signals from multiple intelligence providers and apply scoring models that weight recency, severity, and source credibility. A domain first seen 24 hours ago with a privacy-protected WHOIS record, a Let's Encrypt certificate, and detections on 3 AV engines scores very differently than an established domain with the same detections. Many platforms implement time-decay on historical signals and continuously re-evaluate reputation as new data arrives. Analysts query reputation APIs by submitting a domain name and receive a structured response with scores, category classifications, contributing sources, and raw indicators.

DFIR Platform

DFIR Lab Domain Lookup tool

The DFIR Lab Domain Lookup tool at dfir-lab.ch/domain-lookup provides domain reputation scores aggregated from multiple threat intelligence sources. The Phishing Email Checker also evaluates domain reputation as part of its URL analysis pipeline

View Documentation

Related Concepts

Indicators of CompromiseIOC EnrichmentIP Reputation

Try these concepts in practice

Free tier with 100 credits/month. No credit card needed.

Start Free