Domain Security Score
Combines independent technical, reputation, infrastructure, and authority signals into a single 0-100 score and risk level -- built from the same underlying checks as this site's individual validators, weighted and capped so no single strong signal can hide a confirmed security threat. This is a risk indicator, not a guarantee that a website is safe.
How the Score Is Calculated
Every check is normalized into a pass, warning, fail, or unknown result, grouped into eight weighted categories, and combined into a weighted average out of 100. A separate critical-override layer then runs afterward: a confirmed malware or phishing detection from a high-confidence source caps the final score at 25 regardless of the weighted average, multiple independent malicious detections cap it at 35, and a serious spam/blocklist problem caps it at 50. Domain Authority Signals (Ahrefs DR, Moz DA, Semrush Authority Score) are capped at a 5% weight specifically so they cannot meaningfully offset a security or reputation failure.
| Group | Weight | What it covers |
|---|---|---|
| Malware & Phishing Reputation | 30% | Whether reputable engines and blocklists have flagged this domain for hosting or distributing malware or phishing content. |
| Spam & Abuse Reputation | 15% | Presence on DNS-based blocklists and abuse databases used to catch spam sources and compromised infrastructure. |
| Domain & Infrastructure History | 15% | Signals about the hosting network, IP reputation, and historical DNS/infrastructure stability behind the domain. |
| HTTPS, TLS & Security Headers | 15% | Certificate validity, transport encryption, and browser-facing security headers protecting visitors in transit. |
| DNS Security | 10% | Email-spoofing and DNS-integrity protections: SPF, DKIM, DMARC, DNSSEC, CAA, MTA-STS, and TLS-RPT. |
| Domain Registration & Stability | 5% | Registration age, registrar/RDAP status, and nameserver setup -- newer or unstable registrations carry more inherent risk. |
| Popularity & Legitimacy Signals | 5% | Independent traffic/ranking signals (e.g. Tranco, Cloudflare Radar) that a domain is a real, widely-used site rather than newly thrown up. |
| Domain Authority Signals | 5% | SEO authority metrics (Ahrefs DR, Moz DA, Semrush Authority). These are not security indicators and are deliberately capped at a small weight so they cannot offset a security or reputation failure. |
Data Sources & Methodology
Every source behind the checks in each group below, deduplicated -- see that check's own page for its full Sources & Methodology section and FAQ.
Malware & Phishing Reputation
- Cloudflare Radar API
- VirusTotal API Documentation
- Google Safe Browsing API
- Google Cloud — Web Risk Lookup API (uris.search)
- Google Cloud — Web Risk ThreatType Reference
- Google Cloud — Web Risk Caching Requirements
- Google Cloud — Web Risk Overview
- abuse.ch — URLhaus
- Cisco Talos Intelligence
- OpenPhish
- PhishTank API
- ICANN Domain Metrica — Community API Documentation
Spam & Abuse Reputation
Domain & Infrastructure History
HTTPS, TLS & Security Headers
- hstspreload.org — Chromium HSTS Preload List
- RFC 8446 — The Transport Layer Security (TLS) Protocol Version 1.3
- RFC 5246 — The Transport Layer Security (TLS) Protocol Version 1.2
- RFC 5280 — Internet X.509 Public Key Infrastructure Certificate Profile
- RFC 6962 — Certificate Transparency
- RFC 9110 — HTTP Semantics
- W3C Content Security Policy Level 3
- W3C Mixed Content
- RFC 9116 — A File Format to Aid in Security Vulnerability Disclosure (security.txt)
DNS Security
- RFC 4033 — DNS Security Introduction and Requirements (DNSSEC)
- RFC 8659 — DNS Certification Authority Authorization (CAA)
- RFC 7208 — Sender Policy Framework (SPF)
- RFC 6376 — DomainKeys Identified Mail (DKIM)
- RFC 9989 — Domain-Based Message Authentication, Reporting, and Conformance (DMARC)
- RFC 8461 — SMTP MTA Strict Transport Security (MTA-STS)
- RFC 8460 — SMTP TLS Reporting (TLS-RPT)
Domain Registration & Stability
Popularity & Legitimacy Signals
Domain Authority Signals
FAQ
What is the Domain Security Score?
It's a single 0-100 score combining roughly 35 independent checks -- malware/phishing blocklists, spam/abuse databases, DNS and transport security configuration, registration data, popularity, and SEO authority metrics -- into eight weighted groups. It's a risk indicator built from third-party data and live technical checks, not a certification.
How is the Domain Security Score calculated?
Every check returns PASS, INFO, WARNING, FAIL, or UNKNOWN with a confidence and severity. Results are averaged within each of the eight groups (weighted 5-30% by how directly the group reflects malicious activity), then combined into one weighted average. A critical-override layer runs afterward: a confirmed high-confidence malware/phishing hit caps the score at 25, two or more independent malicious detections cap it at 35, and a serious spam/blocklist listing caps it at 50 -- these caps apply no matter how well everything else scored.
Why does SEOTechTests use multiple independent data sources instead of just one?
No single blocklist, vendor API, or protocol check covers every kind of abuse, and any one source can have false negatives or be temporarily unavailable. Combining independent sources (e.g. Spamhaus, VirusTotal, URLhaus, ICANN Domain Metrica) means a domain has to evade several unrelated detection methods to look clean, and the scoring explicitly avoids double-counting when two sources report the same underlying fact.
What does Coverage mean?
Coverage is the share of applicable checks that actually returned a definitive result (not UNKNOWN) for this domain -- e.g. missing an API credential, a provider timeout, or a rate limit all reduce coverage. A checker that is structurally inapplicable (like a manual-only lookup with no public API) is excluded from coverage entirely rather than counted as a miss.
What does Confidence mean, and why can a group show a low score with low confidence?
Confidence reflects how much of a group's checks actually completed, not how good the result looks. A group where only 1 of 5 checks ran is shown as low-confidence even if that one check passed, so a thin sample is never presented with the same authority as a fully assessed one.
Can a domain with a high score still be malicious?
Yes. The score reflects what independent, automatable checks could detect at the moment they ran -- it cannot see content behind a login, detect a very recent compromise not yet reported to any blocklist, or evaluate anything a check doesn't cover. A high score means no included check found a problem, not a guarantee of safety.
Why are authority metrics like Ahrefs DR or Moz DA given much less weight than direct security signals?
Backlink and traffic authority metrics measure SEO visibility, not security -- a domain can have strong authority and still be compromised or malicious. They're capped at a fixed 5% of the score specifically so a strong SEO profile can never offset a confirmed malware, phishing, or spam finding; direct abuse evidence always carries substantially more weight than contextual signals like domain age, popularity, or authority.