A little over two months ago, I registered a new domain for personal use.
The idea was simple.
I wanted a permanent, professional email address based on my last name, something like .
I registered the domain for ten years because I wasn’t building a disposable project, launching a marketing funnel, or testing some short-lived startup idea.
I wanted an email identity I could keep for the long haul.
I configured the domain properly.
It has valid DNS.
SPF is enabled.
DMARC is enabled.
It isn’t parked for sale.
It isn’t sending spam.
It isn’t distributing malware.
It isn’t impersonating a bank, crypto exchange, social network, government agency, or anyone else.
Then I checked it with IPQualityScore, also known as IPQS.
The result was absurd: Phishing: true Suspicious: true Risk score: 95 Spamming: false Malware: false SPF enabled: true DMARC enabled: true DNS valid: true Parked domain: false Hosted content: false Category: N/A Domain rank: 0 Risky TLD: true In other words, IPQS acknowledged that the domain had valid DNS and email authentication, found no spam, found no malware, found no hosted content, assigned it no content category, and still labeled it as phishing with a risk score of 95 out of
100.
I submitted a correction request about a month ago.
I received no explanation.
No evidence.
No request for verification.
No ticket update.
No human response.
As of August 29, 2026, the status is still unchanged.
That isn’t a harmless technical oddity.
IPQualityScore sells reputation and fraud-risk data that businesses can use to block users, reject signups, review transactions, investigate security alerts, and decide whether a domain, email address, IP address, phone number, or device should be trusted.
If you’re going to sell suspicion as a service, you need to be accountable when your suspicion is wrong.
IPQS, in my case, has been neither accurate nor accountable.
A score of 95 is not a gentle warning IPQualityScore’s documentation describes its URL risk score as an estimate of confidence in malicious URL detection.
It says scores of 85 or higher represent high risk and that these domains are likely to have a poor reputation or be malicious.
Its field indicates that a URL is associated with malicious phishing behavior.1 That matters because a score of 95 is not presented as “we don’t know enough about this domain yet.” It is presented as a very strong finding.
To be precise, a score of 95 does not necessarily mean there is a mathematically valid 95 percent probability that a domain is malicious.
IPQS calls it a confidence score, and its internal formula is proprietary.
But an ordinary user, security analyst, fraud team, or automated system will naturally read 95 as nearly certain danger.
IPQS provides examples showing how customers can flag a URL when phishing is true, malware is true, or the risk score is above
85.
The company also says organizations can use its domain reputation products to screen domains during signups, transactions, and email submissions.2 These are not decorative numbers.
They are designed to influence decisions.
A “phishing: true” result paired with a risk score of 95 can become a rejected signup, a blocked message, a security alert, a denied registration, a failed transaction, or a demand for additional verification.
IPQualityScore may argue that its customer makes the final decision.
Technically, that is true.
But IPQS sells the signal with the expectation that customers will act on it.
It cannot take credit when its data prevents fraud and then pretend to be a passive bystander when the same data harms an innocent user.
The IPQS report contradicts itself The individual findings in my report make the final verdict even harder to defend.
It says there is no malware.
It says there is no spam.
It says the domain is not parked.
It says there is no hosted content.
It says DNS is valid.
It confirms SPF and DMARC.
It has no content category.
It has no traffic rank.
Then, somehow, the IPQualityScore system jumps t