What do we mean?
A false positive is a domain that is not actually malicious, even if malware uses it. Blocking one can break a real service, interrupt a person’s connection, and undermine trust in the whole feed.
Domains used by malware are not automatically malicious. Some are parked, shared, reassigned, or part of an ordinary service. We treat that distinction as the core of the product.
A false positive is a domain that is not actually malicious, even if malware uses it. Blocking one can break a real service, interrupt a person’s connection, and undermine trust in the whole feed.
A human is part of the loop. Automated checks do the large, repetitive part first: they remove weak candidates, look for conflicting evidence, and put the remaining indicators in front of a reviewer.
Before a domain can be published, the pipeline checks its source, family, DNS and passive-DNS context, popularity, parking signals, policy lists, and other available evidence. The reviewer can see why it was proposed and can allow or disallow it explicitly.
Candidate domains are normalised and checked against admission rules before they reach the database.
Source paths, excerpts, families, timestamps, and enrichment are retained so a decision can be explained.
Human review is the final publishing gate. The goal is zero false positives in the feed.