The important bit

False positives are not a footnote.

Domains used by malware are not automatically malicious. Some are parked, shared, reassigned, or part of an ordinary service. We treat that distinction as the core of the product.

What do we mean?

A false positive is a domain that is not actually malicious, even if malware uses it. Blocking one can break a real service, interrupt a person’s connection, and undermine trust in the whole feed.

How do we avoid them?

A human is part of the loop. Automated checks do the large, repetitive part first: they remove weak candidates, look for conflicting evidence, and put the remaining indicators in front of a reviewer.

Domain Intelligence is a Quad9 partner. Our feed is used directly to block DNS queries by Quad9, which serves over 120 million users worldwide. That makes it critical to avoid false positives.

Automation makes review possible at scale.

Before a domain can be published, the pipeline checks its source, family, DNS and passive-DNS context, popularity, parking signals, policy lists, and other available evidence. The reviewer can see why it was proposed and can allow or disallow it explicitly.

Filter weak evidence

Candidate domains are normalised and checked against admission rules before they reach the database.

Keep provenance

Source paths, excerpts, families, timestamps, and enrichment are retained so a decision can be explained.

Review the remainder

Human review is the final publishing gate. The goal is zero false positives in the feed.