· via dev.to (home feed)
New Personal Domain With SPF and DMARC Scores 95 for Phishing on IPQS
A dev.to post reports a two-month-old .me domain with valid SPF and DMARC was flagged as phishing with a 95/100 risk score by IPQualityScore, and a correction request has gone unanswered.

A clean domain, a 95 score
A post on dev.to describes what happened when a developer ran a freshly registered personal domain through IPQualityScore (IPQS), a commercial provider of fraud and reputation data. The domain, a .me address registered roughly two months earlier to host a permanent personal email identity, came back flagged as phishing with a risk score of 95 out of 100.
The same report, according to the author, undercut its own verdict. It showed no spam, no malware, no hosted content and no parking, while confirming valid DNS plus SPF and DMARC. The only other negative signal was a "risky TLD" flag aimed at the .me extension itself.
A strong finding with no visible evidence
According to the dev.to post, IPQS documentation describes its URL risk score as a measure of confidence in detecting malicious URLs, with scores of 85 or above treated as high risk. The formula is proprietary, so a 95 is not literally a 95 percent probability of malice, but downstream consumers — fraud teams, email filters, automated signup checks — will read it as near-certain danger. The post notes that IPQS markets this data for screening domains during signups, transactions and email submissions, so the number is built to influence decisions.
What the report lacks, the author argues, is any evidence for the phishing allegation: no cloned login page, no credential form, no brand impersonation, no linked abuse complaint, no blacklist match. The public result simply asserts phishing. The post draws a sharp distinction here: insufficient reputation is an honest description of a new domain, while a phishing label is an accusation of criminal activity, and blurring the two is the central failure.
The .me penalty
The report also marked the top-level domain as risky. The post says IPQS does not publicly explain which TLDs appear on its list, what abuse rate triggers inclusion, or how heavily the factor weighs on the final score. The author does not dismiss TLD abuse statistics outright, citing Spamhaus's work on measuring abusive domain ratios within TLD zones, but argues such statistics are weak context rather than proof about any individual domain. A .me address is a natural choice for personal email, and treating the extension as inherently suspicious effectively judges every registrant by aggregate numbers for the zone.
The correction process stalled
The author says a correction request submitted about a month before writing produced no explanation, no verification step, no ticket update and no human reply as of August 29, 2026. That silence drives the post's core complaint: a vendor whose scores trigger blocked signups and rejected transactions should be answerable when a score is wrong. The author also points to IPQS's own guidance that not every newly created site is malicious and that individual signals rarely confirm abuse on their own — language the actual output did not reflect.
This is one user's account of a single domain, and IPQS's side of the story is absent because, according to the post, the company never engaged.
Why it matters
Anyone launching a new domain — a personal email setup, a side project, a startup — can inherit hostile scores from reputation vendors before publishing a single page. Those scores feed automated decisions: rejected signups, filtered messages, blocked payments and extra verification demands. For domain owners, the practical steps are to check a new domain against IPQS and similar services before relying on it, to put SPF and DMARC in place early (though in this case it did not help), and to file correction requests promptly while expecting silence. For teams consuming reputation data, the lesson is that a high score on a young domain may mean unknown rather than malicious, and treating the two identically punishes every legitimate newcomer.
- #fraud-detection
- #domain-reputation
- #email-security
- #ipqs
- #false-positives