Transparency

Where the data comes from

Last updated 7 August 2026

Every finding in a Domainity report names the source it came from and links to the underlying record where one exists. This page lists those sources in one place, along with what each can and cannot tell you.

Sources by check

CheckSourceWhat it can't tell you
Blacklists Google Web Risk; APIVoid Absence of a listing is not evidence of safety — only that these sources had nothing at that moment. The two cover different ground and neither is comprehensive: Web Risk is Google's malware and phishing corpus, built to protect people browsing the web; APIVoid aggregates around 50 scam and fraud blocklists, weighted towards crypto fraud and phishing storefronts. Neither specialises in short-lived malware-distribution hosts, so a clean result is narrower than it looks.
Registration Domain registry RDAP (primary); WhoisFreaks (fallback) Registrant identity is redacted by most registries under privacy law, regardless of source.
Ownership history BigDomainData historical WHOIS Coverage varies by domain. Records after 2018 are largely redacted everywhere, so recent ownership usually resolves to a privacy service rather than a person.
Trademark United States federal register, via a third-party index US federal registrations only. No state, common-law or international marks, and no assessment of likelihood of confusion.
DNS & mail Cloudflare DNS over HTTPS (primary); WhoisFreaks (fallback) A point-in-time snapshot. DNS can change minutes later.
Backlinks & authority DataForSEO; Ahrefs Domain Rating; OpenPageRank No authority score indicates whether a link profile is natural or manufactured. Spam and concentration signals are vendor opinions, not determinations. One index is a monthly snapshot and lags recent changes.
Archive history Internet Archive Wayback Machine Coverage is incomplete and uneven. We report that captures exist and link to them — we do not analyse or classify archived content.
Market estimates DomScan; HumbleWorth Automated estimates, not appraisals. Both are models — neither is grounded in what comparable domains actually sold for, because that data is not available to us on commercially viable terms. They exclude traffic, revenue and brand equity, and routinely disagree; when they contradict each other we say so rather than averaging them.

Personal data in historical records

WHOIS records published before 2018 often contain a registrant's full contact details — street address, email, telephone. That information was lawfully public at the time and remains lawful to display, but republishing an individual's home address a decade later is a choice rather than an obligation.

Domainity shows the registrant name, organisation and country where a record contains them. Addresses, email addresses, telephone and fax numbers are never read from the source data at all, so they cannot appear in a report, a log or a cache.

How sources are verified

Data sources are not taken on trust. Each blacklist provider is tested on a schedule against domains known to be distributing malware at that moment, plus a control domain that must come back clean. A provider that flags everything is as useless as one that flags nothing.

This is not hypothetical diligence. During development, two separate, plausible-looking reputation sources were found reporting clean results for domains with active malware listings — one of them grading such a domain "A / low risk". Both failed silently: nothing errored, and the responses parsed correctly. Neither is used.

Verification results are recorded, and a source that stops detecting is removed rather than quietly relied upon.

When a source doesn't answer

Sources time out, rate-limit and occasionally go down. When that happens, the report says so on the same screen as the results, and the affected check is marked unavailable.

An unavailable check is never presented as a clean result. "We looked and found nothing" and "we could not look" are different statements, and conflating them is the single most dangerous thing a due diligence tool can do.

Attribution

Malicious-listing data is provided by Google Web Risk and APIVoid. Archived capture data is provided by the Internet Archive. Trademark data originates from the United States Patent and Trademark Office. Domain Rating is provided by Ahrefs. Domainity.App, LLC is not affiliated with, endorsed by, or sponsored by any of these organisations.

Questions about a specific finding or source: verify@domainity.app.