If you sell suspicion as a service, you must show your work and fix your mistakes fast. IPQS did neither. That isn’t “caution” — it’s reckless labeling at scale.
Clean on every check, guilty in the verdict
A little over two months ago I registered a new personal domain. Not a burner, not a funnel — a first@lastname.me identity I intend to keep for decades. Ten-year registration, proper DNS, SPF and DMARC locked down, not parked, not for sale, not impersonating anyone.
IPQS’s own lookup confirmed it. Then it convicted it anyway.
I filed a correction request about a month ago. As of Aug 29, 2026: no evidence, no ticket update, no human reply, no change. The smear just sits there, rentable to any customer who pays.
95 is a weapon, not a warning
IPQS docs describe the risk score as a “confidence” estimate and say 85+ is high risk / likely malicious. The phishing boolean is described as indicating malicious phishing behavior. View source
Sure, IPQS can claim “95 isn’t a probability.” Users, analysts, and automations don’t care. IPQS shows clients how to auto-flag when phishing==true or risk > 85, and pitches the product for screening signups, transactions, and email submissions. API overview and domain reputation
IPQS wants credit when its signal stops fraud. It wants distance when the same signal harms an innocent. You don’t get both.
The self-contradicting report
| Signal | Finding |
|---|---|
| Malware | false |
| Spamming | false |
| Hosted content | false — nothing to judge |
| Category | N/A |
| DNS / SPF / DMARC | valid / enabled |
| Parked | false |
| Overall verdict | phishing: true — 95/100 |
What tipped it? A fake login? Credential form? Skimmer JS? Malicious redirect chain? Customer complaint? Blacklist hit? ML guess on the name? The report doesn’t say. A damaging, specific accusation with no disclosed evidence is indefensible.
.me is not a crime — guilt by TLD is profiling
IPQS marks .me as “risky TLD” — supposedly frequent abuse — but publishes no list, no threshold, no window, no weight. email validation docs and URL scanner docs
Yes, abuse rates vary by TLD and researchers track them. Spamhaus itself says it’s a mix of ratio and volume and involves judgment calls. TLD report and statistics FAQ That’s why it should be a weak contextual hint, not a conviction. .me is the textbook personal namespace. Criminalizing the neighborhood to judge the house is lazy.
.me drove the 95, defend it with data. If it didn’t, stop displaying “Risky TLD: true” as scare tinsel next to a 95.New ≠ malicious — “unknown” is not “guilty”
Of course attackers use fresh domains. But every legitimate domain was new once. Without abuse, traffic, or content, the honest label is unknown / insufficient data.
IPQS itself admits not every new or unusual site is malicious and single signals rarely prove abuse. View source Yet my output wasn’t “new — can’t tell.” It was “phishing: true.” One is humility. The other is a false accusation with a scientific-looking number slapped on it.
Redirect ≠ phishing
“Redirected: true” sounds scary until you remember the web runs on redirects — HTTP→HTTPS, root→www, old→new, domain→profile. IPQS defines it only as whether a URL redirects, not that it’s malicious. View source Without a bad destination, cloaking, or threat-feed hit, this means nothing.
That Cloudflare IP proves nothing about me
Cloudflare’s proxied hostnames sit behind shared, anycast IPs used by countless unrelated domains. View source You cannot launder strangers’ reputations onto my domain through a shared front door. Did IPQS weight the shared IP? It won’t say. Either answer is damning without transparency.
The black-box business — honeypots, feeds, feedback loops
IPQS says it’s been around since 2011, serves thousands of businesses, and scores 100M+ daily transactions across IP, email, phone, device, proxy/VPN, and URL reputation. About IPQS and homepage Intel comes from honeypots, blocklists, forensics, ML, and customer feedback, with consortium sharing. proxy and VPN detection and Privacy policy
That flywheel is powerful when right — and corrosive when wrong. Bad signals get amplified as they circulate. Which is why correction speed and evidence quality matter more than marketing.
IPQS flaunts logos and case studies and touts integrations with Splunk, Palo Alto Cortex XSOAR, CrowdStrike, Rapid7, ThreatConnect, QRadar, MISP, OpenCTI, SpiderFoot, etc. Reviews and integrations and CrowdStrike listing Caveat: not every logo uses the URL/domain product that flagged me — but the point stands: these scores leak into enterprise dashboards, playbooks, and signup flows. The victim sees “registration denied” and never knows IPQS pulled the trigger.
This isn’t a one-off — a pattern of complaints
On Trustpilot and Reddit you’ll find the same story: clean sites or residential IPs labeled scam/proxy/VPN, appeals met with silence. Trustpilot, HomeNetworking, Cybersecurity Help and Tech Support These are anecdotes, not lab proofs — but the shape repeats. Meanwhile IPQS also enjoys 4.9/5 on business review sites. Capterra and G2 Of course the buyer likes “more blocks.” The person blocked — not the customer — eats the cost. Without a real appeals process, the harmed have no leverage.
99.99% hype vs “as is” fine print
Marketing screams “lowest false-positive rates” and “prevent fraud without false positives.” Reviews, About and account fraud detection Try finding a public benchmark, confusion matrix, or false-positive breakdown. You won’t. Yet docs quietly admit stricter settings raise false positives. URL scanner options and proxy detection options And Terms say the service is “as is” with no warranty of accuracy and capped liability. View source
Support promised hours. I got a month of silence.
IPQS advertises quick replies and 24–48h review for IP false positives. Contact and false-positive form For domains/URLs there’s no dedicated, clearly labeled appeal flow with a case number, status page, or written reason. I used what exists. A month later — nothing. Even a reasoned rejection would be more useful than the void. When your system brands someone’s property a phish, “submit and pray” isn’t due process.
Why customers of IPQS should be angry too
False positives don’t just hurt domain owners. They burn your funnel: good users rejected, good transactions blocked, good emails bounced, analysts chasing ghosts, support drowning, sales lost without ever knowing why. Teams stop trusting alerts, build sloppy allowlists, and weaken real security. Measuring “how often we blocked when IPQS said block” is circular — you’re grading IPQS with its own homework.
What IPQS must do — immediately
- Stop calling “unknown” phishing. Use unknown / insufficient data / low confidence unless you have direct evidence.
- Ship a real domain/URL appeal flow — case numbers, status page, SLA, written reasons.
- Show reason codes and source type — new, low history, TLD stats, redirect, shared CDN, heuristic/ML, feed hit, customer report — plus evidence date.
- Explain
risky_tld— list, threshold, window, weight. No more scare badges. - Fix shared-infra handling — isolate Cloudflare/CDN/shared-hosting reputations.
- Publish verifiable false-positive stats by product, TLD, age, infra — with methodology.
- Notify customers when you correct a distribution that already went out.
- Allow ownership proof via DNS/email to trigger human review.
- Keep a public history — created → reviewed → changed.
- Nudge to step-up verification for new/unknown — not auto-block.
None of that helps phishers. It just stops punishing the innocent to make a dashboard look decisive.
What I want — simple, specific, on the record
- Manual review and removal of the false phishing label if no direct evidence exists.
- A plain-English breakdown of what pushed the score to 95 and how much
.meand the Cloudflare IP weighted. - Evidence category + date: blacklist hit, live scan, feed match, customer report, or pure heuristic/ML guess.
- An acknowledgment that false phishing labels cause real harm — and a commitment to fix the process.
If IPQS can show a real phishing page, credential harvest, or malicious campaign tied to my domain — type, date, source class — I’ll take it down today. If it can’t, the label comes down today. That’s basic accountability.
Sources & notes
- IPQualityScore, “Malicious URL Scanner API Response Parameters,” accessed Aug 29, 2026. View source
- IPQualityScore, “Malicious URL Scanner API Overview” and “Domain Reputation Test,” accessed Aug 29, 2026. API overview and domain reputation
- IPQualityScore, “Malicious URL Scanner API Response Parameters” and “Email Validation API Response Parameters,” accessed Aug 29, 2026. URL scanner docs and email validation docs
- Spamhaus, “The World’s Worst Top Level Domains” and “Reputation Statistics FAQ.” TLD report and statistics FAQ
- IPQualityScore, “Domain Reputation Test,” accessed Aug 29, 2026. View source
- IPQualityScore, “Malicious URL Scanner API Response Parameters,” accessed Aug 29, 2026. View source
- Cloudflare, “Cloudflare IP Addresses.” View source
- IPQualityScore, “About IPQS” and IPQS homepage, accessed Aug 29, 2026. About IPQS and IPQS homepage
- IPQualityScore, “About IPQS” and “Proxy and VPN Detection.” About IPQS and proxy and VPN detection
- IPQualityScore, “Privacy Policy” and “Terms of Service.” Privacy policy and terms
- IPQualityScore, “Reviews and Testimonials” and case studies. Reviews, Bolt, Phone.com, Toluna, ZinQ
- IPQualityScore, “Fraud Prevention Integrations,” and CrowdStrike Marketplace. IPQS integrations and CrowdStrike listing
- Trustpilot and Reddit user reports (anecdotal). Trustpilot, HomeNetworking, Cybersecurity Help, Tech Support
- Capterra and G2 reviews. Capterra and G2
- IPQualityScore, “Reviews and Testimonials,” “About IPQS,” “Account Creation Fraud Detection.” Reviews, About, account fraud
- IPQualityScore, “Malicious URL Scanner Advanced Options” and “Proxy Detection API Advanced Options.” URL scanner options and proxy detection options
- IPQualityScore, “Terms of Service.” View source
- IPQualityScore, “Contact Us” and “Report a False Positive.” Contact and false-positive form
- IPQualityScore, “Privacy Policy” and “Data Processing Agreement.” Privacy and DPA
Disclosure: This is a first-hand account and opinion about the author’s own domain and public IPQS documentation as of Aug 29, 2026. Third-party reviews are cited as anecdotes, not proven findings. If IPQS has non-public evidence, it should disclose category, source type, and date.