Documented false positive • No evidence disclosed • No reply for 30+ days • IPQualityScore (IPQS)
REPUTATION DOSSIER — IPQS ACCOUNTABILITY
CASE # IPQS-95 • AUG 29, 2026 • STATUS: STILL FLAGGED
IPQS Investigation • First-hand test

IPQS called my spotless personal domain phishing.
Risk: 95/100. Proof: Zero.

I registered a lastname.me domain for 10 years as a permanent private email. No spam. No malware. No content to even judge. Valid DNS, SPF, DMARC. IPQualityScore flagged it as malicious anyway — and ghosted my appeal for a month.

IPQS Risk Score
95/100
Phishing: true • Suspicious: true
IPQS says 85+ = High Risk / Likely Malicious

What IPQS itself admits in the same report

Spammingfalse
Malwarefalse
DNS validtrue
SPF / DMARCenabled
Parkedfalse
Hosted contentfalse
Category N/A
Domain rank 0 (new)
Risky TLDtrue (.me)
Redirected true
In other words: “We found nothing, validated your auth, saw no content — but you’re a phisher.” That’s not detection. That’s prejudice by profile.

If you sell suspicion as a service, you must show your work and fix your mistakes fast. IPQS did neither. That isn’t “caution” — it’s reckless labeling at scale.

!
The line IPQS crossed: “Unknown” or “insufficient history” would have been honest for a two-month-old personal domain. IPQS instead published phishing: true with 95/100 — an accusation of a cybercrime — with nothing to back it.

Clean on every check, guilty in the verdict

A little over two months ago I registered a new personal domain. Not a burner, not a funnel — a first@lastname.me identity I intend to keep for decades. Ten-year registration, proper DNS, SPF and DMARC locked down, not parked, not for sale, not impersonating anyone.

IPQS’s own lookup confirmed it. Then it convicted it anyway.

I filed a correction request about a month ago. As of Aug 29, 2026: no evidence, no ticket update, no human reply, no change. The smear just sits there, rentable to any customer who pays.

95 is a weapon, not a warning

IPQS docs describe the risk score as a “confidence” estimate and say 85+ is high risk / likely malicious. The phishing boolean is described as indicating malicious phishing behavior. View source

Sure, IPQS can claim “95 isn’t a probability.” Users, analysts, and automations don’t care. IPQS shows clients how to auto-flag when phishing==true or risk > 85, and pitches the product for screening signups, transactions, and email submissions. API overview and domain reputation

IPQS wants credit when its signal stops fraud. It wants distance when the same signal harms an innocent. You don’t get both.

The self-contradicting report

SignalFinding
Malwarefalse
Spammingfalse
Hosted contentfalse — nothing to judge
CategoryN/A
DNS / SPF / DMARCvalid / enabled
Parkedfalse
Overall verdictphishing: true — 95/100

What tipped it? A fake login? Credential form? Skimmer JS? Malicious redirect chain? Customer complaint? Blacklist hit? ML guess on the name? The report doesn’t say. A damaging, specific accusation with no disclosed evidence is indefensible.

.me is not a crime — guilt by TLD is profiling

IPQS marks .me as “risky TLD” — supposedly frequent abuse — but publishes no list, no threshold, no window, no weight. email validation docs and URL scanner docs

Yes, abuse rates vary by TLD and researchers track them. Spamhaus itself says it’s a mix of ratio and volume and involves judgment calls. TLD report and statistics FAQ That’s why it should be a weak contextual hint, not a conviction. .me is the textbook personal namespace. Criminalizing the neighborhood to judge the house is lazy.

Furious but fair: If .me drove the 95, defend it with data. If it didn’t, stop displaying “Risky TLD: true” as scare tinsel next to a 95.

New ≠ malicious — “unknown” is not “guilty”

Of course attackers use fresh domains. But every legitimate domain was new once. Without abuse, traffic, or content, the honest label is unknown / insufficient data.

IPQS itself admits not every new or unusual site is malicious and single signals rarely prove abuse. View source Yet my output wasn’t “new — can’t tell.” It was “phishing: true.” One is humility. The other is a false accusation with a scientific-looking number slapped on it.

Redirect ≠ phishing

“Redirected: true” sounds scary until you remember the web runs on redirects — HTTP→HTTPS, root→www, old→new, domain→profile. IPQS defines it only as whether a URL redirects, not that it’s malicious. View source Without a bad destination, cloaking, or threat-feed hit, this means nothing.

That Cloudflare IP proves nothing about me

Cloudflare’s proxied hostnames sit behind shared, anycast IPs used by countless unrelated domains. View source You cannot launder strangers’ reputations onto my domain through a shared front door. Did IPQS weight the shared IP? It won’t say. Either answer is damning without transparency.

The black-box business — honeypots, feeds, feedback loops

IPQS says it’s been around since 2011, serves thousands of businesses, and scores 100M+ daily transactions across IP, email, phone, device, proxy/VPN, and URL reputation. About IPQS and homepage Intel comes from honeypots, blocklists, forensics, ML, and customer feedback, with consortium sharing. proxy and VPN detection and Privacy policy

That flywheel is powerful when right — and corrosive when wrong. Bad signals get amplified as they circulate. Which is why correction speed and evidence quality matter more than marketing.

IPQS flaunts logos and case studies and touts integrations with Splunk, Palo Alto Cortex XSOAR, CrowdStrike, Rapid7, ThreatConnect, QRadar, MISP, OpenCTI, SpiderFoot, etc. Reviews and integrations and CrowdStrike listing Caveat: not every logo uses the URL/domain product that flagged me — but the point stands: these scores leak into enterprise dashboards, playbooks, and signup flows. The victim sees “registration denied” and never knows IPQS pulled the trigger.

This isn’t a one-off — a pattern of complaints

On Trustpilot and Reddit you’ll find the same story: clean sites or residential IPs labeled scam/proxy/VPN, appeals met with silence. Trustpilot, HomeNetworking, Cybersecurity Help and Tech Support These are anecdotes, not lab proofs — but the shape repeats. Meanwhile IPQS also enjoys 4.9/5 on business review sites. Capterra and G2 Of course the buyer likes “more blocks.” The person blocked — not the customer — eats the cost. Without a real appeals process, the harmed have no leverage.

99.99% hype vs “as is” fine print

Marketing screams “lowest false-positive rates” and “prevent fraud without false positives.” Reviews, About and account fraud detection Try finding a public benchmark, confusion matrix, or false-positive breakdown. You won’t. Yet docs quietly admit stricter settings raise false positives. URL scanner options and proxy detection options And Terms say the service is “as is” with no warranty of accuracy and capped liability. View source

Translation: Marketing: “Trust us about other people.” Legal: “We might be wrong and we’re barely responsible.” When your product is reputation, that’s a tell.

Support promised hours. I got a month of silence.

IPQS advertises quick replies and 24–48h review for IP false positives. Contact and false-positive form For domains/URLs there’s no dedicated, clearly labeled appeal flow with a case number, status page, or written reason. I used what exists. A month later — nothing. Even a reasoned rejection would be more useful than the void. When your system brands someone’s property a phish, “submit and pray” isn’t due process.

Why customers of IPQS should be angry too

False positives don’t just hurt domain owners. They burn your funnel: good users rejected, good transactions blocked, good emails bounced, analysts chasing ghosts, support drowning, sales lost without ever knowing why. Teams stop trusting alerts, build sloppy allowlists, and weaken real security. Measuring “how often we blocked when IPQS said block” is circular — you’re grading IPQS with its own homework.

What IPQS must do — immediately

  1. Stop calling “unknown” phishing. Use unknown / insufficient data / low confidence unless you have direct evidence.
  2. Ship a real domain/URL appeal flow — case numbers, status page, SLA, written reasons.
  3. Show reason codes and source type — new, low history, TLD stats, redirect, shared CDN, heuristic/ML, feed hit, customer report — plus evidence date.
  4. Explain risky_tld — list, threshold, window, weight. No more scare badges.
  5. Fix shared-infra handling — isolate Cloudflare/CDN/shared-hosting reputations.
  6. Publish verifiable false-positive stats by product, TLD, age, infra — with methodology.
  7. Notify customers when you correct a distribution that already went out.
  8. Allow ownership proof via DNS/email to trigger human review.
  9. Keep a public history — created → reviewed → changed.
  10. Nudge to step-up verification for new/unknown — not auto-block.

None of that helps phishers. It just stops punishing the innocent to make a dashboard look decisive.

What I want — simple, specific, on the record

If IPQS can show a real phishing page, credential harvest, or malicious campaign tied to my domain — type, date, source class — I’ll take it down today. If it can’t, the label comes down today. That’s basic accountability.

Suspicion is easy. Accuracy is hard. It’s easy to call anything new, uncommon, redirected, or low-traffic “suspicious” and wrap weak correlations in a scientific-looking number. The hard part is admitting uncertainty, showing your work, and correcting bad data before it spreads. IPQS failed all three — then went silent. That’s not caution. That’s negligence.

Sources & notes

  1. IPQualityScore, “Malicious URL Scanner API Response Parameters,” accessed Aug 29, 2026. View source
  2. IPQualityScore, “Malicious URL Scanner API Overview” and “Domain Reputation Test,” accessed Aug 29, 2026. API overview and domain reputation
  3. IPQualityScore, “Malicious URL Scanner API Response Parameters” and “Email Validation API Response Parameters,” accessed Aug 29, 2026. URL scanner docs and email validation docs
  4. Spamhaus, “The World’s Worst Top Level Domains” and “Reputation Statistics FAQ.” TLD report and statistics FAQ
  5. IPQualityScore, “Domain Reputation Test,” accessed Aug 29, 2026. View source
  6. IPQualityScore, “Malicious URL Scanner API Response Parameters,” accessed Aug 29, 2026. View source
  7. Cloudflare, “Cloudflare IP Addresses.” View source
  8. IPQualityScore, “About IPQS” and IPQS homepage, accessed Aug 29, 2026. About IPQS and IPQS homepage
  9. IPQualityScore, “About IPQS” and “Proxy and VPN Detection.” About IPQS and proxy and VPN detection
  10. IPQualityScore, “Privacy Policy” and “Terms of Service.” Privacy policy and terms
  11. IPQualityScore, “Reviews and Testimonials” and case studies. Reviews, Bolt, Phone.com, Toluna, ZinQ
  12. IPQualityScore, “Fraud Prevention Integrations,” and CrowdStrike Marketplace. IPQS integrations and CrowdStrike listing
  13. Trustpilot and Reddit user reports (anecdotal). Trustpilot, HomeNetworking, Cybersecurity Help, Tech Support
  14. Capterra and G2 reviews. Capterra and G2
  15. IPQualityScore, “Reviews and Testimonials,” “About IPQS,” “Account Creation Fraud Detection.” Reviews, About, account fraud
  16. IPQualityScore, “Malicious URL Scanner Advanced Options” and “Proxy Detection API Advanced Options.” URL scanner options and proxy detection options
  17. IPQualityScore, “Terms of Service.” View source
  18. IPQualityScore, “Contact Us” and “Report a False Positive.” Contact and false-positive form
  19. IPQualityScore, “Privacy Policy” and “Data Processing Agreement.” Privacy and DPA

Disclosure: This is a first-hand account and opinion about the author’s own domain and public IPQS documentation as of Aug 29, 2026. Third-party reviews are cited as anecdotes, not proven findings. If IPQS has non-public evidence, it should disclose category, source type, and date.