Skip to main content

Domain Submission Classification

The following table defines the Domain Trust Platform Taxonomy, which standardizes the data fields and classifications used for domain submissions.
Each entry lists the field title, its possible values, and a description of those values.


Field TitleField ValueField Value Description
ActivityactiveDomain is active
blockedDomain is blocked
non-existentDomain does not exist
suspendedDomain has been suspended
taken-downDomain has been taken down
Abuse TypebotnetsDomain involved in botnet operations
malwareDomain hosting or distributing malware
pharmingDomain redirecting users to malicious sites
phishingDomain used for phishing attacks
spamDomain used for spam activities
Classificationdefinitely-cleanDefinitely not malicious; designed to allow loading of allowed lists, negative false positives, or investigations underway
definitely-maliciousDefinitely malicious (in the provider’s opinion)
possibly-maliciousPossibly malicious
probably-maliciousProbably malicious (in the provider’s opinion)
Provider Ratinghigh-confidenceHigh confidence provider such as police officer or judge
med-confidenceMedium confidence provider with high-scale SOC such as CERTs/CSIRTs, ISPs, and TELCOs
low-confidenceLow confidence provider such as anti-spam and anti-scam contributors
predictivePredictive intelligence provider such as artificial intelligence contributors
trialTrial or evaluation provider
Provider RoleICANNInternet Corporation for Assigned Names and Numbers
otherOther type of provider
registrarDomain registrar
registryDomain registry operator
resellerDomain reseller
Sourceexternal-reportedReported by external source
self-reportedSelf-reported by the provider
Type (optional)brand-spoofDomain spoofing legitimate brands
fraudDomain used for fraudulent activities
Static FieldsCommentsAdditional comments or notes
Date IdentifiedDate the domain was found to be malicious or suspicious
DomainFull domain name being reported
Is BlockedWhether the domain is blocked by Quad9
ProviderName of the information provider
Registration DateDate the domain was registered with a registrar
Root DomainRoot domain (e.g., example.com)
SLDSecond-level domain (e.g., example in example.com)
Source NameName of the reporting source
SubdomainSubdomain portion (e.g., www in www.example.com)
TLDTop-level domain (e.g., .com, .org)
URLsAssociated URLs with malicious activity

Note: This taxonomy defines the standardized field values accepted and returned by Domain Trust’s APIs and the web interface.