Skip to main content

Domain Detection

Every domain in Chainara has been analyzed across six coverage areas: from the moment it was registered to what it's doing right now. Here's what we check and why it matters for catching crypto scams.

๐Ÿ”ค
Domain Patterns

Keywords, typosquats, suspicious TLDs, domain length, and brand impersonation. Scammers register domains like xrp-giveaway-ripple.com: we catch the pattern before a single victim visits.

๐Ÿ“‹
Registration Data

How old is the domain? Who registered it? Is the registrant hidden behind privacy masking? Scam infrastructure is almost always newly registered: domains under 30 days old are a strong signal.

๐Ÿ—๏ธ
Hosting Infrastructure

Hosting ASN, country, nameservers, SSL certificate issuer, and IP reputation. Bad actors rely on bulletproof hosting providers and free SSL to operate at scale: we fingerprint that infrastructure.

๐Ÿ›ก๏ธ
External Threat Feeds

Cross-referenced against VirusTotal (70+ engines), URLhaus, AbuseIPDB, and community reports. If the wider security community has already flagged it, we know immediately.

๐ŸŒ
Page Content

What the site actually says and does: giveaway language, wallet address forms, redirect chains, copied branding. This is what separates a newly registered legitimate site from a scam that hasn't been reported yet.

๐Ÿค–
AI Classification

An LLM evaluates all signals together and assigns a threat category with a confidence score. It catches edge cases that rules miss: like a domain that looks clean but whose content describes a fake XRP doubling event.

What You Getโ€‹

Every analyzed domain produces a risk score (0โ€“99), a risk level (low / medium / high / critical), a threat classification, and a full signal breakdown explaining exactly which factors drove the score.

0โ€“24 ยท Safe
25โ€“49 ยท Low Risk
50โ€“74 ยท Medium Risk
75โ€“89 ยท High Risk
90โ€“99 ยท Critical

Domains scoring 75+ trigger automatic alerts to your webhook endpoints. Domains scoring 90+ are auto-flagged as critical and appear at the top of the Domains list.

Detection Accuracyโ€‹

MetricRate
True positive rate94.2%
False positive rate2.1%
Avg. time to detection~2.5โ€“3.5 seconds (uncached, single domain, standard load)
Cached result latency<10ms