How the Dralvia score works
Every Dralvia scan ends with a number from 0 to 100 and one of three verdicts. This guide explains how that number is built, so you can read it, check it, and disagree with it.
The short version
- The score counts risk evidence found in this scan. Higher means more, and stronger, evidence of phishing or fraud.
- 0 to 20 is Safe, 21 to 69 is Caution, 70 to 100 is Avoid.
- Every point comes from a named finding you can see in the report, under Why this score.
- Safe means we found no meaningful risk evidence. It is not a promise that the page is honest.
The three verdicts
The score is not a percentage or a probability. It is a sum of weighted findings, capped at 100, and it always maps to exactly one verdict:
This scan found no meaningful risk evidence.
Go ahead with normal care. If the message that brought you here asks for a password, a payment or a code, still check that the request itself makes sense.
Some risk evidence, but not enough to call it phishing.
Do not enter passwords, card details or codes. Reach the company through its app or an address you type yourself, and check there.
Strong evidence of phishing, fraud or malware.
Close the page. Do not sign in, pay or download anything. If you already did, follow I clicked a phishing link: what to do now.
Where the points come from
A scan opens the link in an isolated browser and runs a set of checks. Each check can raise findings, and each finding carries a weight. The findings fall into these groups:
- Threat feeds and blocklists: the address or domain is already listed as phishing or malware.
- Brand imitation: a lookalike name (paypa1, micros0ft), a known brand's logo or icon on a domain that brand does not own, or a brand name placed in a subdomain to look official.
- Page content: a login, card or one-time-code form, a form that sends what you type to another site, a seed-phrase prompt, or hidden and scrambled scripts.
- Redirects: how many hops the link takes, whether it jumps to another site, and whether it hides where it ends up.
- Domain and registration: how new the domain is, its registration record, its ending (.com, .top, .xyz) and the shape of the address.
- Certificate: whether the site has a valid certificate for its own name.
- DNS and hosting: where the site lives and what else is hosted there.
- Campaign links: whether the link leads somewhere that earlier scans already found in a phishing campaign.
One moderate finding rarely convicts a site on its own. When several independent kinds of evidence appear together, for example a domain registered this week, a login form and a bank's logo, Dralvia adds a correlation finding with a high weight. That is how real phishing reaches Avoid without a single weak signal doing it.
Outside reputation services count too. When one of them reports the site as malicious, the score rises to at least 68, and reports from two or more put it in Avoid.
What lowers a score, and why you can see it
Three rules pull a score down. Each one is written into the report with the score before and after, so nothing is removed silently.
- A brand's own domain: a scan of a site that is, or sits under, a known brand's real domain scores 0, unless it finds something critical such as a blocklist hit, an invalid certificate or a brand-new registration.
- An established domain: a long-standing domain with a valid certificate, or a long clean history in our scans, is capped at 15 unless this scan finds strong phishing evidence (a login form, brand imitation, a blocklist hit and similar).
- Security hygiene alone: missing security headers are a hardening gap, not phishing. When they are the only findings, the score stays at 6 or below.
None of these rules is based on a name alone. A lookalike of a brand never inherits the brand's trust, and strong evidence always overrides an established domain's cap.
Reading your report
Start with the verdict
Safe, Caution or Avoid tells you what to do. The number tells you how much evidence sits behind it.
Open Why this score
It lists the points per group and every adjustment, so the total can be checked by hand. If the parts do not add up to the score, that is a bug and we want to hear about it.
Look at the evidence
The screenshot shows what the page looked like when we opened it, the redirect chain shows every hop, and the certificate and domain details show who is behind the address.
Check the scan time
The report says whether it is a fresh scan or a cached result. A stable Safe result can be reused for up to 30 days; riskier results are refreshed sooner. Ask for a fresh scan when it matters.
What a score cannot tell you
- A scan is a snapshot. A page can change after we look at it, and some phishing kits show a harmless page to scanners and the real one to victims.
- A real site can carry a scam. A genuine form builder, file-sharing or document site can be Safe as a site while the form or file on it asks for your password. The question is always also: why is this asking me for that?
- A score is about the link, not the message. A Safe link in an email that pressures you to pay an unexpected invoice is still a reason to call the sender on a number you already know.
- We can be wrong. Signed-in users can report a result under Think this result is wrong?, and a security analyst reviews it by hand. The original result stays on record while they look.
Check a link now, free
Paste the link you are unsure about. It opens in an isolated browser on our side, never on your device, and you get a verdict with the evidence behind it. No account needed.
Questions people ask
- Does a score of 0 mean the site is guaranteed safe?
- No. It means this scan found no risk evidence, or the site is a known brand's own domain with nothing critical found. No scanner can promise that a page is honest, only report what it found.
- Why did a well-known site get Caution?
- Usually because the address was not the brand's own domain, or the scan found something real, such as an invalid certificate or a login form on an unexpected host. Open Why this score to see exactly which findings added the points.
- Can the same link get a different score tomorrow?
- Yes. Pages change, domains get listed on blocklists, and new evidence appears. Run a fresh scan when you need today's answer.
- Is the score the same in the app, the API and the reports?
- Yes. The same scan produces the same score and the same verdict everywhere it is shown.
More guides
Eight quick checks to tell a real link from a phishing link: see the real address, read the domain the right way, spot lookalikes, and scan it for free.
A 30-second checklist for suspicious emails: the real sender, the pressure, the links, the attachments and the request. Plus what to do when you find one.
Clicked a phishing link or typed your password into a fake page? The steps to take right now, depending on what happened, in the order that limits the damage.