URL Reputation — How to Use and Interpret a Check
Use the OpenTrojan URL Reputation checker to normalize a URL and compare its domain against threat-intelligence records, and weigh a hit responsibly.
Quick Answer
URL Reputation normalizes a URL and checks its domain against recorded threat-intelligence; a hit is corroborating evidence to weigh with the full URL context, not a proof of phishing.
Definition
URL Reputation normalizes a URL and compares its domain against known threat-intelligence records.
What it is
URL Reputation (/tools/url/) takes a URL, normalizes it, extracts the domain, and checks that domain against recorded threat-intelligence.
How to use
- Open
/tools/url/. - Paste a full URL (with scheme and path).
- Review the reputation result for the host domain.
Interpretation
- Domain on a record — corroborating signal that the domain has been tied to malicious/abuse activity; consider it meaningful but weigh the full URL (freshness, lookalike, redirects).
- No record — no known association here; legitimate-but-new and malicious-but-unseen both look like “no record”.
Limitations
- Reputation is domain-level and record-fresh; it reflects what has been reported, not a real-time judgment.
- A single clean domain check does not clear a URL — inspect the path, query and any redirect for obfuscation.
Privacy
The URL is sent to the API for normalization/check; it is not placed in browser history or logged as raw input beyond the lookup, consistent with platform analytics policy.
Next steps
- Parse the URL structure locally first → URL Analyzer guide.
- Weigh signals in a full triage → Malicious URL analysis playbook.
References
Ask OpenTrojan's evidence-backed assistant about this topic — answers cite their sources.