Know a domain is hostile before it costs you anything to find out.
A curated platform-wide list of known-malicious domains is consulted first and treated as authoritative. Domains it does not cover can be checked against external reputation feeds, with every verdict cached so the same lookup is never paid for twice.
A platform-maintained list, managed centrally, takes precedence over anything external.
With no feed enabled — the default — no external call is ever made.
Results are stored with a configurable lifetime, which keeps free-tier rate limits comfortable.
The curated list is checked first because it represents deliberate platform judgement, with a severity that maps directly to score. Only when a domain is absent from it are external feeds consulted, and only those you have explicitly enabled and supplied a key for.
A feed that errors, times out or rate-limits contributes nothing. Reputation is a corroborating signal, so its absence lowers confidence rather than manufacturing a false verdict.
Large public phishing lists are handled differently from per-domain lookups: they are imported on a schedule into the same verdict cache, so matching a bulk list costs a local read rather than a network round trip. The importer is inert until a list is configured.
A domain with no reputation record is not safe — it is unverified, which is a meaningfully different thing. VeridLock reports it that way, and the decision engine treats an unverified reputation as a reason to require confirmation rather than as a pass.
The platform list is checked and, on a hit, its severity drives the score directly.
Previously resolved verdicts, including imported bulk lists, are read locally.
Enabled external feeds are consulted for anything still unresolved.
The verdict is stored for its configured lifetime.
The outcome
Known-bad infrastructure is stopped on the first contact, without making every scan depend on a third party being available.
Set up your organization in minutes — no inbound migration required.