TLD reputation — down-score suspicious domain endings automatically.

Some top-level domains show up disproportionately often in spam and phishing. MailGuard assigns them a score penalty — and learns that score continuously from your own mail traffic instead of relying on a rigid block list.

How it works

If a mail contains sender addresses or URLs with a top-level domain rated as risky (e.g. .xyz, .top, .gq), it gets a score contribution towards spam. Each TLD rule carries either its own score or — when left empty — the system-wide default. The source of every rule is labelled transparently: static (shipped defaults), learned (auto-learned from traffic) or manual (set by the administrator).

Learns from your own traffic

MailGuard continuously observes which TLDs appear in spam and in ham mail. TLDs with a statistically high spam ratio are automatically scored, or their score is raised. Each TLD's spam ratio is shown colour-coded:

  • Grey — below 20 % spam ratio (unremarkable)
  • Orange — 20–50 % (heightened attention)
  • Red — above 50 % (high spam ratio)

So protection adapts to the real threat landscape of your domains — not to a generic average that is the same for every customer.

Operator lock — you stay in control

Not every unusual TLD is spam. If a customer runs a legitimate .xyz domain, the administrator can set the score manually and pin it with an operator lock. The locked score overrides automatic learning permanently — the TLD is never down-scored by mistake. Full control over automatic detection and manual exceptions, in one place.

Typical high-risk TLDs — preinstalled

MailGuard ships with a curated starting list of endings known from experience to be spam-heavy, at an elevated score:

.xyz · .top · .click · .loan · .win · .gq · .tk · .ml · .cf · .ga · .download · .stream · .racing · .trade

Every entry can be adjusted, disabled or extended — the list is a starting point, not a rigid corset.

Reputation that learns from your traffic?

TLD scores adapt to your real mail landscape — with an operator lock against false positives.

See pricing