TLD reputation — down-score suspicious domain endings automatically.
Some top-level domains show up disproportionately often in spam and phishing. MailGuard assigns them a score penalty — and learns that score continuously from your own mail traffic instead of relying on a rigid block list.
How it works
If a mail contains sender addresses or URLs with a top-level domain rated as risky (e.g. .xyz, .top, .gq), it gets a score contribution towards spam. Each TLD rule carries either its own score or — when left empty — the system-wide default. The source of every rule is labelled transparently: static (shipped defaults), learned (auto-learned from traffic) or manual (set by the administrator).
Learns from your own traffic
MailGuard continuously observes which TLDs appear in spam and in ham mail. TLDs with a statistically high spam ratio are automatically scored, or their score is raised. Each TLD's spam ratio is shown colour-coded:
- Grey — below 20 % spam ratio (unremarkable)
- Orange — 20–50 % (heightened attention)
- Red — above 50 % (high spam ratio)
So protection adapts to the real threat landscape of your domains — not to a generic average that is the same for every customer.
Operator lock — you stay in control
Not every unusual TLD is spam. If a customer runs a legitimate .xyz domain, the administrator can set the score manually and pin it with an operator lock. The locked score overrides automatic learning permanently — the TLD is never down-scored by mistake. Full control over automatic detection and manual exceptions, in one place.
Typical high-risk TLDs — preinstalled
MailGuard ships with a curated starting list of endings known from experience to be spam-heavy, at an elevated score:
.xyz · .top · .click · .loan · .win · .gq · .tk · .ml · .cf · .ga · .download · .stream · .racing · .trade
Every entry can be adjusted, disabled or extended — the list is a starting point, not a rigid corset.
Reputation that learns from your traffic?
TLD scores adapt to your real mail landscape — with an operator lock against false positives.
See pricing