gateway-update[.]io is classified as high with a risk score of 79/100: elevated-risk posture; converging signals indicate intent. The recommended downstream action is alert_only.
The risk model observed 8 signals (including 3 core signals) across 5 taxonomy groups (DNS History, HTTP Crawling, Relational Intelligence, and others). The strongest indicators are Newly-Activated Domain, Self-Signed SSL Certificate, Malicious Outbound Link, plus 5 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.
Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /enrichwith the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.