Skip to content
Suspicious60/100actionalert_only
VerdictIQSecurity Report

Subject

40gmail[.]com

Recommended actionalert_onlyIOC typedomainVerified2026-08-01

Risk level

Suspicious

score 60 / 100

Why this verdict

Evidence and analysis

VerdictIQ AIGenerated from 29 deterministic signals

40gmail[.]com is classified as suspicious with a risk score of 60/100: ambiguous posture; signals suggest concern but lack convergent evidence. The recommended downstream action is alert_only.

The risk model observed 29 signals (including 9 core signals) across 5 taxonomy groups (HTTP Crawling, WHOIS, DNS History, and others). The strongest indicators are Critical SSL CA Issue, Low-Control General Hosting Network, Frequent Nameserver Change, plus 26 additional supporting signals. Each signal carries its own trigger evidence and direction; signal fusion drives the calibrated tier assignment.

Recommended response. Surface to analyst review or SIEM correlation. Evidence is strong enough to warrant attention but not strong enough to block without context. For active investigation, run POST /verdict with the indicator to confirm the verdict against the current state of the domain. VerdictIQ's scoring recomputes today's signals on every call.

VerdictIQ AI re-states deterministic signal evidence as natural language. The verdict itself comes from the calibrated risk model, not the AI layer. Re-runs are stable and explainable.

Signal evidence

Top 10 of 29Showing all 29
  • Critical SSL CA IssuecoreHTTP CrawlingIt means that the SSL/TLS certificate presented by the domain failed critical validation checks.
  • Low-Control General Hosting NetworkcoreDNS HistoryIt indicates that the ASN belongs to hosting environments statistically associated with higher abuse rates, weak onboarding controls, or historically malicious operations.
  • Frequent Nameserver ChangecoreDNS HistoryIt indicates that both IP and NS (nameserver) records of a domain are changing frequently, a behavior known as 'Double-Flux'.
  • Flagged by Security VendorscoreThreat IntelligenceIt means that one or more commercial security vendors, including antivirus engines, sandboxes, or threat intelligence providers, have classified or reported the domain as malicious.
  • Newly Active HTTP Service DetectedHTTP CrawlingIt indicates that the domain has recently started serving web content over HTTP or HTTPS after a long period of inactivity or being newly registered.
  • Free-Issued SSL CertificateHTTP CrawlingIt indicates that the domain uses an SSL certificate issued by a free or automated Certificate Authority, such as Let's Encrypt.
  • Geolocation Mismatch or High-Risk RegionDNS HistoryIt indicates that the ASN shows geolocation anomalies, such as a mismatch between registry country and observed country or continent, or that it is associated with a country known for elevated abuse…
  • Limited Web Structure DetectedHTTP CrawlingIt means the domain hosts only a few subpages or internal links.
  • Newly-Activated DomainDNS HistoryIt indicates that the domain has recently become active and started responding to DNS queries after a period of inactivity or recent registration.
  • Low Content Density (Homepage)HTTP CrawlingIt means that the domain’s homepage contains a very small amount of textual or visual content.
  • Short-Term SSL Certificate ValidityHTTP CrawlingIt means the SSL/TLS certificate of the domain has an unusually short validity period, often lasting only days or weeks.
  • Newly-Issued SSL CertificateHTTP CrawlingIt indicates that the SSL certificate associated with the domain has been newly created or issued.
  • Small IP Block AllocationDNS HistoryIt indicates that the IP block allocated to the ASN is unusually small.
  • One-Off Popularity RisePopularity & BacklinkIt indicates that the domain's PageRank time series contains a single interior point where the rank improved (numerically decreased) by more than the extreme_spike_ratio (default 100x) compared to…
  • Unstable or Intermittent HTTP Service DetectedHTTP CrawlingIt refers to a domain whose HTTP or HTTPS service repeatedly switches between being online and offline within short time intervals.
  • Default Web Page DetectedHTTP CrawlingIt refers to a website that displays the default or placeholder page of a known web technology, such as 'Apache Default Page' or 'Nginx Welcome Page'.
  • Long-Registered DomaincoreWHOISIt indicates that the domain’s WHOIS record shows a long registration duration, typically 2, 5, or 10+ years.
  • SSL DV ValidationcoreHTTP CrawlingIt indicates that the SSL/TLS certificate’s Common Name (CN) or Subject Alternative Name (SAN) correctly matches the accessed hostname.
  • Long-lived HTTP Service DetectedcoreHTTP CrawlingThis term refers to a web service (HTTP/HTTPS) that has been continuously active and reachable for a long duration without significant downtime.
  • Global Popularity ScorecorePopularity & BacklinkIt refers to globally recognized, high-traffic domains with verified ownership and a long operational history, such as google.com or microsoft.com.
  • Long-Running IPcoreDNS HistoryThese refer to domains that have consistently resolved through DNS over a long period.
  • ASN Allocated Long Time AgoDNS HistoryIt means that the ASN was allocated many years ago and has a long operational history.
  • Gradual Popularity Growth DomainPopularity & BacklinkIt reflects a consistent and organic increase in user visits, backlinks, and visibility over time.
  • Stable NS Usage Long TermDNS HistoryIt shows that the domain has maintained the same nameserver configuration without fluctuations, suggesting predictable and well-managed DNS infrastructure.
  • Observed and Registered Geolocation ConsistencyDNS HistoryIt indicates that the observed geolocation of the IP matches its registered geolocation, suggesting a stable and expected geographic placement for the infrastructure at the time of observation.
  • Strict-Policy RIR RegionDNS HistoryIt indicates that the ASN is allocated by a regional internet registry known for strict allocation controls and strong abuse-handling processes, providing supportive safe context for the…
  • Country-Level IP Geolocation CentralizationDNS HistoryIt indicates that all currently active IP addresses of a domain are geographically concentrated in a single location scope, typically within one country.
  • Not Listed in Open-Source Threat FeedsThreat IntelligenceIt indicates that the domain does not appear in any public or open-source threat intelligence feeds, malware repositories, or IOC databases.
  • EU Compliance LocationDNS HistoryIt indicates that the IP address is consistently hosted within EU regions known for strict regulatory, privacy and operational compliance standards, reducing the likelihood of unmanaged or…

Read the full scoring methodology at /product/ioc-verdict or the canonical signal taxonomy at /signal-library.

More like this

Similar verdicts

Domains sharing signals with 40gmail[.]com. Pattern similarity often indicates campaign reuse or shared infrastructure.

Query any domain, not just this one

POST /verdict returns the same signals, score and recommended action for any indicator you send, computed against today's data.

Part of a curated wave, re-verified periodically; reports older than 90 days are de-indexed until re-verified. Dispute a verdict at reports@verdictiq.io, response within 5 business days. Trust & compliance →