Skip to content

High Number of Inbound Links

It indicates that the domain receives a large number of backlinks from diverse external sources across the internet. This often reflects high popularity or trustworthiness and is a common pattern among legitimate websites such as news platforms or social media domains.

Analyst Q&A

What this signal answers

Three questions every analyst asks before acting on this signal.

What it detects01

What does 'High Number of Inbound Links' mean in domain intelligence analysis?

It indicates that the domain receives a large number of backlinks from diverse external sources across the internet. This often reflects high popularity or trustworthiness and is a common pattern among legitimate websites such as news platforms or social media domains.

Why it matters02

How is the threshold for 'High Number of Inbound Links' determined?

The threshold is defined based on statistical analysis of global backlink distributions. This value is derived from large-scale data studies and used as a fixed reference point in analysis. Domains exceeding this statistically established threshold are flagged as having a high number of inbound links, allowing analysts to distinguish between natural link growth and potential link manipulation or spam-like behavior.

How analysts use it03

Can a domain with many inbound links still be malicious?

Yes. Although rare, some malicious actors artificially generate backlinks to appear reputable or to manipulate search rankings. Therefore, a high number of inbound links alone does not guarantee legitimacy—it must be correlated with other indicators such as domain age, registration behavior, and historical threat intelligence data.

Evidence shape

What High Number of Inbound Links looks like in the response

A realistic shape of the entry the engine appends to the risk_signals array when this signal fires. Evidence keys are subgroup-default; per-signal overrides documented in the API reference.

json
{
  "slug": "a_lot_of_inlink",
  "name": "High Number of Inbound Links",
  "group": "relational_intelligence",
  "subgroup": "web_relational_infra",
  "direction": "safe",
  "evidence": {
    "inlink_count": 312,
    "malicious_outlink_count": 4,
    "visited_by_malicious_count": 2,
    "backlink_quality": "mixed"
  }
}
See in API reference
Siblings

Peers in Web Relational Infrastructure

2 other signals share the same subgroup. They detect related behaviors and often co-fire on the same IOC.

Active Association with Malicious Domain

It indicates that the domain was contacted or interacted with by a known malicious domain during the same session or act

MaliciousCore
Malicious External Link

It refers to outbound links on a webpage that point to malicious or restricted domains. These links are often injected i

MaliciousCore
In the wild

See High Number of Inbound Links fire on real IOCs

The Verdict Gallery is a curated stream of real verdicts. Filter by this signal to see exactly which IOCs it caught, what other signals fired alongside it, and what the engine recommended.

Open Verdict Gallery
Pre-filtered to High Number of Inbound Links. See real IOCs this signal caught and the verdicts the engine returned.
Verdicts ✓

Start free, in five minutes

100 IOCs/day on the free tier, LLM layer included. No card required.