← Back to blog
White Pages & Infrastructure · 2026-07-29 · 9 min read

Domain Reputation for Media Buyers: Check It Before You Burn It

How domain reputation works for media buyers: DNS blacklists, Safe Browsing, VirusTotal, IP neighborhoods — and how to check a domain before you spend.

Domain reputation is the accumulated verdict of blacklists, Safe Browsing, and scanner engines about your domain and its IP. Check it before every campaign: run the domain against 30+ DNS blacklists, query Safe Browsing status, and review VirusTotal verdicts — all free, all public, all visible to reviewers too.

The uncomfortable part: domains arrive pre-burned. The expired domain you bought at auction this morning may carry listings from a previous owner's spam run two years ago. The seller won't mention it. Many sellers don't know. And the first time most buyers find out is the rejection email, after the spend.

This article is the reference version: what these systems actually are, how a domain gets listed, how to check one properly, and when a listing is fixable versus when the domain is done.

What domain reputation actually is

There is no single reputation score for a domain. What reviewers, ad platforms, browsers, and security vendors call "reputation" is a composite of verdicts from systems that each track a different slice of abuse:

No single one of these is "the" reputation. But a bad verdict in any of them can poison a review, because ad platforms and their security vendors consult overlapping sources. How much weight these signals carry inside a review is its own topic — I broke that down in trust signals for white pages. Here we stay on the systems themselves.

The three systems that build it

DNS blacklists

A DNSBL is a queryable "known bad" list. Mail servers were the original consumers: connect, look up the sender's IP or domain, reject if listed. The model spread — abuse desks, security vendors, and ad platforms now consult overlapping sets of these lists.

Domains get listed for a handful of recurring reasons:

The part that matters for media buyers: listings persist through ownership changes. Reputation attaches to the domain, not to whoever currently pays for it.

Google Safe Browsing

Safe Browsing is the listing with the most direct consequences for an advertiser. It powers the red "Deceptive site ahead" interstitial in Chrome and other browsers, and in most cases a flagged page behind a Google Ads campaign is a mechanical rejection — the platform will not send its users to a page its own browser warns about.

Sites get flagged for four broad reasons: hosting malware (usually via compromise, not intent), phishing pages, social-engineering patterns like fake system warnings or fake download buttons, and unwanted software distribution. Note the first one. You don't have to do anything wrong. A hacked plugin on your own white page can get you flagged, and the first place you'll notice is a rejection or a red warning screen.

VirusTotal

VirusTotal runs a submitted URL or domain past dozens of scanner engines and archives the verdicts. Reviewers and security teams treat it as a quick consensus check: what's the count?

Reading it takes some judgment:

The archived history matters too: verdicts, passive DNS, and past resolutions stay on record. A domain that was flagged eight months ago and "cleaned" still shows the trail.

The IP neighborhood you inherit

Your domain resolves to an IP. That IP sits in a block, the block belongs to a hosting network, and the network has a reputation of its own.

Cheap hosting ranges accumulate throwaway domains. When abuse systems can't keep up domain by domain, they list whole ranges at a time, and some vendors score entire networks. If your clean domain resolves into a dirty range, you inherit the neighborhood's verdict — no support ticket fixes the other two hundred tenants.

This is also why "we host thousands of landing pages here" is a warning rather than a reassurance when the host is popular with churn-and-burn operators. And a mismatch between where the business claims to be and where the infrastructure actually lives is a quiet flag on top.

How to check a domain before money touches it

The manual route works, and it teaches you what the data means:

  1. Blacklist check. Query the domain and its IP against the major DNSBLs. One list at a time, by hand — fine for one domain, dead by the tenth.
  2. Safe Browsing. Check the domain's status. If there's a warning, the advisory usually names the category.
  3. VirusTotal. Search the domain. Read the verdict count and the history tab, not just the headline number.
  4. WHOIS and archive. Registration date, and what the domain hosted in its previous life. A casino doorway in another language is a walk-away.

The batch route: AdInfraCheck runs reputation as part of 17 modules per domain — 30+ DNS blacklists, Safe Browsing, VirusTotal — against live sources at run time, so the result reflects right now, not a cached score. Each module reports separately, so you see whether it's the blacklist layer or the Safe Browsing layer that failed.

For buying decisions there's compare mode: batch A against batch B on the same 17 parameters. When two sellers each swear their domains are clean, the reports settle it. That check belongs inside a broader pre-launch pass — the full version is the white page checklist.

Fixable or burned: reading the results

Not every bad verdict means "throw the domain away":

Source Typical cause Fixable? How
DNS blacklist listing Previous owner's spam run Sometimes Fix the cause, then follow each list's removal process; some lists are effectively permanent
Safe Browsing flag Compromised site, injected code Usually Clean the site fully, then request a review; the warning lifts after re-scan
VirusTotal flags False positive or real payload Usually Re-scan after fixing; dispute false positives engine by engine — slow, but possible
IP neighborhood Host's other tenants No Move hosts, or walk away from the setup
Bad domain history Previous scam content No This is what the pre-purchase check is for

The distinction that saves money: fixable means the cause is yours to remove. A hacked site is yours — clean it. A dirty IP range is not yours. A domain whose past life was a scam doorway carries that history regardless of what you build on it.

The worst version of this story is discovering it after launch: spend goes out, ads get rejected, and now the ad account has a disapproval history attached to a domain you could have walked away from for free.

FAQ

I checked a domain a month ago. Is that check still valid?

Treat it as stale. Reputation is live data: listings appear and lift constantly, and a domain that was clean last month can be flagged today — especially on shared hosting. Check the same week you launch; same day is better.

Can a clean domain get flagged after launch?

Yes, and it usually isn't your fault in the way you'd expect. Compromised CMS installs, injected third-party scripts, and neighbor abuse on a shared IP are the common causes. This is why re-running checks after a rejection wave matters: sometimes the creative is innocent and the infrastructure underneath it got dirty mid-flight.

One VirusTotal engine flags my domain. Am I burned?

Usually not. A single flag from an obscure engine is frequently an aggressive heuristic — dispute it and monitor. Multiple flags from major engines is the pattern that means the domain is done. The count and the names matter more than the raw verdict.

Should I buy aged domains to skip reputation problems?

Aged is not the same as clean. An aged domain with a scam doorway in its past is worse than a fresh domain with no past at all. If you buy aged, check history and reputation before money moves — checking domains you don't own yet is one of the best uses of these tools.

Can I delist a domain myself?

For many DNSBLs, yes: fix the cause, then use the list's removal process — the reputable lists publish one. Safe Browsing lifts after you clean the site and request a review. What's not delistable is history and neighborhood. Those you route around, not remove.

Check your domains before the spend

Every source in this article — 30+ DNS blacklists, Safe Browsing, VirusTotal — is queried live, per domain, by AdInfraCheck, alongside WHOIS, DNS, SSL, and the rest of its 17 modules. Paste one domain or a whole batch, or run two batches against each other in compare mode before you buy.

It's free with an account, and it takes less time than reading one rejection email.