Assessed Signals
Opportify evaluates dozens of signals across multiple intelligence sources to produce a composite risk score. This page documents the baseline categories of signals we can assess. The actual signals evaluated for any given request depend on the inputs you provide — for example, email signals are only assessed when an email address is included, and behavioral signals require the JS Script integration.
Our signal library is dynamic and continuously expanding. The signals listed here represent the foundational categories we evaluate. We regularly add new detectors, refine scoring weights, and introduce novel signal sources without requiring any changes on your end.
For security reasons, we do not disclose the full list of signals, internal scoring weights, or detection thresholds. Publishing every signal in detail would give fraudsters a blueprint to evade detection. Our goal is transparency about what we assess, while keeping how we score it unpredictable to adversaries.
Risk Score Overview
Every analysis produces a risk score ranging from 200 (lowest risk) to 1000 (highest risk), along with a human-readable risk level:
| Score Range | Level | Interpretation |
|---|---|---|
| ≤ 300 | lowest | Very low risk — likely legitimate |
| 301–400 | low | Low risk — minor signals present |
| 401–600 | medium | Moderate risk — warrants review |
| 601–800 | high | High risk — likely fraudulent |
| > 800 | highest | Very high risk — strong fraud indicators |
The final score is a weighted composite of signals from six intelligence sources: email, IP, content, session (behavioral), velocity, and geographic consistency.
Email Intelligence Signals
Assessed when an email address is provided.
Deliverability & Mailbox
| Signal | Description |
|---|---|
| SMTP verification | Real-time probe to determine if the mailbox exists and accepts mail |
| Deliverability classification | Classified as yes, no, or unknown |
| Catch-all detection | Whether the domain accepts mail to any address |
| Mailbox full detection | Whether the mailbox is over quota |
| Reachability | Whether the domain's mail infrastructure is reachable |
Domain Classification
| Signal | Description |
|---|---|
| Disposable domain detection | Temporary/throwaway email providers |
| Free provider detection | Well-known free email services (Gmail, Yahoo, etc.) |
| Provider identification | Resolved email provider name |
| Email type classification | private, free, or disposable |
DNS & Authentication
| Signal | Description |
|---|---|
| MX record validation | Whether valid mail exchange records exist |
| SPF record validation | Sender Policy Framework presence and validity |
| DKIM configuration | DomainKeys Identified Mail selector presence |
| DMARC validation | Domain-based Message Authentication policy |
| MX relay detection | Whether the domain routes through a relay service |
| MX relay categorization | security-gateway, alias-forwarder, or transactional-relay |
Domain Enrichment
| Signal | Description |
|---|---|
| Domain age | How long the domain has been registered |
| Domain expiration | Expiry status (expired, expiring soon, recently expired) |
| Registrar identification | Domain registrar |
| SSL certificate validity | Whether the domain has a valid SSL cert |
| A record validation | Whether the domain resolves to a valid IP |
| Blocklist status | Whether the domain appears on known blocklists |
| MTA-STS / BIMI status | Email security policy indicators |
Address Structure
| Signal | Description |
|---|---|
| Plus-addressing (tag) detection | Identifies user+tag@domain patterns |
| Role address detection | Shared inboxes like info@, support@, admin@ |
| No-reply detection | Addresses matching no-reply patterns |
| Email correction | Misspelling detection and suggested corrections |