| Baseline uncertainty | +10 | Always applied |
|---|
| No HTTPS | +15 | When the submitted address is not encrypted |
|---|
| Uses HTTPS | -4 | A small transport-security reduction; never proof |
|---|
| Page could not be accessed reliably | +25 | A failed access check also forces insufficient evidence |
|---|
| Contact information not found | +8 | Only after the contact checks complete |
|---|
| Refund policy link not found | +10 | Only after the page check completes |
|---|
| Privacy policy link not found | +7 | Only after the page check completes |
|---|
| Aggressive discount language | +10 | When a configured pattern is detected |
|---|
| Pressure or urgency language | +10 | When a configured pattern is detected |
|---|
| Recently registered domain | +18 | Only with completed age evidence |
|---|
| Higher-risk domain ending | +8 | A weak clue from a configured caution list |
|---|
| Possible brand impersonation | +18 | When a configured domain pattern matches |
|---|
| Threat-intelligence match | +50 | Only when a configured provider reports a match |
|---|
| Redirect to another domain | +18 | When the validated chain leaves the submitted site |
|---|
| HTTPS downgrade | +20 | When a redirect changes from HTTPS to HTTP |
|---|
| Same-site origin change | +3 | A host change that remains on the same site and scheme |
|---|
| Two redirects | +4 | A small point increase for a two-step chain |
|---|
| Complex redirect chain | +8 | Three redirects or a chain that exceeds the limit |
|---|