Before reporting an unexpected result
ThreatScope Check is a point-in-time reading of public evidence. A result can legitimately differ after recent DNS, mail, hosting or delegation changes, while data is propagating, when a public source is unavailable, or where a domain has an unusual but valid configuration.
If the result still appears unexpected, the exact domain, what you expected and what you observed are usually enough to begin investigating. For the authoritative interpretation model, read the Method.
