Method reference
Provider Catalogue
A versioned reference of documented infrastructure associations maintained by ThreatScope Check. Provider Resolution uses these associations to interpret selected DNS hosting, inbound mail and SPF observations while preserving the underlying evidence and limits of attribution.
What this catalogue is
The Provider Catalogue connects selected observable infrastructure values with documented provider and service associations. Released rules are used by Provider Resolution to interpret authoritative or managed DNS, inbound mail routes and gateways, and literal SPF service references.
An association means that an observed value matches a documented and bounded infrastructure pattern for the stated role. It does not by itself establish a commercial relationship, ownership, registrar, website host, mailbox backend, active mail flow or complete service chain.
What qualifies for inclusion
Provider associations are not released from hostname resemblance, provider familiarity or repeated observation alone. A released rule requires evidence that identifies the relevant provider or operator, establishes the service role, supports the observable matching boundary and provides sufficient context to avoid misleading attribution.
Evidence that materially suggests an association but does not yet satisfy the release standard remains outside ordinary Provider Resolution until the remaining evidentiary gap is resolved.
Current release
—Supported association roles
— active documented patterns · Schema version — · Maintained by ThreatScope Check · Rule-level source provenance and evidence review dates are retained with the catalogue.
How to interpret an association
—
DNS hosting
Recognises authoritative or managed DNS infrastructure from nameserver values. It does not establish who registered the domain or where its website is hosted.
—
Inbound mail route
Recognises an MX routing destination or email-security gateway. It does not necessarily identify the mailbox provider, customer relationship or complete mail path.
—
SPF reference
Recognises a literal service reference in a published SPF policy. It does not prove active sending, effective authorisation or DMARC alignment.
Provider Resolution is role-bound and intentionally selective. Released rules use exact hostnames or bounded hostname suffixes. Evidence that does not support a released association remains unresolved rather than being converted into a provider label.
Released provider reference
This reference lists provider identities represented by the current catalogue release and the observable roles and services supported by active rules. It is not an exhaustive vendor directory and does not imply that every product, region, reseller configuration or endpoint operated by a provider is recognised.
| Provider | Observable roles | Recognised services | Rules |
Release provenance and citation
Provider Catalogue releases are versioned so that provider associations can be traced to the rules and evidence in use at a particular point in time.
- Catalogue version
- —
- Provider Resolution
—
- Schema version
- —
- Catalogue SHA-256
—
Suggested citation
ThreatScope Check. Provider Catalogue, version —. ThreatScope Check Provider Resolution. https://threatscopecheck.com/method/provider-catalogue/
For technical reproducibility, record the catalogue version and SHA-256 above with the citation.
Versioning and corrections
The catalogue is maintained as a versioned reference because provider endpoints, product names and published configuration guidance change. Each rule retains source provenance, rationale, status and an evidence review date. Entries may be revised, added, suppressed or removed through a catalogue release.
A provider association should not be the sole basis for a security, legal, commercial or attribution decision. Unknown, custom, white-label and insufficiently documented patterns remain unresolved rather than being forced into a provider label. Found a missing or incorrect association? Submit Provider Catalogue evidence or a correction.
Related: Method, Changelog, Privacy notice, and Terms / acceptable use.