TrustScore Methodology
Vysiro TrustScore is a composite score from 0 to 1000 that measures how well a domain implements email authentication, encryption, DNS security, and infrastructure best practices. Each domain is scanned across 29 categories totalling 162 implemented checks, weighted by impact, then normalized to a 1000-point scale.
The score is fully deterministic: the same inputs always produce the same score, computed by fixed RFC-based rules with no AI or LLM involvement - so it is reproducible and auditable. AI is used only to draft fix suggestions on top of the deterministic result; it never influences the score itself.
This page is rendered live from src/lib/check-registry.ts - the same canonical registry that drives the scoring engine. Every number on this page is derived; nothing is hand-typed. Roadmap: 33 planned checks take the total to 195 across 29 categories.
Grade Bands
| Grade | Score Range | Description |
|---|---|---|
| A+ | 900 - 1000 | Exceptional. Full protocol deployment with enforcement. |
| A | 800 - 899 | Strong. Nearly complete coverage with minor gaps. |
| B+ | 700 - 799 | Good. Core protocols present, some advanced features missing. |
| B | 600 - 699 | Above average. Basics covered, enforcement incomplete. |
| C | 400 - 599 | Needs improvement. Significant gaps in authentication or encryption. |
| F | 0 - 399 | Failing. Minimal security posture - the domain is vulnerable to spoofing and interception. |
Scoring Categories
Raw points are earned per category based on RFC-compliant checks. The total raw maximum across all 29 live categories is 1598 points, then normalized to a 0-1000 scale. Categories with planned additions show a count of upcoming checks.
| Category | Live checks | Planned | Max points |
|---|---|---|---|
| DMARC | 13 | +4 | 272 |
| SPF | 8 | +3 | 135 |
| SSL/TLS | 10 | - | 138 |
| DKIM | 5 | +3 | 103 |
| Infrastructure Stability | 5 | +12 | 35 |
| Agent Readiness | 17 | +7 | 79 |
| Domain Health | 13 | - | 101 |
| Security Headers | 8 | - | 90 |
| DNSSEC | 6 | - | 75 |
| MTA-STS | 4 | +2 | 52 |
| DNS Hygiene | 7 | - | 55 |
| BIMI | 4 | +1 | 42 |
| IP Reputation | 2 | - | 43 |
| DANE/TLSA | 3 | - | 40 |
| Attack Surface Exposure | 9 | - | 39 |
| Certificate Lifecycle | 9 | - | 36 |
| Threat Intelligence | 3 | - | 33 |
| PQC Readiness | 6 | - | 32 |
| Availability | 4 | - | 32 |
| AI Safety | 4 | - | 31 |
| Web Trust | 4 | - | 29 |
| ARC | 3 | - | 28 |
| CAA | 3 | - | 27 |
| Privacy & Legal | 4 | - | 23 |
| Brand Integrity | 2 | - | 9 |
| RPKI & Route Security | 3 | - | 7 |
| ARC & Email Forwarding | 1 | +1 | 4 |
| DNS Resilience | 1 | - | 5 |
| Content Integrity | 1 | - | 3 |
| Total | 162 | +33 | 1598 |
Planned column shows upcoming checks. They are documented in the registry but not yet scoring against domains - this is the public roadmap from 162 to 195.
Score Normalization
Raw category scores are summed and then linearly normalized to the 0-1000 scale:
For example, a domain earning 700 raw points out of 1598 would receive a TrustScore of 438.
Compliance Framework Mapping
TrustScore categories map to controls in 9 compliance frameworks. When a domain satisfies the relevant scoring checks, Vysiro flags the corresponding compliance control as met.
| Framework | Required categories |
|---|---|
| SOC 2 | dmarc, ssl, security-headers |
| PCI DSS | ssl, dnssec, security-headers |
| GDPR | ssl, dmarc, mta-sts |
| NIS2 | dmarc, spf, dnssec, ssl |
| CISA | dmarc, spf, dkim, ssl |
| NIST | dmarc, spf, dkim, ssl, dnssec, security-headers |
| PDPA | ssl, dmarc, mta-sts |
| Essential Eight | ssl, security-headers, dnssec |
| EU AI Act | agent-readiness, ai-safety, dnssec, dmarc, ssl |
Methodology version v1.7. Weights and modifiers are subject to change as new protocols emerge and industry best practices evolve. Every scoring deduction cites the relevant RFC section in the detailed scan report.