Skip to main content

TrustScore Methodology

Vysiro TrustScore is a composite score from 0 to 1000 that measures how well a domain implements email authentication, encryption, DNS security, and infrastructure best practices. Each domain is scanned across 29 categories totalling 162 implemented checks, weighted by impact, then normalized to a 1000-point scale.

The score is fully deterministic: the same inputs always produce the same score, computed by fixed RFC-based rules with no AI or LLM involvement - so it is reproducible and auditable. AI is used only to draft fix suggestions on top of the deterministic result; it never influences the score itself.

This page is rendered live from src/lib/check-registry.ts - the same canonical registry that drives the scoring engine. Every number on this page is derived; nothing is hand-typed. Roadmap: 33 planned checks take the total to 195 across 29 categories.

162
Live checks
33
Planned checks
29
Categories
v1.7
Model version

Grade Bands

GradeScore RangeDescription
A+900 - 1000Exceptional. Full protocol deployment with enforcement.
A800 - 899Strong. Nearly complete coverage with minor gaps.
B+700 - 799Good. Core protocols present, some advanced features missing.
B600 - 699Above average. Basics covered, enforcement incomplete.
C400 - 599Needs improvement. Significant gaps in authentication or encryption.
F0 - 399Failing. Minimal security posture - the domain is vulnerable to spoofing and interception.

Scoring Categories

Raw points are earned per category based on RFC-compliant checks. The total raw maximum across all 29 live categories is 1598 points, then normalized to a 0-1000 scale. Categories with planned additions show a count of upcoming checks.

CategoryLive checksPlannedMax points
DMARC13+4272
SPF8+3135
SSL/TLS10-138
DKIM5+3103
Infrastructure Stability5+1235
Agent Readiness17+779
Domain Health13-101
Security Headers8-90
DNSSEC6-75
MTA-STS4+252
DNS Hygiene7-55
BIMI4+142
IP Reputation2-43
DANE/TLSA3-40
Attack Surface Exposure9-39
Certificate Lifecycle9-36
Threat Intelligence3-33
PQC Readiness6-32
Availability4-32
AI Safety4-31
Web Trust4-29
ARC3-28
CAA3-27
Privacy & Legal4-23
Brand Integrity2-9
RPKI & Route Security3-7
ARC & Email Forwarding1+14
DNS Resilience1-5
Content Integrity1-3
Total162+331598

Planned column shows upcoming checks. They are documented in the registry but not yet scoring against domains - this is the public roadmap from 162 to 195.

Score Normalization

Raw category scores are summed and then linearly normalized to the 0-1000 scale:

TrustScore = (rawTotal / 1598) * 1000

For example, a domain earning 700 raw points out of 1598 would receive a TrustScore of 438.

Compliance Framework Mapping

TrustScore categories map to controls in 9 compliance frameworks. When a domain satisfies the relevant scoring checks, Vysiro flags the corresponding compliance control as met.

FrameworkRequired categories
SOC 2dmarc, ssl, security-headers
PCI DSSssl, dnssec, security-headers
GDPRssl, dmarc, mta-sts
NIS2dmarc, spf, dnssec, ssl
CISAdmarc, spf, dkim, ssl
NISTdmarc, spf, dkim, ssl, dnssec, security-headers
PDPAssl, dmarc, mta-sts
Essential Eightssl, security-headers, dnssec
EU AI Actagent-readiness, ai-safety, dnssec, dmarc, ssl

Methodology version v1.7. Weights and modifiers are subject to change as new protocols emerge and industry best practices evolve. Every scoring deduction cites the relevant RFC section in the detailed scan report.