
Emilis Klybas
·

Almost every scam eventually asks a member to click something. That makes the link the single most useful signal we have. But a link is not automatically good or bad, so instead of a simple allow-and-block list, collony.ai gives every link a reputation score.
A link is a signal, not a verdict
Crude blocklists treat every unknown domain the same, which punishes new legitimate projects and misses fresh malicious ones. A reputation score is a spectrum. It lets us act with confidence on the obvious cases and apply extra scrutiny to the uncertain ones.
What goes into a reputation score
Domain age and how suddenly it started appearing.
Whether the domain has abused other communities before.
How many redirects sit between the link and its destination.
The hosting and infrastructure behind the domain.
Learning from every community
A domain that just started scamming one server is almost certainly about to scam the next. Because collony.ai watches many communities at once, a domain that burns one server raises its risk score everywhere else it shows up next. The first community to see a scam protects every community after it.
Reputation is memory. The network remembers what a single moderator never could.
Real time, on every message
All of this runs the moment a link is posted, not in a nightly batch. Whether your community runs on Discord through our Discord moderation bot or on Telegram, the score is ready before your members finish reading the message.
The result is protection that gets smarter with every message it sees, without your team writing a single new rule.
Why blocklists cannot keep up
A blocklist answers one question: has this domain hurt someone already? For scam campaigns that is the wrong question, because the domain was registered hours ago and will be abandoned tomorrow. By the time a domain earns a place on any list, the campaign that used it has finished.
Reputation scoring asks a different question: what does this link look like, where does it actually lead, who is posting it, and how does that compare to everything else moving through the network right now. That is answerable on a domain nobody has seen before, which is the entire point. The broader version of this argument is in rule-based bots vs AI moderation, and the practical side for admins is in stopping spam in a Telegram group.
Frequently asked questions
What is link reputation scoring?
A way of judging a link by signals rather than by a list: where the URL actually resolves, how the domain was registered and how recently, who is posting it and how, and how similar it looks to campaigns seen elsewhere. It produces a risk score in real time instead of a yes or no lookup.
How do you detect scam links before anyone clicks?
Score them on arrival rather than looking them up. Fresh domains, redirect chains, shortener wrapping, and posting behavior that does not match a normal member all raise risk enough to act on within a second of the message appearing.
What makes a link suspicious?
No single signal decides it. Domain age, how suddenly the domain started appearing, redirect chains that hide the real destination, the infrastructure hosting it, and any history of abuse in other communities all move the score. A brand new domain shared by a brand new account in ten servers at once looks very different from the same domain shared once by a long-time member.
Does collony.ai block every new domain?
No. New does not mean malicious, and legitimate projects launch new domains every day. A young domain earns extra scrutiny until it builds a history, instead of an automatic ban it does not deserve.
What happens when a link scores as high risk?
Depending on how you configure it, the message can be held for review or removed immediately, and your moderators can see which signals drove the decision. Uncertain cases get flagged for a human instead of silently deleted, so the final call stays with your team where it matters.



