Share the threat. Never the server.
A phishing campaign does not hit one server. The same domain lands in dozens of communities within hours. The Threat Network lets AntiLink servers pool threat signals so that domain is recognised early - while everything that could identify your community is destroyed before it ever leaves.
Contribution is off by default and free on every plan. It is an extra signal, never a replacement for the reputation feeds behind /checklink.
A domain goes in. A fingerprint comes out.
The conversion happens inside your bot, before anything is written and long before anything is shared. It only runs one way.
Seen in your server
https://steamcornmunity-gift.top/claim?u=9f1
- Path, query and fragment are discarded.
- The host is normalised: lowercased, www. stripped.
- Bare IPs and internal names never qualify.
HMAC-SHA256
keyed, one way
no reverse
All the network ever receives
9c4b7e21a0f38d6510bb2ec7f4a99d3e5c81
0a6f27db4e93cc15a8f0621d7bb34e9082cd
The same domain always produces the same fingerprint, so reports can be counted without the domain itself ever being stored.
The disclosure ledger
Stated exactly, because this is the part that matters most
What leaves your server
A one-way fingerprint of a domain
HMAC-SHA256, keyed with a secret held only by the bot. Not the full link.
The kind of threat signal
For example: an external feed confirmed it, scam phrases sat beside it, it was hidden in a QR image.
When it was seen
A timestamp, so stale reputation can decay and expire on its own.
That is the complete list. Three fields, none of which can be traced back to your community.
What never leaves, at all
Message content
Not the message, not a snippet, not a hash of it.
Member, user or channel identifiers
Nobody in your server is represented in the network at all.
Your server name or ID
The network cannot list your community, because it never learns it.
Full links, paths, query strings or fragments
The domain is reduced before it is hashed. The rest is discarded.
Attachment contents
A decoded QR image contributes a signal class, never the image.
Which server reported anything
Reporters are counted, never named - not even to AntiLink staff.
One narrow exception, stated plainly. When an external feed such as URLhaus or VirusTotal has already publicly listed a domain as malicious, AntiLink keeps that domain readable so it can be named on the public network page. It applies only to domains those feeds already published, it is never used for matching, and it still says nothing about which servers reported it. Everything the network works out on its own stays an unreadable fingerprint.
One fingerprint. Several independent communities.
Nothing acts on a single report. The network only speaks when the same fingerprint arrives from communities that have nothing to do with each other - and even then, only with outside confirmation.
Indicator 9c4b7e21
fingerprint onlyIndependence is counted by owner, not by server. Three reporters here means three genuinely separate operators - one person running twenty servers still counts once.
Confidence gates
Breadth, not volume. A lone voice cannot open a gate.
Watch - inert, never shown to anyone
Where a single report always lands. A lone reporter is capped at 30 confidence, so it can never leave this state. One anonymous report can never become a public accusation.
Suspicious
Needs 3 or more independent reporters, at least 2 of them with strong evidence, and 40 confidence.
Malicious
Additionally requires an external feed confirmation, 3 or more independent reporters and 65 confidence. The network on its own never invents a malicious verdict.
A server that blocks every external link contributes nothing.
If your server blocks all outside links, AntiLink removes a great many perfectly ordinary ones. That is a policy choice, and it says nothing whatsoever about whether a domain is dangerous. So those removals are never contributed. Without that single rule, a network like this slowly learns that the entire web is suspicious.
Attack it. Here is why it fails.
Any shared reputation system invites the same obvious attack: report a rival until the network calls it malicious. Each of these is closed by design, not by moderation.
One server reports a rival domain with the strongest possible evidence
A single reporter is capped at 30 confidence and can never move a domain past the inert watch state, no matter how strong the evidence is.
One server posts the same link thousands of times
Volume is ignored. The score is built from how many independent communities reported it, and repeats inside a 24 hour window collapse into one counted report.
One person runs 20 servers and reports from all of them
Reporters are grouped by owner, so a single operator counts as one reporter no matter how many servers they run.
A brand new throwaway server starts reporting
Reporting requires a minimum installation age of 7 days and at least 20 members, and blocked servers are excluded outright.
Weak circumstantial signals repeated widely
Weak evidence can only ever produce a watch note. Leaving watch requires strong evidence from several independent communities.
A legitimate domain gets caught and stays caught
Two confirmed false positives permanently demote a domain, confidence decays while it goes unreported, and AntiLink staff suppression overrides everything immediately.
Reputation is never permanent
A network that can only accuse is a network that eventually gets it wrong forever. Every entry here can fade, be demoted, be overridden or be erased.
Confidence decays
A domain that stops being reported loses confidence every idle day, and a fully stale indicator expires after 90 days.
False positives demote
Two confirmed false positives push a domain back to the inert watch state and keep it there.
Suppression overrides everything
AntiLink staff can suppress any domain instantly. It stops returning a signal while the record needed to audit the decision survives.
Erase what you contributed
A server can request that everything it ever contributed be erased. Every affected score is recalculated without it straight away.
Rolled out in stages, on purpose
A shared blocklist that starts deleting on day one is how false positives become outages.
- 1Observe only
Signals are collected and scored. They have no effect on /checklink and no effect on whether any message is removed.
- 2Advisory
A clearly labelled AntiLink Network field appears in /checklink beside the existing reputation results. It never changes the risk verdict, and nothing is removed because of it.
- 3Optional enforcement
A server can turn on Act on confirmed network verdicts. Only malicious indicators qualify. Your whitelist and staff exemptions still win, and if the network is unavailable nothing is removed.
Enforcement additionally requires each server to opt in, so it can never switch on by surprise.
What you see, by plan
The signal itself is identical for everyone. Only the amount of detail differs.
AntiLink Basic
The confirmed verdict plus a plain explanation of what it means. Contributing and acting on confirmed verdicts are both free here.
AntiLink Plus and AntiLink Premium
Additionally the network history: how many independent communities reported it and when it was first seen, so you can judge the verdict yourself instead of taking it on trust.
Turning it on
Open Security in the dashboard and enable Contribute anonymised threat signals. That is the only control, and it is off until you enable it.
Limits, stated honestly
It starts out knowing very little
Early on the network has almost nothing to say. Its value grows as more communities contribute.
Observation is not proof
It reports what several communities have observed. AntiLink never describes a link as guaranteed safe.
It is not a web crawler
It only ever sees domains already flagged by a real signal inside a contributing server, so it is not a general web reputation service.
Defend together. Stay anonymous.
Add AntiLink, open Security, and contribute one hashed fingerprint at a time. Your community never appears in the ledger - only the threat does.