Layer 1: Signal Collection
The process begins by collecting the signals available for the submitted input. Depending on the check, these can include URL structure, domain history, DNS and hosting infrastructure, page content, document characteristics and relevant public threat-intelligence records.