Demo: behavioral detector
Type a hostname or pick an example. Ward’s detector scores how machine-generated the name looks and shows which signals drove the score. How the detector works has the details.
Loading Ward (4.1 MB of WebAssembly, downloaded once)…
In the live demo you type a hostname and Ward's detector, compiled to WebAssembly, scores it in your browser. It strips the public suffix, measures five signals (entropy, rare letter patterns, digits, consonant runs and length), adds up their weights into a score between 0 and 1, and flags names above the threshold. In the beta a flag never blocks. Run the real thing with the Quickstart.
Trigram statistics derived from the Majestic Million, CC BY 3.0.
A flagged name shows Flagged — not blocked (beta). In the beta, Ward records the flag and still forwards the query. To enforce, add the name to a blocklist.
This demo scores whatever you type. On your network, ward serve skips OS connectivity checks such as msftncsi.com before scoring, so those names are never flagged there.
The CDN example is there on purpose. Hash-like names on content-delivery networks can look random, and the result shows how Ward handles that case today.