Lexical filter
Pure string analysis, no network call. Each feature that triggers adds +1 to the score.
F1domain_length > 20F2num_dots ≥ 2F3num_hyphens ≥ 1F4num_digits ≥ 1F5entropy_url > 4.0(Shannon entropy of full URL)
level1_score ≥ 2 → Phishing, otherwise benign.