Phishing Domain Checker API

POST

Catch malicious phishing domains before your users click them.

Phishing Domain Checker verifies whether a domain or URL appears in a comprehensive database of known phishing sites. Updated every 6 hours from two independent blocklists covering 570,000+ phishing domains.

Try it — live request, no key required

Request
POSTapi.apiverve.com/v1/phishingcheck
Body
Verification
Format

No key required to try it. Get a key to use it in your app.

Example
{
  "status": "ok",
  "error": null,
  "data": {
    "domain": "secure-banking-login.suspicious-domain.com",
    "isPhishing": true,
    "matchedDomain": "suspicious-domain.com",
    "inputType": "url",
    "originalInput": "https://secure-banking-login.suspicious-domain.com/auth",
    "isPunycode": false,
    "isIpAddress": false,
    "riskScore": 85,
    "riskLevel": "high",
    "sources": [
      "phishing-database",
      "blocklistproject"
    ]
  }
}

About the Phishing Domain Checker API

Phishing Domain Checker uses the Phishing.Database project, which aggregates phishing domains from multiple sources, and The Block List Project's phishing list; sources reports which matched. Entries naming a top-50k site outright are excluded so one listed page cannot flag a whole platform. The API accepts either a domain or full URL and checks against the active phishing domains list, and additionally applies list-free structural heuristics — punycode/IDN homograph detection, raw-IP hosts and other indicators — to produce a composite risk score for domains that may not be listed yet.

What people use it for

Email Security
Check links in emails before users click them to prevent phishing attacks
Browser Extensions
Build security extensions that warn users about phishing sites in real-time
URL Shortener Safety
Verify destination URLs before allowing shortened links to be created
Chat/Messaging Moderation
Automatically detect and block phishing links shared in chat platforms

Ways to call it

One endpoint, many ways in — REST with JSON, XML, YAML and CSV, plus GraphQL and an MCP interface for AI agents.

JSON
Default REST response
XML
Markup format
YAML
Human-readable
CSV
Tabular export
Beta
GraphQL
Query language
New
MCP
For AI agents

Other ways to use Phishing Domain Checker

Same data, same APIVerve account, same credit balance — one key works on all of them.

Questions.

Common questions about the Phishing Domain Checker API.

Read the docs →
Can I check full URLs or only raw domain names?
You can check both. The API provides dedicated endpoints for standalone domains and full URLs. When you submit a full URL, it automatically extracts the hostname before running the threat check and structural heuristics.
Where does the threat data come from and how fresh is it?
Data comes from two independent blocklists: the Phishing.Database project and The Block List Project's phishing list, together covering more than 570,000 phishing domains. Both are refreshed every 6 hours.
Can it catch brand-new phishing domains that are not on the blocklist yet?
Yes, on paid plans. Beyond database lookup, the API evaluates structural indicators such as punycode/IDN homograph encoding and raw-IP hosts. These indicators produce a composite risk score and risk band to flag suspicious domains before they appear on public blocklists.
Are the risk score and homograph detection included on the Free plan?
No. The Free plan returns basic phishing confirmation, but the risk score, risk level, punycode flag, raw-IP flag, and matched threat domain are premium fields. Any paid plan, starting with Starter, unlocks all premium fields.
How many phishing checks does the Free plan cover?
The Free plan covers 20 checks per month, using 10 credits per call from your 200 monthly credits. If you need higher volume, the Starter plan provides 200,000 credits for 20,000 checks per month, which works out to about $0.0015 per check or $1.50 per 1,000 checks.

Ready to build with Phishing Domain Checker? Start with 200 free credits — one key unlocks all 300+ APIs.

Explore the catalog

300+ APIs on the same key and the same response shape.

Browse all APIs