OPEN THREAT INTELLIGENCE

Phishing.Meet yourdead end.

The internet has enough bad actors.
Here are the tools to fight back.

Free APIs, open blocklists, and public evidence.
Built by PhishDestroy. Built for defenders.

Independent. Non-commercial. Since 2019.
THE PHISHDESTROY PIPELINESYS / 001
OPEN BY DESIGN
$0.00Cost to get started
500Domains per bulk request
5REST API endpoints
2019When the mission began
01 / THE TOOLKIT

Good tools.
Bad news for phishing.

Investigate a domain. Build a defense.
Find your starting point.

02 / FOR DEVELOPERS

Less friction.
More protection.

A free phishing threat intelligence API that fits into the tools you already build. Start with a request. No signup. No API key.

Domain risk scoring Up to 500 domains per request Downloadable threat feeds
Full API documentation

A domain absent from a blocklist is not a guarantee of safety. Use threat signals as part of a broader assessment.

YOUR FIRST REQUESTAPI v1
curl --fail-with-body \
  "https://api.destroy.tools/v1/check?domain=example.com"
WHAT YOU GET

Domain verdict, risk score, severity, matched lists, and detection flags.

For agents & integrators

A concise project guide, a readable overview, and a structured directory of official services.

BUILT TO FIT YOUR STACKBrowser extensionsSecurity botsDNS filtersResearch workflows
03 / THE MISSION

Make the internet
harder to exploit.

PhishDestroy is an independent, non-commercial project. We make threat evidence accessible so more people can act on it.

01

Find the signal.

Discover suspicious domains through infrastructure monitoring, public feeds, and community reports.

02

Build the evidence.

Investigate infrastructure and preserve scans, screenshots, and the context behind a detection.

03

Request action.

Submit evidence for registrar and hosting-provider review. Enforcement remains their decision.

04

Keep it open.

Publish findings, share indicators, and follow up on changes in a domain's availability.

Evidence over noise. No paid delistings.Read the full mission
04 / OPEN BY DEFAULT

Take the data.
Build something safer.

Explore the repositories, inspect public records, or contribute an improvement. Stronger defenses start with shared knowledge.

JSONTXTHostsAdBlockDNS
05 / STAY IN THE LOOP

A shared problem.
A collective defense.

Report a threat, follow the research,
or get in touch with the team.

More from the projectMastodonMediumGitLab
THE SHORT ANSWERS

Know before
you build.

Explore the full FAQ
Is the API really free?
Yes. The public PhishDestroy API is free to access and does not require an API key. The documentation covers domain checks, bulk requests, search, feeds, and statistics.
How is destroy.tools related to PhishDestroy?
Destroy Tools brings the PhishDestroy ecosystem into one place. The main investigation platform is phishdestroy.io; the API lives at api.destroy.tools, the URL scanner at ban.destroy.tools, and the domain analyzer at analyze.destroy.tools.
Does a clean result mean a domain is safe?
No. Blocklists and risk signals reflect available information and can miss new threats. An unlisted domain is not a safety certificate, and false positives are possible.
How do I report a false positive?
Use the official appeals process and include supporting evidence. Delisting is free; PhishDestroy does not accept payment to remove detections.
DEFENSE IS BETTER WHEN IT'S OPEN.

Your move, defenders.

Explore PhishDestroy