This tool answers one question about a website: is its domain linked to phishing? Enter the domain and WhoisFreaks checks it against its threat data. If the domain is a known phishing domain, or shares registration or hosting details with known phishing domains, the result says so and shows the evidence. If there is no record, the result says that too, without guessing or inventing a risk score.
A website can be unsafe for reasons other than phishing, such as malware or spam. For a wider view of a domain's risk, run the Domain Reputation Check, which returns a safe, suspicious, or malicious verdict and a 0 to 100 trust score.
Feature: Checks for direct matches: the domain itself appears in WhoisFreaks phishing threat data
Feature: Checks for related infrastructure matches: the domain shares a registrant email, organization, MX record, or nameserver with known phishing domains
Feature: Works on sender domains in email headers, domains in DNS and proxy logs, and domains in text messages
Feature: Returns evidence for every flag, not just a score
Signs a website is a phishing or scam site: lookalike spelling (swapped, added, or dropped letters from a known brand, or words like "login", "secure", or "verify"); recent registration (check the date in the WHOIS record); hidden or mismatched owner (registrant is redacted or unrelated to the brand); pressure to act (the page asks for a password, card number, or code right away under a deadline or threat). A phishing check covers the first question — it does not review shop listings, prices, or delivery claims.
A flagged result requires different actions depending on your role. Follow the steps most relevant to you below.
Block the domain at your DNS resolver, email gateway, or web proxy to stop further contact across your organization.
Block the domain at your DNS resolver, email gateway, or web proxy to stop further contact across your organization.
Search email, proxy, and DNS logs for any contact with the domain to understand how many users or systems reached it.
Search email, proxy, and DNS logs for any contact with the domain to understand how many users or systems reached it.
Reset credentials for any user who submitted details on the site, and check for password reuse across other services.
Reset credentials for any user who submitted details on the site, and check for password reuse across other services.
Pull the WHOIS record and run a Reverse WHOIS search to find other domains registered by the same party.
Pull the WHOIS record and run a Reverse WHOIS search to find other domains registered by the same party.
Brand protection teams: save the evidence and the WHOIS record for your takedown request, then report the domain to the registrar's abuse contact and the hosting provider.
Brand protection teams: save the evidence and the WHOIS record for your takedown request, then report the domain to the registrar's abuse contact and the hosting provider.
Run a typosquat check of your brand to find sibling domains that may be part of the same campaign.
Run a typosquat check of your brand to find sibling domains that may be part of the same campaign.
The phishing checker is used by anyone who needs to know whether a domain is tied to phishing before clicking, delivering, or blocking it. Below are four common use cases.
Triage domains from alerts, email headers, and DNS logs, and attach the evidence to the ticket.
Check a sender domain before you release a quarantined message or approve a new vendor.
Confirm whether a lookalike of your domain is already used for phishing before you file a takedown.
Check a domain from a text, email, or ad before you log in or pay.
The checker handles one domain at a time in the browser. To run the same phishing detection inside your own tools — an email gateway, a sign-up flow, or a SOAR playbook — call the Domain Reputation API. It returns the verdict and threat matches as JSON, so your systems can flag or block a domain without a manual lookup.
Block every known phishing domain daily with the WhoisFreaks Threat Intelligence Feed. It delivers the full list of threat domains every day as a complete daily file — not a delta — so each file stands on its own and a missed day never leaves gaps in your blocklist. Domain threat categories cover phishing, malware, and spam, and every record carries a confidence value and a risk score so you can set your own blocking threshold.
Use this phishing checker when you need a direct answer on phishing and the evidence behind it. Use the Domain Reputation Check when you need an overall trust score for a domain, built from threat intelligence, DNS, WHOIS, SSL, and DGA analysis. Many teams run both: the phishing check for a quick yes or no, and the reputation report to decide how much to trust a domain that came back clean.