█ Append-only blacklist · since 1 July 2025
Live phishing threat feed.
Every detected scam domain, logged as we see it.
The PhishDestroy live phishing threat feed is an append-only public record of recently detected phishing domains and malicious infrastructure. DNS resolvers, browser extensions and threat-intelligence pipelines use the same raw evidence.
█ Daily threat activity
Last 30 days, by detection volume.
peak: 27.07 · 1,572 detections
01 / Featured investigations · this week
Why the registrars bury our reports.
/news →
Investigation · NameSilo
NameSilo killed our Twitter because we told the truth about them.
Two PhishDestroy X accounts locked under three shifting justifications. X's own automation cleared us in writing — the ban held anyway. Two weeks earlier we had documented NameSilo sheltering a $20M+ Monero-theft operation now under active EU criminal investigation.
Investigation · Trustname (IANA #4318)
Trustname.com: "bulletproof" registrar with €120 in declared revenue.
An ICANN-accredited registrar that calls itself bulletproof in its own DNS TXT record. Estonian shell company, €120 revenue, one employee, Belarusian owners — and a week of fresh fake-Elon crypto-casino domains hidden behind its in-house privacy proxies.
02 / Append log · DestroyList
The blacklist scrolls whether you watch or not.
Format: append-only · CC-BY-4.0
▸ append-only blacklist · once added, an entry is never edited or removed
▸ 150,126 live-feed records since 01.07.2025 · sync interval ≈ 14s
scan@phishdestroy:~$ tail -f scan_results | jq
03 / Infrastructure analytics
Where the infrastructure hides — and what it costs users.
Auto-refresh 60s
Top TLDs · by detections
04 / Latest entries
The dossier — raw, unfiltered, append-only.
Sorted by detection time
Filters apply to loaded entries. Load more to expand results.
█ Submit · escalation desk
Found one we have not logged yet?
Send the URL to our triage queue. No account or sign-in is required.