Platform Health

179,921
Threats Tracked
Full historical set since 2019
51,337
Last Seen Active
Responded during the latest stored scan
128,584
Unavailable at Last Check
Did not serve content during the latest stored scan
434
New in Last 24h
⌘KLook up any domain in our 179,921 threat database
LIVE
Detectedloading live feed…

Flagship

Six tools that do the heavy lifting

Everything else orbits these. Real-time data, open APIs, deep analysis, on-chain intelligence — free and unlimited.

REAL-TIME

Explore Live Threats

Stream of phishing detections as they happen — domain, brand, registrar, cloaking flags. Refreshed continuously.

Watch the feed →
179,921 DOMAINS

Domain Intel Hub

Per-domain dossiers: WHOIS, DNS, TLS, VirusTotal, cloaking, kit fingerprint, abuse-report history. Searchable.

Browse reports →
NO API KEY

Free REST API

Check a domain, pull a feed, bulk-scan 500/req. 960K+ threat records, CC-BY licensed, zero cost.

Read API docs →
ONE-CLICK

URL Analyzer

Paste any URL — get VirusTotal consensus, drainer-kit fingerprint, cloaking test, SSL chain, screenshot.

Analyze now →
ON-CHAIN

Phishing Wallets DB

Drainer addresses, rug-pull wallets, linked infrastructure across EVM + Solana. Flagged, searchable, exportable.

Search wallets →
OPEN SOURCE

DestroyList Blocklist

Community-curated threat feed on GitHub. Auto-updated domain blocklist for firewalls, DNS filters, browser extensions.

View on GitHub →

Connected Security Ecosystem

Security Ecosystem

Open data, public reports, and interoperable feeds across the security ecosystem.

350K+
Domains Analyzed
54+
Security Vendors
17M+
Flagged Wallets

For Developers

Destroy API

Free, open, no API key. Real-time domain risk scoring across 960K+ threats.

Endpoints
5
Bulk Limit
500 /req
Auth
Open
Sync
Hourly
api.destroy.tools
$ curl "https://api.destroy.tools/v1/check?domain=suspicious-site.xyz"
{
"threat": true,
"risk_score": 85,
"severity": "critical",
"sources": ["destroylist", "community"],
"dns_active": true
}
Threat Scoring (0—100)
Critical 70—100High 40—69Medium 20—39Low 1—19
Available Endpoints
API Endpoints
MethodEndpointDescription
GET/v1/check?domain=Single check
POST/v1/check/bulkBulk (500/req)
GET/v1/search?q=Keyword search
GET/v1/feed/{list}Full feeds
GET/v1/statsLive stats

Live Intelligence

Latest Detections

Recently stored phishing detections from the public feed.

Protect Yourself

Essential Security Resources

Emergency: I Was Scammed

Immediate steps if your crypto wallet was drained. Revoke approvals, secure remaining assets, and report the crime.

Get Help Now

Ultimate Security Checklist

Step-by-step guide to hardening your crypto security. Hardware wallets, 2FA settings, and browsing hygiene.

Open Checklist

Privacy Arsenal & Tools

Recommended privacy tools, secure browsers, VPNs, and operating systems to stay anonymous online.

Explore Tools

Support & Legal

Disclaimer and Frequently Asked Questions

Non-commercial, independent project. We are an open community focused on identifying, documenting, and disrupting phishing and scam infrastructure for public benefit.

  • Open by design. Where safe and lawful, indicators and scans are publicly accessible.
  • No user databases. We do not store personal data. For appeals and takedown status we use a ticket ID only.
  • No direct takedowns. We submit evidence to registrars, hosting providers, and trusted vendors; enforcement is their decision.
  • Safe for legitimate sites. Our passive scans and reports do not harm lawful resources.
  • No warranties. Content is provided "as is", without guarantees of completeness or fitness.
  • Lawful cooperation. For qualifying cases, artifacts may be shared with competent authorities.

  • Scanning. We perform safe, passive checks to collect artifacts and indicators.
  • Escalation. We request professional services to verify resources and ask registrars/hosts to review clients via abuse teams.
  • Investigations. We occasionally conduct hobby-level OSINT; results are published, shared with peers, or forwarded to authorities. We do not hoard private data. See our Gambler Panel investigation for an example. Browse all research on our News & Investigations page.
  • Collaboration. We are open to partnerships. Certain private tools and materials can be shared for defensive purposes on request.
  • Dashboards. Explore stolen funds across all chains via the DeFi Hack Explorer or investigate scam infrastructure with our Scam Intelligence Dashboard.

No whitelist or ignore list. We do not maintain any whitelist/ignore program. Duplicate suppression only prevents re-adding the same domain.

Appeal removes the domain. If an appeal is approved, the domain is removed from our database and from any places where we published it.

Ticket-only tracking. We do not store personal data. For status checks and takedown requests we use a ticket ID only.

  • Open access. The bot is open to everyone, which does not change its purpose: faster disruption of fraud.
  • No paid leniency. We have never asked for or accepted payment for unbans or favors. The process and database are open and verifiable.
  • Trusted reporters. Reputable users may report without pre-moderation and submit bulk complaints for speed.

Act fast and preserve evidence: URLs, TXIDs, wallet addresses, screenshots, timestamps, chat logs. File an official report. For prevention, read our Crypto Security Essentials guide.

  • United States: https://www.ic3.gov/
  • United Kingdom: https://www.actionfraud.police.uk/
  • Other countries: contact your national cybercrime unit or local police

Personal Recommendation

For any incident, I strongly recommend contacting the SEAL 911 Bot. This is a rapid response group of professionals who really know their stuff and can help in any situation.