PhishDestroy Public API

Read-only threat intelligence endpoints. Open access, CC-BY-4.0.

No auth required CC-BY-4.0 JSON + RSS + plaintext

Endpoints

Probe
Live availability check
GET /api/probe.php?domain=example.com

Returns current DNS and HTTP availability evidence. This endpoint does not issue a phishing or safety verdict.

Global Stats
Platform-wide metrics
GET /api/stats.php

Returns defined counts for tracked domains, latest stored availability, confirmed takedowns, stored report records, and dataset scope.

CTI Breakdown
By registrar, TLD, brand
GET /api/stats-cti.php

Returns defined aggregate counters, keeping confirmed takedowns separate from latest-check unavailability.

Report Feed
Atom — recently updated reports
GET /feed.xml

Atom feed of recently updated domain-security reports. Individual entries retain their own evidence status.

Threat Feed
RSS — newly detected
GET /feed-threats.xml

Real-time RSS stream of newly detected phishing domains, updated as threats emerge.

LLM Overview
AI-readable site index
GET /llms.txt

Machine-readable plain-text summary of platform capabilities and data boundaries.

LLM Full
Extended machine-readable context
GET /llms-full.txt

Extended machine-readable platform context, source boundaries, endpoint definitions, and reuse notes.

Domain Dossier
Per-domain LLM report
GET /domain/{domain}/llm.txt

Structured threat intelligence dossier for a specific domain in plain text for AI agent use.

Sitemaps & Discovery

License & Attribution

Data: CC-BY-4.0. Cite as: PhishDestroy CTI, https://phishdestroy.io, accessed YYYY-MM-DD

For high-volume or commercial use, contact us on Telegram — we welcome partnerships.