PhishDestroy Public API
Read-only threat intelligence endpoints. Open access, CC-BY-4.0.
Endpoints
GET /api/probe.php?domain=example.com Returns current DNS and HTTP availability evidence. This endpoint does not issue a phishing or safety verdict.
GET /api/stats.php Returns defined counts for tracked domains, latest stored availability, confirmed takedowns, stored report records, and dataset scope.
GET /api/stats-cti.php Returns defined aggregate counters, keeping confirmed takedowns separate from latest-check unavailability.
GET /feed.xml Atom feed of recently updated domain-security reports. Individual entries retain their own evidence status.
GET /feed-threats.xml Real-time RSS stream of newly detected phishing domains, updated as threats emerge.
GET /llms.txt Machine-readable plain-text summary of platform capabilities and data boundaries.
GET /llms-full.txt Extended machine-readable platform context, source boundaries, endpoint definitions, and reuse notes.
GET /domain/{domain}/llm.txt Structured threat intelligence dossier for a specific domain in plain text for AI agent use.
Sitemaps & Discovery
Data: CC-BY-4.0. Cite as: PhishDestroy CTI, https://phishdestroy.io, accessed YYYY-MM-DD
For high-volume or commercial use, contact us on Telegram — we welcome partnerships.