PhishDestroy Open Dataset
216,000+ verified phishing domains, crypto drainers, and scam infrastructure. Free, open-source threat intelligence for researchers, browser vendors, ML training, and academic use.
CC0 LicenseUpdated DailyJSON / API216K+ DomainsSince 2019
216,000+
Domains Tracked
27,000+
Takedowns
74,000+
Abuse Reports
951+
Brands Protected
Download Options
STIX 2.1 Bundle
Machine-readable IOCs for TIP/SIEM — OpenCTI, Anomali, Sentinel, ThreatConnect
MISP Feed
Subscribe as a MISP feed URL
Full Phishing Domain List (JSON)
Complete dataset — phishdestroy/destroylist on GitHub
Active Domains Feed
Currently DNS-resolving phishing domains
HuggingFace Dataset
ML-ready dataset for model training
Public REST API
Programmatic access, no API key required
LZT Market Intelligence Dataset
897K stolen accounts indexed across 16 platforms — companion dataset to the Valve investigation
Data access
Use the threat intelligence
Choose a human-readable report, a live feed or a machine-readable interface. Each route documents a different scope rather than presenting unlike counters as one total.
EvidenceDomain ReportsSearch stored WHOIS, DNS, scan and reporting evidence for a specific hostname.Search reports
ObservationsLive Threat FeedReview recent detections and the latest stored availability state.Open the live feed
DevelopersAPI DocumentationUse documented endpoints for programmatic lookups and integration.Read the API docs
Bulk accessThreat Feed CatalogueChoose the feed format and scope that matches your defensive workflow.Compare feeds
ResearchDNS Abuse StatisticsExplore evidence-based summaries without mixing report, domain and enforcement scopes.View DNS statistics
ImplementationDeveloper ToolsFind browser-side utilities, code examples and defensive integrations.Open developer tools
Academic Citation (BibTeX)
@misc{phishdestroy2026, title = {PhishDestroy: Open-Source Phishing Domain Threat Intelligence Dataset}, author = {PhishDestroy Team}, year = {2026}, publisher = {PhishDestroy}, howpublished = {\url{https://phishdestroy.io/dataset}}, note = {216,000+ verified phishing domains, CC0 license} }
Data Fields
domain— phishing domain nameip_address— resolved IPregistrar— domain registrar-
target_brand— impersonated brand (MetaMask, Coinbase, etc.) drainer_type— crypto drainer kit identificationvt_detections— VirusTotal detection countdetected_at— first detection timestampsite_status— alive / dead / banned / parked-
ssl_issuer,ssl_valid_to— SSL certificate data -
asn,ip_country,ip_org— hosting intelligence
License: Released under CC0 1.0 Universal — no restrictions, no attribution required. Use freely for research, commercial products, or ML training. Repository code and tooling are separately licensed under MIT.