█ Append-only blacklist · since 1 July 2025
Every scam domain.
Logged the moment we see it.
This is the raw feed — the same blacklist your DNS resolver, browser extension and threat-intel pipeline pulls from. Append-only. No sanitised dashboards, no warnings, no negotiations. Volunteer-run since 2019.
█ Daily threat activity
Last 30 days, by detection volume.
peak: 11 Apr · 1,403 detections
01 / Featured exposés · this week
Why the registrars bury our reports.
Retaliation
15 Apr 2026
Investigation · NameSilo
NameSilo killed our Twitter because we told the truth about them.
Two PhishDestroy X accounts locked under three shifting justifications. Two weeks earlier we documented NameSilo sheltering a $20M+ Monero-theft operation now under EU criminal investigation.
Registrar
14 Apr 2026
Investigation · Trustname (IANA #4318)
Trustname.com: "bulletproof" registrar with €120 in declared revenue.
An ICANN-accredited registrar that calls itself bulletproof in its own DNS TXT record. Estonian shell, €120 revenue, one employee, Belarusian owners — and a week of fresh fake-Elon casino domains.
Negligence
11 Apr 2026
Investigation · NiceNIC International
NiceNIC: 5,000+ abuse reports, zero takedowns, one excuse.
Top abused registrar in our dataset. 1,865 alive 7+ days after first report, 156 of those re-reported. The "we forwarded your complaint to the registrant" auto-reply is the entire abuse-process.
$20M+ Heist
02 Apr 2026
Investigation · xmrwallet · Monero drainer
10 years, $20M+ stolen, NameSilo never took it down.
Decade-old Monero phishing operation traced from view-key theft to wallet exfiltration. Now under active EU criminal investigation — registrar still hosting derivative domains.
Pattern
28 Mar 2026
Pattern report · 12 registrars
The registrar abuse response failure — a system, not a glitch.
Cross-registrar pattern of delays, deflection and victim-blaming. Same template responses, same 7-day-plus survival rates, same registrants. "Forwarded to registrant" = the gravestone of every abuse complaint.
02 / Append log · destroylist
The blacklist scrolls whether you watch or not.
updated every <30s · UTC
$ wc -l list.json
110,763 domains tracked · 493 appended in last 24h
03 / Surface analytics
Where the infrastructure hides — and what it costs you.
ranked by abuse volume · last 30 days
Top abused registrars
Top abused TLDs · damage dealt
04 / The dossier · active threats
The dossier — raw, unfiltered, append-only.
newest first · scroll for more
█ Submit a threat
Found one we haven't logged yet?
The bot logs your submission, runs WHOIS + URLScan + screenshot capture, then merges into the public list within minutes. No login. No CAPTCHAs. No filler.
# avg time from submission → public list: ~4 min
# avg time to registrar takedown: ~6 hours
# appeals supported via /appeals — see footer