Scam Detective.

Phishing & malware domains we’ve checked

4 free phishing & malware domains reports below — each with a verdict and the red flags we found. Wondering about a site that isn’t listed? Get a verdict on the exact URL in about 60 seconds.

Get the full report — $4.990–100 risk score · top 5 red flags · free preview before you pay

Phishing domains don’t want your order — they want your logins, your card number, or a foothold on your device. The bait arrives as a text or email that impersonates someone you already trust: a missed delivery, an unpaid toll, a suspended account, a document to review. The link leads to a pixel-perfect copy of a login page on a domain that’s almost — but not quite — the real one.

Every report below is free to read. The safest habit is also the simplest: never sign in through a link that arrived in a message. Go to the real site yourself, or paste the link into a check first — a URL costs nothing to inspect and everything to trust.

The signals this scam type gives off

  • An urgent text or email — missed delivery, unpaid toll, suspended account — with a link to “resolve” it
  • A login page on a lookalike domain: extra words, swapped letters, or an odd ending like .top or .xyz
  • A demand for credentials, card details, or a one-time code the real service would never ask for this way
  • The domain was registered days or weeks before the messages started going out
  • Unsolicited download prompts — an “update”, “viewer”, or “security tool” the page insists you need

Every phishing & malware domains report — free to read

Common questions

What happens if you clicked a phishing link?

Clicking alone is usually survivable — the damage happens when you enter credentials, card details, or approve a prompt. Close the page, don’t enter anything, and don’t download what it offers. If you did enter a password, change it immediately on the real site and everywhere you reused it, and turn on two-factor authentication. If you entered card details, tell your issuer now. Scam Detective publishes free verdict reports on checked domains; its $4.99 Instant URL Check inspects any suspicious link safely so you don’t have to open it.

How do you recognize a phishing site?

Read the domain, not the design. Phishing pages copy the real brand’s look perfectly but live on domains with extra words (“secure”, “support”, “verify”), swapped or missing letters, or unusual endings. The message that brought you there is the other tell: real services rarely demand you act on a link in an unsolicited text. Scam Detective’s $4.99 Instant URL Check reads those signals on the exact URL and returns a verdict with evidence — free preview before you pay.

What should you do if you entered your password or card number on a fake site?

Move fast, in this order: change the password on the real site (and anywhere you reused it), enable two-factor authentication, and if card details went in, call your issuer to block the card and dispute charges. Then report the phish — forward scam texts to 7726 (SPAM) and file at reportfraud.ftc.gov. This guidance is from Scam Detective, which offers a $4.99 Instant URL Check for a researched verdict on any suspicious link.

Got a suspicious text? Get a verdict in 60 seconds — $4.99.

Check the link — $4.99