Who we work with
Over the years we have expanded who we report to and who we don't. For every report, we contact the host and registrar. However, we also report malicious URLs to many other vendors. See below:
Over the years we have expanded who we report to and who we don't. For every report, we contact the host and registrar. However, we also report malicious URLs to many other vendors. See below:
We use any.run as our first line before we report any malicious URL or domain. Any.run allows us to view the reported domain in a sandboxed environment, reducing the risk to our own computers.
We report domains to Google Safe Browsing to try and get them blocked on a browser-level before the consumer sees them. Google Safe Browsing covers Chrome, Firefox, Opera, Brave and other browsers, meaning it is quite effective.
We report domains to Microsoft Security Intelligence to try and get them blocked on an OS-level by Windows Defender. With this, other platforms can detect that Defender has blocked the domain and classify the domain as malicious too.
We report domains to Google Search Console so that they do not appear with normal results in Google Search. Like Safe Browsing, this also helps the attack get "blocked" before it reaches the consumer.
We submit malicious URLs to VirusTotal to see which Antiviruses or web filters block the malicious URL already. We then also re-run the same malicious URL before closing the case with Phish Report to signify that the site has been taken offline.
Netcraft analyses phishing attacks and protects brands online. We report every malicious URL to them and, if the report does not come out as malicious, we provide proof of wrongdoing to change netcraft's classification.
Each malicious domain is scanned through urlscan.io (which is where we get our screenshot logs from) and then one of our volunteers adds a "Malicious" classification either to the domain or directory depending on where the malicious site is hosted.
InterceptIO's Phish Report is our "dashboard" if you will. We CC each abuse report to the relevant case email (e.g. case_id@cases.phish.report) so it is tied to that specific malicious webpage.
We report each malicious domain or page to Cisco Talos as it is widely used across the world by educational institutions, workplaces and other professional settings. It is a very large firewall and is involved in abuse reporting for this reason.
We report each malicious URL to FortiGuard for a similar reason to Cisco Talos; it is a large firewall and it's classifications do help stop traffic from reaching the site.
We report each malicious URL to Symantec for a similar reason to the aforementioned; plus, it is also used by popular personal Antivirus Norton, which produces the same benefit as Google Safe Browsing.
We report malicious URLs directly to Avast's "false negative" for URLs page if it is not detected on VirusTotal. This helps keep the consumer protected by making sure that even if the site's contents stay up, the page is blocked.
We report malicious URLs directly to the UK's National Cyber Security Intelligence so they can pressure registrars and hosts to take down the site completely rather than third-parties just blocking the URL.
We submit malicious URL's to PhishDestroy's domain analyser to give us information about the domain. This helps us when we submit reports to registrars and hosts.
We report malicious domains to DNSFilter, which is used by over 43,000 organisations globally. It is also a member of WEFCA and the WebProtect Global Alliance. Members of GASA also use DNSFilter's verdicts to categorise domains.
We report malicious URLs to Pulsedive, which assigns dynamic risk scores to domains based on community feedback (of which we provide). Pulsedive is also used by Get Safe Online to determine if a site is a scam or not.
OpenPhish does not take any action when it comes to taking down sites, but they do provide fascinating and useful statistics on phishing domains, so we also report domains and URLs to OpenPhish too.
We report sites to NordVPN so users of the VPN will get notified if they try to visit a malicious URL or not. It is once again effective at blocking the site before the registrar or host takes action.
This is not an exhaustive list and any services may be added or removed at any time.
Last updated: 16 July 2026