Destroylist: Phishing & Scam Domain Blacklist


Quick Access
Live Statistics
| Primary |
Primary Live |
Community |
Community Live |
 |
 |
 |
 |
| ย |
Today |
Week |
Month |
| Primary |
 |
 |
 |
| Community |
 |
 |
 |
Data Feeds
| Feed |
Description |
Update |
Download |
| Primary |
Curated phishing domains |
โก Real-time |
 |
| Primary Live |
DNS verified active |
๐ 24h |
 |
| Community |
Aggregated from 35+ sources |
๐ 2h |
 |
| Community Live |
Community DNS verified |
๐ 24h |
 |
| Primary Content |
Curated + HTTP content verified |
๐ 12h |
 |
| Community Content |
Aggregated + HTTP content verified |
๐ 24h |
 |
| Allowlist |
False positive protection |
โ Manual |
 |
[!TIP]
Production: list.json or active_domains.json ยท Max coverage: blocklist.json ยท Firewall/DNS: root lists
๐ All Download Formats (TXT, Hosts, AdBlock, Dnsmasq)
| Format | Primary | Primary Live | Community | Community Live |
|:------:|:-------:|:------------:|:---------:|:--------------:|
| **TXT** | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/domains.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/domains.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/domains.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/domains.txt) |
| **Hosts** | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/hosts.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/hosts.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/hosts.txt) |
| **AdBlock** | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/adblock.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/adblock.txt) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/adblock.txt) |
| **Dnsmasq** | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary/dnsmasq.conf) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community/dnsmasq.conf) | [โฌ๏ธ](https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/community_active/dnsmasq.conf) |
> **Hosts** โ Pi-hole, /etc/hosts, Windows ยท **AdBlock** โ uBlock Origin, AdGuard ยท **Dnsmasq** โ DNS server
Root Lists
[!TIP]
Root domains only โ no subdomains, hosting providers excluded
Content-Verified Feeds 
[!NOTE]
Real HTTP content verification โ not just DNS, but actual phishing page detection

| Feed |
Description |
โฐ Update |
Download |
| ๐ฅ Primary Content |
Curated phishing with verified active content |
12h (06:00 / 18:00 UTC) |
content_active.json |
| ๐ Community Content |
Aggregated feeds with verified active content |
24h (03:00 UTC) |
content_live.json |
[!WARNING]
Cloaking Alert: Scammers use cloaking to hide phishing from bots โ showing blank/fake pages to scanners. Domain NOT in content list โ safe! Use Primary All or Community General for full protection.

About Destroylist
[!NOTE]
Live data collection began on July 1, 2025
Destroylist is a powerful tool against phishing and scams, powered by PhishDestroy. It provides reliable intel for:
- โ๏ธ Firewalls
- โ๏ธ DNS resolvers
- โ๏ธ Threat platforms
- โ๏ธ Security research
Protect the web, one domain at a time!
๐ง Quick Integration Examples (Python ยท Bash ยท DNS)
### Python
```python
import requests
blocklist = requests.get('https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.json').json()
is_malicious = "suspicious-domain.com" in blocklist
```
### Bash
```bash
curl -s https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.txt | grep -q "suspicious-domain.com" && echo "BLOCKED"
```
### DNS Blocklist (Pi-hole/AdGuard)
```
https://raw.githubusercontent.com/phishdestroy/destroylist/main/dns/active_domains.json
```

| ๐ **DISCOVER** | ๐ค **REPORT** | โ๏ธ **LEGAL** | ๐ก **PUBLISH** |
|:---:|:---:|:---:|:---:|
| 30+ parsers | 50+ vendors | ICANN compliance | Real-time |
| CT logs, DNS | Google, Microsoft | Abuse notifications | GitHub, Telegram |
| Social media | VirusTotal, Cloudflare | Evidence packages | Twitter, Mastodon |
๐ Read Full Workflow Details
### Phase 1: Pre-emptive Discovery & Ingestion
๐ We utilize a distributed network of **30+ proprietary parsers** to identify malicious domains at their earliest stage:
- **Advanced Heuristics:** Continuous monitoring of Google Ads (Malvertising), SEO-manipulated search results, and trending social media campaigns on Twitter (X), YouTube, and Telegram
- **Infrastructure Analysis:** Leveraging *dnstwist* and typosquatting detection to catch look-alike domains targeting established brands
- **Community Intelligence:** Real-time ingestion of community-reported threats via our Telegram Bot and partner intelligence feeds
---
### ๐ค Phase 2: Global Ecosystem Contribution
Once a threat is confirmed, we submit data to over **50 industry-leading vendors**:
```
Cloudflare Google Safe Browsing Microsoft Security VirusTotal
Netcraft ESET Bitdefender Norton Safe Web
Avira PhishTank Dr.Web Yandex Safe Browsing
URLScan.io PolySwarm SiteReview Urlquery
PhishStats PhishReport IsItPhish ThreatCenter
```
---
### ๐ Phase 3: Legal Notifications & Investigation Support
- **Abuse Notifications:** Formal alerts to domain registrars and hosting providers
- **Forensic Evidence Disclosure:** Complete evidence packages including metadata, screenshots, and PDF reports
- **ICANN Compliance Support:** Reports aligned with ICANN standards
- **Conditional Re-Detection Logic:** Follow-up alerts only if threat remains active beyond 24 hours
---
### ๐ข Phase 4: Public Transparency & Community Alerts
- **Open Database:** Real-time commits to this GitHub repository
- **Live Monitoring:** Visual intelligence at [phishdestroy.io/live](https://phishdestroy.io/live/)
- **Social Broadcasting:** Automated alerts on Twitter, Telegram, and Mastodon

Key Info for Online Fraud Victims
Show details about complaints and transparency
๐ผ DestroyList aims to disable malicious domains: scams, phishing, and other illicit sites to enhance internet safety.
Before a domain is added, we:
๐ Scan it across cybersecurity platforms for threat intelligence.
๐ฅ Send an official complaint to the registrar and the hosting provider (via WHOIS), including scan results, screenshots, and a request for client investigation. The complaint also notifies them about inclusion in our public database.
๐ According to ICANN rules, registrars must review such complaints within 24 hours.
---
๐ฆ We work hard to eliminate threats quickly. Every malicious domain is analyzed, documented, reported, and published transparently.
However, when a domain receives 10โ30+ abuse reports and a registrar still ignores them for months, the situation changes: the registrar is no longer a passive party. It effectively provides infrastructure for illegal activity.
Some registrars behave as if their internal policies somehow override ICANN requirements and national laws โ as if phishing and fraud are "allowed" as long as they personally decide not to act.
๐ฎ We document this publicly so that anyone can see: threats persist not because they were unnoticed, but because the responsible providers simply chose to do nothing.
---
**Requests from private individuals:**
DestroyList is an open-source, non-commercial volunteer project.
Private individuals may request the number of abuse reports we have sent for a specific domain, but only through public channels:
- via GitHub issues
- via commit history: https://github.com/phishdestroy/destroylist/commits/main/
โ We do not respond to private e-mail requests from individuals about report counts.
โ๏ธ This is a legal requirement for transparency and equal access to information.
Official government or law-enforcement requests may be answered privately.
---
๐ If you were defrauded by a domain already listed here, check its addition date using the commit history or via our Telegram/Mastodon channels.
๐ฌ If the fraud happened after the domain was already listed, the registrar's or host's delay may indicate they share responsibility for the loss. Future potential victims can also see this negligence documented publicly.
๐ Registrars and hosts that tolerate scam operations may reasonably be expected to assist victims or their legal representatives.

Goals, Usage & Historical Vault
| โ๏ธ Network security | โ๏ธ Automation | โ๏ธ Threat research | โ๏ธ ML training |
|:---:|:---:|:---:|:---:|
| ๐ค | ๐ฌ | ๐ |
|:---:|:---:|:---:|
| **AI Training** | **Research** | **Trend Analysis** |
[!IMPORTANT]
Open collaboration = Stronger security. Letโs team up!
[!TIP]
๐ฉ Historical Vault (500K+ domains, 5+ years archived): contact@phishdestroy.io

Appeals Process
Wrongly listed? Fix it fast:
|
|
|
|:โ:|:โ:|
- โ๏ธ Appeals Form โ fastest option
- โ๏ธ GitHub Issue with proof
Accuracy first! ๐ญ

Connect With Us

๐ License

MIT โ Free, open, yours to use!

Join the Fight!
Got ideas, sources, or improvements? We welcome:
- ๐ก Detection algorithm tweaks
- ๐ข Integration tips
- ๐ Fresh threat intelligence
Drop an Issue or PR โ letโs crush phishing together! ๐ช
