How to Check if a Domain Is a Phishing Site: A Step-by-Step Guide (2026)
Got a link that looks suspicious? Before you click it, report it, or escalate it, you want one thing: certainty. This guide walks through exactly how to check a domain for phishing, what signals to look for, and how to capture evidence so a confirmed fake can be taken down quickly.
The golden rule first: do not open a suspected phishing site in your own browser. Visiting a live malicious page can expose you to malware and can tip off the attacker. Use a phishing scanner that inspects the page and its infrastructure for you.
How to check a domain for phishing, step by step
- Scan the URL with a phishing scanner. Paste the full URL, domain, or IP into a phishing scanner to get an instant risk score. A scanner checks the page and its infrastructure far faster and more safely than visiting the site yourself.
- Check the domain registration and age. Review WHOIS or RDAP data for the creation date and registrar. A domain registered very recently that mimics a known brand is a strong phishing signal.
- Inspect hosting, DNS, and TLS certificate. Look at the hosting provider, name servers, and the TLS certificate. Brand-adjacent certificates issued days ago, or hosting that does not match the legitimate brand, raise the risk.
- Compare the page against the real brand. Check for a lookalike or typosquatting domain, a cloned login or checkout page, a copied logo, and forms that ask for credentials or payment details. These confirm impersonation.
- Capture evidence. Save the live URL, screenshots, and the domain, hosting, and certificate data. A clean evidence package is what makes a fast takedown possible.
- Report and take it down. Submit the evidence to the hosting provider and registrar, and escalate to upstream providers and browser blocklists if the first report is ignored, until the site is removed.
The signals that reveal a phishing domain
When you analyze a domain name and the page behind it, a handful of signals do most of the work. None is conclusive alone, but together they paint a clear picture:
- Recent registration: phishing domains are usually used within days of being created.
- Lookalike or typosquatting name: swapped, added, or transposed characters, or homoglyphs that mimic a real brand.
- Fresh TLS certificate: a brand-adjacent certificate issued only days ago.
- Mismatched hosting: infrastructure that does not match where the legitimate brand is hosted.
- Cloned content: a copied login or checkout page, a lifted logo, and forms asking for credentials or payment data.
For the proactive side of this, where you find suspicious domains before anyone sends you a link, see our guide to domain intelligence and monitoring.
Why a scanner beats manual checking
You can gather most of these signals by hand, but it is slow and risky. A phishing scanner pulls the registration, hosting, certificate, and content signals together in seconds and returns a risk score with the reasons behind it, all without you ever loading the malicious page. That explainability matters: a score you can defend is what lets you escalate confidently.
PhishDown is built for exactly this first-pass check. Submit a URL, domain, or IP and get a clear, explainable risk assessment with domain, hosting, and lookalike signals in one place. See how the platform works.
After you confirm it: taking the site down
If the check confirms phishing, the next step is removal. Capture your evidence, identify the registrar and hosting provider, and submit an abuse report to each, escalating until the site is gone. We cover the full process in how to report a phish and take it down instantly and in our domain and phishing takedown services guide. If you would rather hand it off, a managed takedown service can run the whole process for you.
Frequently asked questions
How do I check if a domain is a phishing site?
Scan the URL or domain with a phishing scanner for an instant risk score, check the domain's registration age and registrar, inspect the hosting, DNS, and TLS certificate, and compare the page against the real brand for cloned pages or credential-harvesting forms. A scanner does most of this automatically and lets you avoid visiting the site directly.
Is it safe to visit a suspected phishing site to check it?
No. Visiting a live phishing site can expose you to malware or drive-by attacks and can tip off the attacker. Use a phishing scanner that analyzes the page and its infrastructure for you instead of opening it in your own browser.
What are the signs of a phishing domain?
Common signals include a very recent registration date, a lookalike or typosquatting name, a TLS certificate issued only days ago, hosting that does not match the legitimate brand, a cloned login or checkout page, and forms requesting passwords, card numbers, or one-time codes.
How do I take down a phishing website after I confirm it?
Capture evidence (the URL, screenshots, and domain and hosting data), identify the registrar and hosting provider, and submit an abuse report to each. If the first report is ignored, escalate to upstream providers, the registry, and browser safe-browsing programs. A takedown service can run this end to end for you.
Can I check a domain for phishing for free?
Yes. Free phishing scanners let you submit a URL, domain, or IP and get a risk assessment with the reasons behind the score, which is enough for first-pass triage before deciding whether to escalate to a takedown.
Sources and further reading
- CISA — Recognize and Report Phishing: official US guidance on identifying and reporting phishing safely.
- APWG — Phishing Activity Trends Reports: report phishing to reportphishing@apwg.org and review the Anti-Phishing Working Group's data.
- FBI IC3: file an internet crime complaint and read the annual Internet Crime Report.
About the author
Eric Wallace
Security Researcher at PhishDown
Eric researches phishing detection, domain intelligence, and brand-protection takedowns at PhishDown. He writes about how organizations can find and remove phishing sites, lookalike domains, and brand impersonation before they reach customers.
View all articles by Eric Wallace →Why you can trust this guide
- Written and reviewed by PhishDown's security research team.
- Grounded in how phishing detection, domain intelligence, and takedowns actually work in practice, not marketing claims.
- References authoritative sources including CISA, the APWG, ICANN, and the FBI's IC3.
- Last reviewed and updated June 10, 2026.
Related Articles
Check a suspicious domain in seconds
PhishDown scans any URL, domain, or IP for phishing signals and gives you an explainable risk score, then connects confirmed threats to takedown. See how the platform works or get in touch.