What we checkReputationRP-03
PhishStats
Recent phishing reports naming your domain.
- Area
- Reputation
- Check
- RP-03
- Included
- Free in every scan
What we check
We query PhishStats for recent reports referencing your domain.
Why it matters
Phishing hosted on your domain damages your sending reputation and your customers' trust at the same time, and both take far longer to rebuild than the page took to remove.
It also has a second cost that outlasts the page. Once your domain has been seen hosting phishing, mail filters treat your outgoing messages more harshly, and that reputation takes far longer to rebuild than the removal takes.
How to fix it
- 1
Look for hijacked pages, an abused subdomain, or an open redirect being used to lend your domain's credibility to someone else's link.
- 2
Remove it and request a review.
- 3
Look specifically for an open redirect. It is the most common way a domain ends up in a phishing report without hosting anything malicious at all.
Common questions
- I am phished but not hosting phishing. Does this catch that?
- No. This looks for phishing hosted on your domain. Someone imitating you on a lookalike domain is a different problem — certificate transparency monitoring is the tool for that.
- What is an open redirect?
- A URL on your site that forwards to any address given in a parameter. Attackers use them so a link looks like it points at you.
- How current is the data?
- Recent reports only. An old, resolved incident should not appear.
See how your domain does on this check.
All 34 checks, a grade, and the exact fix for anything that isn’t right — in about twenty seconds, no signup.