Back to rankings

Real-time phishing & scam domain blocklist โ€” 180k+ curated threats, 888K+ community, free API, multiple formats

blacklistcybersecuritydomainsdrainermalwarephishingscamthreat-intelligenceseed-phishingblocklistcrypto-scamdns-blocklist
Star Growth
Stars
1.5k
Forks
375
Weekly Growth
โ€”
Issues
2
5001k1.5k
Jul 25Nov 25Mar 26Jul 26
README

Performing Arts Destroylist: Phishing & Scam Domain Blacklist

Destroylist

Typing SVG

Rootlist On List Update Update Statistics Deploy GitHub Pages

Status License Contributions Last Commit Stars Forks

Rocket Quick Start

Add to Pi-hole or AdGuard Home in one click โ€” paste this URL into your blocklist settings:

https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt

More formats: Hosts ยท AdBlock ยท Dnsmasq ยท Unbound ยท RPZ ยท API

High Voltage Quick Access

Table of Contents

Live Statistics

Primary Primary Live Community Community Live
Primary Content Community Content
Today Week Month
Primary
Community

File Folder Data Feeds

Feed Description Update Download
Primary Curated phishing domains โšก Real-time JSON TXT
Primary Live DNS verified active ๐Ÿ• 24h JSON TXT
Community Aggregated from 13+ sources ๐Ÿ• 2h JSON TXT
Community Live Community DNS verified ๐Ÿ• 24h JSON TXT
Primary Content Curated + HTTP content verified ๐Ÿ• 12h JSON TXT
Community Content Aggregated + HTTP content verified ๐Ÿ• 24h JSON TXT
Allowlist False positive protection โœ‹ Manual JSON

[!TIP] Production: list.json or active_domains.json ยท Max coverage: blocklist.json ยท Firewall/DNS: root lists

๐Ÿ“ All Download Formats (TXT, Hosts, AdBlock, Dnsmasq, Unbound, RPZ)
Format Primary Primary Live Community Community Live
TXT โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ
Hosts โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ
AdBlock โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ
Dnsmasq โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ
Unbound โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ
RPZ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ โฌ‡๏ธ

Hosts โ†’ Pi-hole, /etc/hosts, Windows ยท AdBlock โ†’ uBlock Origin, AdGuard ยท Dnsmasq โ†’ dnsmasq DNS ยท Unbound โ†’ pfSense, OPNsense ยท RPZ โ†’ BIND, Knot DNS

Laptop Root Lists

[!TIP] Root domains only โ€” no subdomains, hosting providers excluded

All Roots Live Only Services Only
๐Ÿ”ด Primary JSON ยท TXT JSON ยท TXT JSON ยท TXT
โšซ Community JSON ยท TXT JSON ยท TXT JSON ยท TXT

All Roots โ€” clean root domains (no infra) ยท Live Only โ€” DNS-verified active ยท Services Only โ€” hosting platform subdomains (Vercel, Pages.dev, Netlify, etc.)

Content-Verified Feeds

[!NOTE] Real HTTP content verification โ€” not just DNS, but actual phishing page detection

Primary Content Community Content

Feed Update Description
Primary Content 12h (06:00 / 18:00 UTC) Curated phishing with verified active content
Community Content 24h (03:00 UTC) Aggregated feeds with verified active content

Download links: see Data Feeds above

[!WARNING] Cloaking Alert: Scammers use cloaking to hide phishing from bots โ€” showing blank/fake pages to scanners. Domain NOT in content list โ‰  safe! Use Primary or Community full lists for complete protection.

Alien Monster Threat Intelligence API

API

%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart LR
  Request["๐ŸŒ Client Request<br/>(Single / Bulk)"] e1@--> API["โšก Live API<br/>api.destroy.tools"]
  API e2@--> Engine["๐Ÿง  Threat Engine<br/>(Risk Score 0-100)"]
  Engine e3@--> DB[("๐Ÿ—„๏ธ Destroylist DB<br/>1M+ Threats")]
  DB e4@--> Engine
  Engine e5@--> Response["๐Ÿ“‹ JSON Response<br/>(Severity & Status)"]

  classDef client fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF;
  classDef api fill:#000000,stroke:#FF0000,stroke-width:2px,color:#FFFFFF;
  classDef db fill:#000000,stroke:#333333,stroke-width:2px,stroke-dasharray: 5 5,color:#FFFFFF;
  classDef animate stroke:#FF0000,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;
  classDef animateDark stroke:#333333,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;

  class Request client;
  class API,Engine,Response api;
  class DB db;
  class e1,e2,e3,e5 animate;
  class e4 animateDark;

API Stats

Free, open, no API key. Real-time domain risk scoring (0-100) across 888K+ threats ยท 2h sync ยท Single & bulk check (500/req) ยท Keyword search ยท Full feeds

๐Ÿ“– API Endpoints, Scoring & Integration Examples

Endpoints

Method Endpoint Description
GET /v1/check?domain= Single domain check with risk score & severity
POST /v1/check/bulk Bulk check up to 500 domains per request
GET /v1/search?q= Search blocklisted domains by keyword
GET /v1/feed/{list} Download full domain feeds (primary, community, active)
GET /v1/stats Live statistics & domain counts

Threat Scoring

Every domain gets a risk score (0-100) based on multiple signals:

Signal Points Description
Curated blocklist +40 In primary destroylist
Community reported +20 Reported by community sources
DNS active +30 Domain currently resolves
Multi-source +10 Confirmed by multiple feeds
Suspicious keywords +5 each metamask, wallet, airdrop, etc.
Risky TLD +5 .xyz, .top, .club, .icu, etc.

๐Ÿ”ด Critical 70-100 ยท ๐ŸŸ  High 40-69 ยท ๐ŸŸก Medium 20-39 ยท ๐ŸŸข Low 1-19

Quick Integration

cURL

curl "https://api.destroy.tools/v1/check?domain=suspicious-site.xyz"

Python

import requests
r = requests.get(f"https://api.destroy.tools/v1/check?domain={domain}")
if r.json()["threat"]:
    print(f"BLOCKED: {r.json()['severity']} (score: {r.json()['risk_score']})")

JavaScript

const r = await fetch(`https://api.destroy.tools/v1/check?domain=${domain}`);
const data = await r.json();
if (data.threat) console.warn("PHISHING:", data.severity, data.risk_score);

Bulk Check

curl -X POST "https://api.destroy.tools/v1/check/bulk" \
  -H "Content-Type: application/json" \
  -d '{"domains":["site1.com","site2.xyz","site3.top"]}'

Telescope About Destroylist

[!NOTE] Live data collection began on July 1, 2025

888K+ domains tracked ยท 13+ threat sources ยท 50+ vendor reports ยท 6 output formats ยท Free API

Destroylist is a real-time threat intelligence platform by PhishDestroy โ€” protecting firewalls, DNS resolvers, browser extensions, and security teams worldwide. Every domain is discovered, verified, reported to registrars, and published transparently.

Data Pipeline

%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart TB
  subgraph Sources["๐Ÿ” Threat Sources"]
    S1[30+ Parsers]
    S2[Community Feeds]
    S3[Telegram Bot]
    S4[CT Logs / DNS]
  end

  subgraph Ingestion["๐Ÿ“ฅ Ingestion"]
    I1[smart_aggregator.py]
    I2[validate_and_clean.py]
  end

  subgraph Enrichment["๐Ÿง  Enrichment"]
    E1[DNS Validation]
    E2[HTTP Content Check]
    E3[VirusTotal / GSB]
  end

  subgraph Distribution["๐Ÿ“ก Distribution"]
    D1[JSON / TXT]
    D2[Hosts / AdBlock]
    D3[RPZ / Unbound]
    D4[API Feed]
  end

  Sources --> Ingestion
  Ingestion --> Enrichment
  Enrichment --> Distribution

  classDef source fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF;
  classDef ingest fill:#000000,stroke:#FF0000,stroke-width:2px,color:#FFFFFF;
  classDef enrich fill:#000000,stroke:#CC0000,stroke-width:2px,color:#FFFFFF;
  classDef dist fill:#000000,stroke:#FF0000,stroke-width:2px,stroke-dasharray: 5 5,color:#FFFFFF;

  class S1,S2,S3,S4 source;
  class I1,I2 ingest;
  class E1,E2,E3 enrich;
  class D1,D2,D3,D4 dist;
๐Ÿ”ง Quick Integration Examples (Subscribe URLs ยท curl ยท Python ยท Bash)

One-Click Subscribe URLs

Tool Format URL
Pi-hole Hosts https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt
AdGuard Home AdBlock https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt
uBlock Origin AdBlock https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt
pfSense / OPNsense (Unbound) Unbound https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf
BIND / Knot DNS (RPZ) RPZ https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone
Dnsmasq Dnsmasq https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf

Pi-hole โ€” Settings > Blocklists > paste the Hosts URL
AdGuard Home โ€” Filters > DNS Blocklists > Add blocklist > paste the AdBlock URL
uBlock Origin โ€” Settings > Filter lists > Import > paste the AdBlock URL
pfSense โ€” Services > DNS Resolver > paste the Unbound URL
BIND/Knot โ€” Add the RPZ URL as a response-policy zone

curl One-Liners

# Plain domain list
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/domains.txt -o domains.txt

# Hosts format (Pi-hole, /etc/hosts)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/hosts.txt -o hosts_blocklist.txt

# AdBlock format (uBlock Origin, AdGuard)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/adblock.txt -o adblock.txt

# Dnsmasq
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/dnsmasq.conf -o dnsmasq_blocklist.conf

# Unbound (pfSense / OPNsense)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/unbound.conf -o unbound_blocklist.conf

# RPZ (BIND / Knot)
curl -fsSL https://raw.githubusercontent.com/phishdestroy/destroylist/main/rootlist/formats/primary_active/rpz.zone -o rpz_blocklist.zone

Python

import requests
blocklist = requests.get('https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.json').json()
is_malicious = "suspicious-domain.com" in blocklist

Bash

curl -s https://raw.githubusercontent.com/phishdestroy/destroylist/main/list.txt | grep -q "suspicious-domain.com" && echo "BLOCKED"

Shield Threat Intelligence & Automated Remediation Workflow

%%{init: {"theme":"base", "themeVariables": { "background": "transparent", "mainBkg": "#000000", "primaryColor": "#000000", "primaryTextColor": "#FFFFFF", "primaryBorderColor": "#FF0000", "lineColor": "#FF0000", "secondaryColor": "#111111", "tertiaryColor": "#111111", "fontFamily": "Inter, system-ui, sans-serif"}, "flowchart": {"curve": "basis", "htmlLabels": true}}}%%
flowchart LR
  Discover["๐Ÿ” DISCOVER<br/>30+ Parsers"] e1@--> Report["๐Ÿ“ค REPORT<br/>50+ Vendors"]
  Report e2@--> Legal["โš–๏ธ LEGAL<br/>ICANN Compliance"]
  Legal e3@--> Publish["๐Ÿ“ก PUBLISH<br/>Real-time Feed"]

  classDef box fill:#000000,stroke:#333333,stroke-width:2px,color:#FFFFFF;
  classDef animate stroke:#FF0000,stroke-width:2px,stroke-dasharray:10 5,stroke-dashoffset:900,animation:dash 22s linear infinite;

  class Discover,Report,Legal,Publish box;
  
  class e1,e2,e3 animate;

Workflow

๐Ÿ” DISCOVER ๐Ÿ“ค REPORT โš–๏ธ LEGAL ๐Ÿ“ก PUBLISH
30+ parsers 50+ vendors ICANN compliance Real-time
CT logs, DNS Google, Microsoft Abuse notifications GitHub, Telegram
Social media VirusTotal, Cloudflare Evidence packages Twitter, Mastodon
๐Ÿ“– Read Full Workflow Details

๐Ÿ” Phase 1: Pre-emptive Discovery & Ingestion

๐Ÿ”Ž We utilize a distributed network of 30+ proprietary parsers to identify malicious domains at their earliest stage:

  • Advanced Heuristics: Continuous monitoring of Google Ads (Malvertising), SEO-manipulated search results, and trending social media campaigns on Twitter (X), YouTube, and Telegram
  • Infrastructure Analysis: Leveraging dnstwist and typosquatting detection to catch look-alike domains targeting established brands
  • Community Intelligence: Real-time ingestion of community-reported threats via our Telegram Bot and partner intelligence feeds

๐Ÿ“ค Phase 2: Global Ecosystem Contribution

Once a threat is confirmed, we submit data to over 50 industry-leading vendors:

Cloudflare        Google Safe Browsing      Microsoft Security      VirusTotal
Netcraft          ESET                      Bitdefender             Norton Safe Web
Avira             PhishTank                 Dr.Web                  Yandex Safe Browsing
URLScan.io        PolySwarm                 SiteReview              Urlquery
PhishStats        PhishReport               IsItPhish               ThreatCenter

  • Abuse Notifications: Formal alerts to domain registrars and hosting providers
  • Forensic Evidence Disclosure: Complete evidence packages including metadata, screenshots, and PDF reports
  • ICANN Compliance Support: Reports aligned with ICANN standards
  • Conditional Re-Detection Logic: Follow-up alerts only if threat remains active beyond 24 hours

๐Ÿ“ข Phase 4: Public Transparency & Community Alerts

  • Open Database: Real-time commits to this GitHub repository
  • Live Monitoring: Visual intelligence at phishdestroy.io/live
  • Social Broadcasting: Automated alerts on Twitter, Telegram, and Mastodon

Police Car Key Info for Online Fraud Victims

Abuse Process

Show details about complaints and transparency

๐Ÿ’ผ DestroyList aims to disable malicious domains: scams, phishing, and other illicit sites to enhance internet safety.

Before a domain is added, we:

๐Ÿ” Scan it across cybersecurity platforms for threat intelligence.

๐Ÿ“ฅ Send an official complaint to the registrar and the hosting provider (via WHOIS), including scan results, screenshots, and a request for client investigation. The complaint also notifies them about inclusion in our public database.

๐Ÿš” According to ICANN rules, registrars must review such complaints within 24 hours.


๐Ÿฆ– We work hard to eliminate threats quickly. Every malicious domain is analyzed, documented, reported, and published transparently.

However, when a domain receives 10โ€“30+ abuse reports and a registrar still ignores them for months, the situation changes: the registrar is no longer a passive party. It effectively provides infrastructure for illegal activity.

Some registrars behave as if their internal policies somehow override ICANN requirements and national laws โ€” as if phishing and fraud are "allowed" as long as they personally decide not to act.

๐Ÿ‘ฎ We document this publicly so that anyone can see: threats persist not because they were unnoticed, but because the responsible providers simply chose to do nothing.


Requests from private individuals:

DestroyList is an open-source, non-commercial volunteer project.

Private individuals may request the number of abuse reports we have sent for a specific domain, but only through public channels:

โ— We do not respond to private e-mail requests from individuals about report counts.

โœ”๏ธ This is a legal requirement for transparency and equal access to information.

Official government or law-enforcement requests may be answered privately.


๐Ÿ’” If you were defrauded by a domain already listed here, check its addition date using the commit history or via our Telegram/Mastodon channels.

๐Ÿ’ฌ If the fraud happened after the domain was already listed, the registrar's or host's delay may indicate they share responsibility for the loss. Future potential victims can also see this negligence documented publicly.

๐Ÿ”ž Registrars and hosts that tolerate scam operations may reasonably be expected to assist victims or their legal representatives.

Bar Chart Use Cases & Historical Vault

Network security ยท Threat research ยท AI/ML training ยท Trend analysis ยท Automation

[!TIP] ๐Ÿ“ฉ Historical Vault (500K+ domains, 5+ years archived): contact@phishdestroy.io

Magic Wand Appeals Process

Appeals

Wrongly listed? Fix it fast:

Appeals Form GitHub Issue
  • โœ”๏ธ Appeals Form โ€” fastest option
  • โœ”๏ธ GitHub Issue with proof

Accuracy first! ๐Ÿ”ญ

Black Heart Connect With Us

Website Medium Telegram Bot Twitter Mastodon

API Ban Service Email

๐Ÿ‘พ Pac-Man Contribution Graph

pacman-contribution-graph
Repository Description
namesilo-evidence Evidence archive โ€” NameSilo registrar abuse investigation
nicenic-evidence Evidence archive โ€” NiceNIC registrar abuse investigation
trustname-evidence Evidence archive โ€” TrustName registrar abuse investigation
ScamIntelLogs Raw scam intelligence logs and IOC data
DestroyScammers Scammer exposure and disruption operations

๐Ÿ“„ License

License

MIT โ€” Free, open, yours to use!

Handshake Join the Fight!

Every star helps this project reach more security teams and protect more users.

Star this repo Open an Issue Submit a PR

We welcome contributions:

  • ๐Ÿ” Fresh threat intelligence & new blocklist sources
  • ๐Ÿ’ก Detection algorithm improvements
  • ๐Ÿ“ข Integration guides for new platforms
  • ๐ŸŒ Translations & documentation

Drop an Issue or PR โ€” let's crush phishing together! ๐Ÿ’ช

Related repositories
hagezi/dns-blocklists

DNS-Blocklists: For a better internet - keep the internet clean!

TextGNU General Public License v3.0dnsads
24.6k753
cobaltdisco/Google-Chinese-Results-Blocklist

ๆˆ‘็ปˆไบŽ่ƒฝ็”จ่ฐทๆญŒๆœไธญๆ–‡ไบ†โ€ฆโ€ฆ

blacklistspam-sites
7.5k282
yokoffing/NextDNS-Config

Setup guide for NextDNS, a DoH proxy with advanced capabilities

GNU General Public License v3.0dnssecurity
3.1k75
kboghdady/youTube_ads_4_pi-hole

YouTube script to add the new Ads list for Pi-hole

Shellpiholepihole-blocklists
2.6k251
stamparm/ipsum

Daily feed of bad IPs (with blacklist hit scores)

The Unlicensesecurityblacklist
2.3k178
notracking/hosts-blocklists

Automatically updated, moderated and optimized lists for blocking ads, trackers, malware and other garbage

blocklisthostfile
2.3k142
badmojr/1Hosts

Advanced DNS filter/blocklists for privacy, security, and clean browsing.

HTMLMozilla Public License 2.0adblockblocklist
badmojr.github.io/1Hosts/
2.2k122
nickspaargaren/no-google

Completely block Google and its services

PythonPyPIThe Unlicensegooglepi-hole
1.6k117
ben-z/free-sidecar

Enable Sidecar on Unsupported iPads and Macs running iPadOS 13 and macOS Catalina

SwiftGNU General Public License v3.0sidecarpatch
1.6k96
USBGuard/usbguard

USBGuard is a software framework for implementing USB device authorization policies (what kind of USB devices are authorized) as well as method of use policies (how a USB device may interact with the system)

C++GNU General Public License v2.0usbusb-devices
usbguard.github.io
1.4k152
neodevpro/neodevhost

The Powerful Friendly Uptodate AD Blocking Hosts ๆœ€ๆ–ฐๅผบๅคง่€Œๅ‹ๅ–„็š„ๅŽปๅนฟๅ‘Š

Adblock Filter ListMIT Licenseadawayad
neodev.team
1.4k84
akaunting/laravel-firewall

Web Application Firewall (WAF) package for Laravel

PHPPackagistMIT Licensephplaravel
akaunting.com
1k116