Frequently Asked Questions

Find answers to common questions about openphish.

What is openphish?

openphish is a free, community-driven phishing URL database. Users can submit suspected phishing URLs, which are then verified by the community through a voting system.

How do I submit a phishing URL?

Click on 'Submit' in the navigation bar, enter the suspicious URL, optionally identify the target brand being impersonated, and submit. Your submission will be added to the verification queue.

How does verification work?

Community members vote on whether a submitted URL is a valid phishing attempt or not. Once a submission receives enough votes (3+ valid votes), it becomes verified and is added to the official database.

Is the API free to use?

Yes, our API is completely free. You can check URLs against our database, download phishing lists, and integrate our data into your security tools.

How can I check if a URL is in your database?

Use the 'Quick URL Check' on the homepage, or use our API endpoint /api/check?url=YOUR_URL to programmatically check URLs.

What should I do if I find a phishing site?

Submit it to openphish! The more phishing URLs we collect and verify, the better we can protect internet users worldwide.

Can I use openphish data commercially?

Yes, the data is freely available for both personal and commercial use. We encourage integration into security products and services.

How do I earn reputation?

You earn reputation by submitting phishing URLs that get verified by the community, and by participating in the verification process with accurate votes.