Security Tools

Phishing Domain Checker — Punycode, Keywords & TLD Heuristics

Score hostname phishing risk from punycode, keywords, TLD abuse, and structural patterns

How to Use This Tool

  1. Enter a domain, subdomain, or URL — scheme and path strip automatically.
  2. Hostname normalizes to lowercase with trailing dot removed.
  3. Punycode xn-- prefix triggers homograph attack signal.
  4. Keyword, TLD, hyphen, digit, depth, and length heuristics accumulate riskScore.
  5. riskLevel maps to low, medium, or high from score thresholds.
  6. Optional HTTPS HEAD request reports reachable status when domain is valid.

About This Tool

Phishing campaigns register domains that mimic trusted brands through punycode homographs, keyword stuffing, cheap TLDs, and long hyphenated labels. Before users click, analysts need fast hostname-level triage that does not require fetching malicious page content. VSPIC phishing domain checker normalizes your input and applies weighted heuristics — punycode detection, suspicious keyword matches, risky TLD list, hyphen and digit density, subdomain depth, raw IPv4 hostname patterns, and excessive length — producing riskScore, riskLevel, and signals array.

Results include suspicious boolean, punycode flag, hyphenCount, digitCount, optional reachable HEAD probe status, and summary text. Clean scores do not prove safety — always verify through official channels before entering credentials. High scores flag patterns common in phishing but may match legitimate marketing domains — human review remains essential.

Common use cases

  • Check if a VPN or proxy is detected on your connection
  • Validate SSL certificates before launch
  • Scan for email addresses in known breaches

Why use VSPIC for ?

  • Fast hostname heuristics without fetching page content.
  • Punycode and homograph detection with explicit signal text.
  • Risky TLD and suspicious keyword lists tuned for phishing patterns.
  • Transparent signals array explaining each score contribution.
  • riskScore and riskLevel for automation thresholds.
  • Free instant analysis — no account required.

Hostname heuristics versus content scanning

Full phishing detection requires rendering pages, analyzing forms, and comparing visual branding — operations unsafe to run blindly on unknown malware hosts. Hostname heuristics provide a first-pass filter analysts run on millions of indicators daily. Our checker encodes patterns seen across campaigns: IDN homographs, login-verify keyword combos, and free TLD abuse.

riskScore summarizes pattern density. signals array documents each hit so reviewers override false positives with context — a legitimate secure-login.example.com may trigger keyword signals while being authentic.

Punycode and homograph attacks

Internationalized domain names encode Unicode characters in ASCII using punycode xn-- prefixes. Attackers substitute visually similar Cyrillic or Greek letters for Latin brand characters — microsoft.com versus a homograph with Cyrillic 'o'. punycode true in results triggers a twenty-five-point penalty and explicit signal text.

Browsers increasingly show Unicode in address bars with punycode fallback, but email clients and messaging apps often hide the distinction. Flag punycode domains in user awareness training regardless of score.

Suspicious keyword matching

We scan joined hostname labels for tokens common in phishing: login, verify, secure, account, banking, wallet, password, signin, confirm, suspend, support, and related terms. One keyword match adds twelve points and records the matched token in signals.

Keyword hits are intentionally broad — marketing landing pages use verify and account legitimately. Combine with domain reputation checker age signals and threat intelligence lookup for composite judgment.

Risky TLD abuse patterns

Certain TLDs — including .tk, .ml, .ga, .cf, .gq, .xyz, .top, .bond, and .cam — appear disproportionately in bulk phishing registration due to low cost and weak verification. TLD match adds twenty points with explanatory signal text.

Legitimate projects use these TLDs too. TLD signal is one factor among many — not automatic block justification without additional evidence.

Structural signals — hyphens digits and depth

Three or more hyphens suggest auto-generated phishing labels like secure-pay-verify-account.example.com. Four or more digits in the hostname suggest tracking-style phishing URLs. Five or more domain labels indicate deep subdomain chains used to obscure apex ownership.

hyphenCount and digitCount appear in results for numeric threshold tuning in SOAR playbooks. Adjust automation cutoffs based on your false positive tolerance.

Raw IPv4 hostname pattern

Phishing emails sometimes link directly to http://203.0.113.45/path without DNS names to evade domain blocklists temporarily. IPv4-as-hostname detection adds thirty points — among the strongest single signals in the model.

Legitimate appliances and staging environments occasionally use IP URLs — rare in consumer-facing brand communications. Investigate context when this signal fires.

reachable HEAD probe behavior

When input validates as a public domain, we attempt a short HTTPS HEAD request to report reachable true or false. Unreachable does not mean benign — attackers may geo-fence or user-agent filter. Reachable does not mean safe — phishing pages respond 200 routinely.

Treat reachable as supplementary metadata. Core riskScore derives from hostname analysis independent of HTTP availability.

riskLevel thresholds and SOC workflows

riskScore twenty-five or above sets suspicious true with medium or high riskLevel. High starts at fifty-five points. SOAR integrations can map high to automatic ticket creation, medium to analyst queue, and low to log-only.

Export signals array into SIEM fields for searchable indicator history. Recheck domains after takedown — re-registration under new labels resets score until patterns reappear.

Relationship to malware URL scanner

Malware URL scanner analyzes full URLs including path, redirect chains, and structural reachability signals across batch inputs. Phishing domain checker focuses on hostname pattern heuristics without deep URL crawling.

Paste bare domains here for quick triage. Paste full suspicious URLs into malware URL scanner when path and query parameters matter.

Privacy and responsible use

Analysis runs on domains you submit. HEAD probes contact public HTTPS endpoints briefly. Use for authorized phishing triage and user report investigation — not for harassing legitimate sites.

Heuristic flags are not accusations. Document human review steps before sharing results externally.

Important notes & limitations

  • Heuristic patterns only — legitimate brands can trigger keyword hits.
  • Clean score does not prove destination safety.
  • Does not scan page HTML or JavaScript for credential forms.
  • reachable HEAD probe may fail on firewalled sites unrelated to phishing.
  • Verify suspicious links through official channels before acting.

Frequently Asked Questions

Yes. VSPIC offers this phishing domain checker at no cost with no account required. Results load in real time.

We do not permanently store your queries on our servers. Some tools run entirely in your browser; others fetch public data for the request only.

Yes. Open the page in any modern phone or tablet browser. Results work on Wi‑Fi and mobile data.

No. Clean heuristics do not prove safety. Verify through official app or bookmark before entering credentials.

Keyword or TLD heuristics may match marketing hostnames. Read signals array and apply human judgment.

Domains starting with xn-- encode Unicode characters. Attackers use them for homograph impersonation of brand names.

No. Core analysis is hostname heuristics. A optional HEAD request checks reachability only.

Yes. We strip the scheme and path, analyzing the hostname portion only.

Threat intelligence lookup aggregates DNSBL, IP reputation, and phishing heuristics. This tool focuses solely on hostname pattern scoring.

Next step for your check

Continue with malware url scanner on VSPIC.

Malware URL Scanner

Trusted by Users Who Value Privacy

Always Free

No premium plan ever

100% Private

Files processed in browser

Instant Results

Convert in seconds

Works Everywhere

Any device, any OS