Phishing Domain Checker — Punycode, Keywords & TLD Heuristics
Score hostname phishing risk from punycode, keywords, TLD abuse, and structural patterns
How to Use This Tool
- Enter a domain, subdomain, or URL — scheme and path strip automatically.
- Hostname normalizes to lowercase with trailing dot removed.
- Punycode xn-- prefix triggers homograph attack signal.
- Keyword, TLD, hyphen, digit, depth, and length heuristics accumulate riskScore.
- riskLevel maps to low, medium, or high from score thresholds.
- Optional HTTPS HEAD request reports reachable status when domain is valid.
About This Tool
Phishing campaigns register domains that mimic trusted brands through punycode homographs, keyword stuffing, cheap TLDs, and long hyphenated labels. Before users click, analysts need fast hostname-level triage that does not require fetching malicious page content. VSPIC phishing domain checker normalizes your input and applies weighted heuristics — punycode detection, suspicious keyword matches, risky TLD list, hyphen and digit density, subdomain depth, raw IPv4 hostname patterns, and excessive length — producing riskScore, riskLevel, and signals array.
Results include suspicious boolean, punycode flag, hyphenCount, digitCount, optional reachable HEAD probe status, and summary text. Clean scores do not prove safety — always verify through official channels before entering credentials. High scores flag patterns common in phishing but may match legitimate marketing domains — human review remains essential.
Common use cases
- •Check if a VPN or proxy is detected on your connection
- •Validate SSL certificates before launch
- •Scan for email addresses in known breaches
Why use VSPIC for ?
- Fast hostname heuristics without fetching page content.
- Punycode and homograph detection with explicit signal text.
- Risky TLD and suspicious keyword lists tuned for phishing patterns.
- Transparent signals array explaining each score contribution.
- riskScore and riskLevel for automation thresholds.
- Free instant analysis — no account required.
Hostname heuristics versus content scanning
Full phishing detection requires rendering pages, analyzing forms, and comparing visual branding — operations unsafe to run blindly on unknown malware hosts. Hostname heuristics provide a first-pass filter analysts run on millions of indicators daily. Our checker encodes patterns seen across campaigns: IDN homographs, login-verify keyword combos, and free TLD abuse.
riskScore summarizes pattern density. signals array documents each hit so reviewers override false positives with context — a legitimate secure-login.example.com may trigger keyword signals while being authentic.
Punycode and homograph attacks
Internationalized domain names encode Unicode characters in ASCII using punycode xn-- prefixes. Attackers substitute visually similar Cyrillic or Greek letters for Latin brand characters — microsoft.com versus a homograph with Cyrillic 'o'. punycode true in results triggers a twenty-five-point penalty and explicit signal text.
Browsers increasingly show Unicode in address bars with punycode fallback, but email clients and messaging apps often hide the distinction. Flag punycode domains in user awareness training regardless of score.
Suspicious keyword matching
We scan joined hostname labels for tokens common in phishing: login, verify, secure, account, banking, wallet, password, signin, confirm, suspend, support, and related terms. One keyword match adds twelve points and records the matched token in signals.
Keyword hits are intentionally broad — marketing landing pages use verify and account legitimately. Combine with domain reputation checker age signals and threat intelligence lookup for composite judgment.
Risky TLD abuse patterns
Certain TLDs — including .tk, .ml, .ga, .cf, .gq, .xyz, .top, .bond, and .cam — appear disproportionately in bulk phishing registration due to low cost and weak verification. TLD match adds twenty points with explanatory signal text.
Legitimate projects use these TLDs too. TLD signal is one factor among many — not automatic block justification without additional evidence.
Structural signals — hyphens digits and depth
Three or more hyphens suggest auto-generated phishing labels like secure-pay-verify-account.example.com. Four or more digits in the hostname suggest tracking-style phishing URLs. Five or more domain labels indicate deep subdomain chains used to obscure apex ownership.
hyphenCount and digitCount appear in results for numeric threshold tuning in SOAR playbooks. Adjust automation cutoffs based on your false positive tolerance.
Raw IPv4 hostname pattern
Phishing emails sometimes link directly to http://203.0.113.45/path without DNS names to evade domain blocklists temporarily. IPv4-as-hostname detection adds thirty points — among the strongest single signals in the model.
Legitimate appliances and staging environments occasionally use IP URLs — rare in consumer-facing brand communications. Investigate context when this signal fires.
reachable HEAD probe behavior
When input validates as a public domain, we attempt a short HTTPS HEAD request to report reachable true or false. Unreachable does not mean benign — attackers may geo-fence or user-agent filter. Reachable does not mean safe — phishing pages respond 200 routinely.
Treat reachable as supplementary metadata. Core riskScore derives from hostname analysis independent of HTTP availability.
riskLevel thresholds and SOC workflows
riskScore twenty-five or above sets suspicious true with medium or high riskLevel. High starts at fifty-five points. SOAR integrations can map high to automatic ticket creation, medium to analyst queue, and low to log-only.
Export signals array into SIEM fields for searchable indicator history. Recheck domains after takedown — re-registration under new labels resets score until patterns reappear.
Relationship to malware URL scanner
Malware URL scanner analyzes full URLs including path, redirect chains, and structural reachability signals across batch inputs. Phishing domain checker focuses on hostname pattern heuristics without deep URL crawling.
Paste bare domains here for quick triage. Paste full suspicious URLs into malware URL scanner when path and query parameters matter.
Privacy and responsible use
Analysis runs on domains you submit. HEAD probes contact public HTTPS endpoints briefly. Use for authorized phishing triage and user report investigation — not for harassing legitimate sites.
Heuristic flags are not accusations. Document human review steps before sharing results externally.
Important notes & limitations
- Heuristic patterns only — legitimate brands can trigger keyword hits.
- Clean score does not prove destination safety.
- Does not scan page HTML or JavaScript for credential forms.
- reachable HEAD probe may fail on firewalled sites unrelated to phishing.
- Verify suspicious links through official channels before acting.
Frequently Asked Questions
Yes. VSPIC offers this phishing domain checker at no cost with no account required. Results load in real time.
We do not permanently store your queries on our servers. Some tools run entirely in your browser; others fetch public data for the request only.
Yes. Open the page in any modern phone or tablet browser. Results work on Wi‑Fi and mobile data.
No. Clean heuristics do not prove safety. Verify through official app or bookmark before entering credentials.
Keyword or TLD heuristics may match marketing hostnames. Read signals array and apply human judgment.
Domains starting with xn-- encode Unicode characters. Attackers use them for homograph impersonation of brand names.
No. Core analysis is hostname heuristics. A optional HEAD request checks reachability only.
Yes. We strip the scheme and path, analyzing the hostname portion only.
Threat intelligence lookup aggregates DNSBL, IP reputation, and phishing heuristics. This tool focuses solely on hostname pattern scoring.
Next step for your check
Continue with malware url scanner on VSPIC.
Related Tools
Explore more free VSPIC tools for IP, DNS, security, and network diagnostics.
Malware URL Scanner
URL reputation scan — single or batch, phishing & malware signals
Use Free →Domain Reputation Checker
Domain trust score from WHOIS age, SPF, DMARC, and DNSBL signals
Use Free →Threat Intelligence Lookup
Aggregate IP or domain threat brief — reputation, Spamhaus, phishing, DNSBL
Use Free →Open Redirect Checker
Detect potential open redirect vulnerabilities
Use Free →SSL Checker
Validate SSL/TLS certificates and expiration dates
Use Free →Blacklist Checker
Check if an IP is listed on spam and abuse blacklists
Use Free →
Trusted by Users Who Value Privacy
Always Free
No premium plan ever
100% Private
Files processed in browser
Instant Results
Convert in seconds
Works Everywhere
Any device, any OS