Modern approach to URL Intelligence - Expose threats, Empower trust

Who we are & What We Do

URLAbuse is a project run by NetSSR based in Grenoble, France, focused on identifying and reporting malicious domain names (DNS abuse) and URLs involved in phishing, malware distribution, as well as content-related abuse such as fake online shops and illegal gambling. We collect, analyze, and forward abuse cases to the appropriate entities—registries, registrars, hosting providers, and other stakeholders in the domain name system—to support swift takedown actions and enhance online safety. Our mission is to reduce the impact of online threats through collaboration, transparency, and real-time reporting.

Frequently Asked Questions

We collect phishing and malware URLs through honeypots, community submissions, and our automated scanners.

Our reports are shared with domain registries, registrars, CERTs, and other trusted partners responsible for domain takedowns or response actions. We also collaborate with law enforcement agencies, banks, and payment service providers whenever possible to help mitigate abuse.

Yes! We welcome community contributions. You can reach out to us anytime by filling out the contact form or by emailing us directly at contact email. We typically respond within one business day and will provide you with an API key along with the documentation needed to submit data to URLAbuse.

For each URL submitted to URLAbuse, we first analyze it to determine whether it is malicious. If confirmed, we collect evidence of the malicious activity—such as a screenshot—along with additional information like the IP address, ASN, and registrar details. All verified data is then published publicly on our website. Everything submitted by contributors is made freely available for anyone to access and use, at no cost.

URLAbuse's operations rely on two main categories of cost: infrastructure — the servers and IP addresses needed to run real-time detection and measurement at scale — and personnel — the people who maintain the systems, investigate emerging attack techniques, and keep detection methods current. Historically, URLAbuse ran entirely on volunteer time and self-funded infrastructure. As the project has grown — now handling tens of thousands of requests per day — that's no longer sustainable without support. We rely entirely on the community and organizations who use our data to keep this project alive and free. URLAbuse is run by NetSSR, a registered non-profit association (loi 1901) dedicated to Internet security, safety. If URLAbuse's data is valuable to your organization, the most direct way to support its continued operation is by funding NetSSR — whether through a sponsorship, a paid API plan (see our Plans page), or a direct donation. Every contribution goes toward keeping the core threat intelligence free and open for everyone, exactly as it's always been.

We’d be happy to help! Please feel free to send your questions to contact email, and our team will get back to you as soon as possible.

Contact Us