Privacy:  No cookies. No personal data collected. IPs logged for security only and purged periodically.

URLAbuse is a project run by NetSSR, based in Grenoble, France. We identify and report malicious domain names (DNS abuse) and URLs involved in phishing and malware distribution, as well as content-related abuse such as fake online shops and illegal gambling.

We collect, analyze and forward abuse cases to the right entities — registries, registrars, hosting providers and other stakeholders in the domain name system — to support swift takedowns and make the internet safer.

Our mission is to reduce the impact of online threats through collaboration, transparency and real-time reporting.

Phishing Malware Hacked sites Fake shops & scams Illegal gambling

How a report moves through URLAbuse

1

Collect

Suspicious URLs come in from honeypots, community submissions and our automated scanners.

2

Verify

Each URL is analyzed. Confirmed cases get evidence such as a screenshot, plus IP address, ASN and registrar details.

3

Report & publish

Cases go to registries, registrars, CERTs and partners for takedown, and verified data is published openly at no cost.

Frequently asked questions

How does URLAbuse gather malicious URLs?

We collect phishing and malware URLs through honeypots, community submissions and our automated scanners.

Who receives the abuse reports?

Our reports are shared with domain registries, registrars, CERTs and other trusted partners responsible for domain takedowns or response actions. We also collaborate with law enforcement agencies, banks and payment service providers whenever possible to help mitigate abuse.

Can I submit a suspicious URL?

Yes, we welcome community contributions. Fill out the contact form or email us at . We typically respond within one business day and will provide you with an API key and the documentation needed to submit data to URLAbuse.

What happens to the data I submit?

We first analyze each submitted URL to determine whether it is malicious. If confirmed, we collect evidence of the malicious activity, such as a screenshot, along with additional information like the IP address, ASN and registrar details.

All verified data is then published on our website. Everything submitted by contributors is freely available for anyone to access and use, at no cost.

How is URLAbuse funded?

Our costs fall into two categories: infrastructure — the servers and IP addresses needed to run real-time detection and measurement at scale — and personnel — the people who maintain the systems, investigate new attack techniques and keep detection methods current.

URLAbuse started on volunteer time and self-funded infrastructure. Now that it handles tens of thousands of requests per day, that is no longer sustainable. We rely on the community and the organizations that use our data to keep the project alive and free.

URLAbuse is run by NetSSR, a registered non-profit association (loi 1901) dedicated to internet security and safety. If our data is valuable to your organization, the most direct way to support it is by funding NetSSR through a sponsorship, a paid API plan or a direct donation. Every contribution keeps the core threat intelligence free and open for everyone.

My question isn’t answered here.

Send your question to or use the contact form, and our team will get back to you as soon as possible.

URLAbuse data is free and open for everyone.
If it helps your organization, consider supporting NetSSR through a sponsorship, paid API plan or donation.
Support NetSSR

Contact us

Want to become a reporter, ask about our data, or flag something we missed? Send us a message.

We usually reply within one business day.