Industry Guides

Phishing detection, written for your sector

The same API answers one question everywhere: is this domain a known, currently resolving phishing host? What changes from sector to sector is which domains arrive, who reads them, which regulator asks about it afterwards, and where in your stack the answer has to land.

390K+Active phishing domains
24hRebuild cycle
<50msLookup response
10Sector guides
Home / Industries
Ten sectors

Choose the guide that matches your operation

Each guide covers the phishing patterns that sector actually sees, the regulatory frame that applies to it, where the lookup belongs in its typical stack, and what the daily feed changes for teams that cannot make live API calls.

Banking & Financial Services

Portal clones, transaction-signing interception, payment diversion and mule recruitment, set against DORA, PSD2, FFIEC guidance and card-scheme obligations.

Read the guide

Insurance

Carriers are phished through policyholders, the broker channel and the claims back office at the same time, and cyber underwriters ask their own insureds about the same control.

Read the guide

Healthcare

Phishing is the front door for the ransomware that turns a hospital into a paper operation, which makes it a patient-safety control as much as a HIPAA one.

Read the guide

E-commerce & Retail

Cloned storefronts, delivery-fee smishing, loyalty-balance harvesting and seller-account takeover, with a registration cadence that tracks the trading calendar.

Read the guide

Telecommunications

An operator is both an impersonation target and the enforcement point for millions of subscribers who will never install anything, which makes the resolver the obvious place to act.

Read the guide

Government & Public Sector

Tax, benefits, licensing and penalty-notice lures convert because citizens are conditioned to comply, and the victim usually has no relationship with the agency's IT team.

Read the guide

Higher Education

A federated estate behind a single trusted domain, a population that turns over every year, and FERPA plus the GLBA Safeguards Rule sitting behind the student-aid function.

Read the guide

Legal Services

Completion-day payment diversion is the profession's most expensive single attack pattern, and confidentiality duties make the control a professional obligation, not an IT preference.

Read the guide

Logistics & Supply Chain

Freight moves on documents exchanged between parties with no prior relationship, which is exactly the condition carrier impersonation and double-brokering exploit.

Read the guide

Energy & Utilities

Intrusions into operational technology start in the corporate mailbox, and the customer-facing billing channel is phished on the same billing cycle every month.

Read the guide
What every guide shares

One database, three ways to consume it

Sector differences are real, but the underlying delivery options are the same everywhere. Which one you pick is a question about latency, network reachability and volume.

Single lookup

A GET to /api/v1/check returns whether a domain is in the database, its category, its DNS status and a confidence value in under 50 milliseconds. One credit per call.

Batch screening

A POST to /api/v1/batch takes up to 100 domains at a time and returns a per-domain verdict plus a count of hits, billed one credit per domain checked.

Daily feed

The whole DNS-verified database as CSV or JSON, rebuilt every 24 hours, for teams loading a resolver, a firewall or a SIEM rather than calling an API in the request path.

Pick the guide for your sector, then pick a plan

Registration takes a minute and gives you a working key against the live database. Credits are pay-as-you-go, starting at $59 for 10,000 lookups, and the daily feed subscription starts at $499 per month.