# phishdestroy/destroylist

Real-time phishing & scam domain blocklist - 208k+ curated threats, 1M+ community, free API, multiple formats

Repository: https://github.com/phishdestroy/destroylist
Canonical: https://ross.abutalabs.com/products/destroylist
Homepage: https://phishdestroy.github.io/destroylist/scripts/
Language: HTML
License: MIT
License Family: permissive
Topics: blacklist, cybersecurity, domains, drainer, malware, phishing, scam, threat-intelligence, seed-phishing, blocklist, crypto-scam, dns-blocklist, web3-security, anti-phishing, osint, security-tools
Last push: 2026-08-26T19:40:30+00:00

## Health v2 (maintenance only)
Score: 72/100 (v2, computed 2026-09-03T02:39:23.370411+00:00)
- activity 99, release rhythm 61, longevity 29
- inputs: {"age_days": 413, "days_push": 7, "days_rel": 44, "gap_med": 254, "n_releases_24m": 2}
- flags: none
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1624, forks 422 (observed 2026-08-28T04:05:12.739411+00:00)

## What it is
A continuously updated phishing and scam domain blocklist with 208k+ curated threats, distributed in multiple formats (hosts, AdBlock, Dnsmasq, Unbound, RPZ, JSON) plus a free threat-intelligence API. It integrates with Pi-hole, AdGuard Home, routers, and DNS firewalls for real-time protection.

## Use cases
- block phishing domains on pi-hole
- scam domain blocklist for adguard home
- threat intelligence feed of phishing domains
- protect my router from malware domains
- free phishing domain api
- block crypto drainer and scam sites via dns
- dns firewall blocklist for bind or unbound

## When to choose
- you need a free, frequently updated phishing/scam domain feed in standard DNS blocklist formats
- you run Pi-hole, AdGuard Home, Unbound, BIND, or a router and want one-click protection
- you need a JSON or API source of malicious domains for your own security pipeline

## When to avoid
- you need file-level or URL-content malware scanning rather than domain blocking
- you require commercial SLAs, support, or verified enterprise threat intelligence
- you need IP-based or full-URL blocklists rather than domain-level data

## Facets
- artifact type: dataset
- maturity: active
- function: security, osint, vulnerability-scanning, search-engine
- domain: security, privacy, networking, self-hosted, osint
- platform: self-hosted, cli, cloud
- tags: blocklist, phishing, threat-intelligence, dns-blocklist, pi-hole, adguard, scam-protection, hosts-file, crypto-scams, free-api, web-server, docker

## Member repositories
- phishdestroy/destroylist (main) score 72

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:12.739411+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:48:47.903617+00:00, confidence not recorded.
  - readme: https://github.com/phishdestroy/destroylist (fetched 2026-08-28T04:05:12.739411+00:00, sha 0c8d11ed51f0)
  - homepage: https://phishdestroy.github.io/destroylist/scripts/ (fetched 2026-08-29T11:21:24.817348+00:00, sha 593fc44845e0)
- Data as of 2026-08-30T08:39:29.467469+00:00.
