The same API answers one question everywhere: is this domain a known, currently resolving phishing host? What changes from sector to sector is which domains arrive, who reads them, which regulator asks about it afterwards, and where in your stack the answer has to land.
Each guide covers the phishing patterns that sector actually sees, the regulatory frame that applies to it, where the lookup belongs in its typical stack, and what the daily feed changes for teams that cannot make live API calls.
Portal clones, transaction-signing interception, payment diversion and mule recruitment, set against DORA, PSD2, FFIEC guidance and card-scheme obligations.
Read the guideCarriers are phished through policyholders, the broker channel and the claims back office at the same time, and cyber underwriters ask their own insureds about the same control.
Read the guidePhishing is the front door for the ransomware that turns a hospital into a paper operation, which makes it a patient-safety control as much as a HIPAA one.
Read the guideCloned storefronts, delivery-fee smishing, loyalty-balance harvesting and seller-account takeover, with a registration cadence that tracks the trading calendar.
Read the guideAn operator is both an impersonation target and the enforcement point for millions of subscribers who will never install anything, which makes the resolver the obvious place to act.
Read the guideTax, benefits, licensing and penalty-notice lures convert because citizens are conditioned to comply, and the victim usually has no relationship with the agency's IT team.
Read the guideA federated estate behind a single trusted domain, a population that turns over every year, and FERPA plus the GLBA Safeguards Rule sitting behind the student-aid function.
Read the guideCompletion-day payment diversion is the profession's most expensive single attack pattern, and confidentiality duties make the control a professional obligation, not an IT preference.
Read the guideFreight moves on documents exchanged between parties with no prior relationship, which is exactly the condition carrier impersonation and double-brokering exploit.
Read the guideIntrusions into operational technology start in the corporate mailbox, and the customer-facing billing channel is phished on the same billing cycle every month.
Read the guideSector differences are real, but the underlying delivery options are the same everywhere. Which one you pick is a question about latency, network reachability and volume.
A GET to /api/v1/check returns whether a domain is in the database, its category, its DNS status and a confidence value in under 50 milliseconds. One credit per call.
A POST to /api/v1/batch takes up to 100 domains at a time and returns a per-domain verdict plus a count of hits, billed one credit per domain checked.
The whole DNS-verified database as CSV or JSON, rebuilt every 24 hours, for teams loading a resolver, a firewall or a SIEM rather than calling an API in the request path.
Registration takes a minute and gives you a working key against the live database. Credits are pay-as-you-go, starting at $59 for 10,000 lookups, and the daily feed subscription starts at $499 per month.