Free · no account · any brand
Is this link safe?
Paste it. In seconds you know what it is. If it is a phishing site, we report it where it gets taken down, tell the brand it imitates, and email you when it is gone.
For brands
Your customers end up here. Give them a page under your own name.
Replace the phishing@ line on your help page with openbait.com/report/your-brand. Reports about you land in your inbox with an answer already given; you confirm with one click and the rest runs.
What goes on the help page
<a href="https://openbait.com/report/acme">Report a site pretending to be Acme</a>This is a phishing site
It is not Acme. Anything typed into it goes to someone else. We have started reporting it.
- Received
- Reported
- Stopped
What the reporter sees, seconds after pasting.
The 60 seconds after
What happens when someone pastes a link
- Suspicious linkhttps://acme-login[.]com/signinCheck this link
Takes a few seconds. No account needed.
1They paste it
No account, no form to fill in. A link and a bot check.
- acme-login[.]com
This is a phishing site
It is not Acme. Anything typed into it goes to someone else. We have started reporting it.
- Received
- Reported
- Stopped
2They get an answer
The browser blocklists, what the page itself does, and your own domain list decide in seconds. A login form posing as you is called a phishing site.
- Where it was reported
- Browser warnings · submitted
- The imitated brand · told
- Hosting provider · one click from the brand
3It is reported, and followed until it is gone
The site goes to the parties that can block or remove it, the brand it imitates is told, and a case keeps the record. The reporter gets a status page and an email when it is offline.
Help pages today
What a phishing@ mailbox does, and what a report page does
| phishing@ mailbox | Report page | |
|---|---|---|
| Replies to the person who reported | Usually never | In seconds, every time |
| Accepts a link | Often not | That is the whole form |
| Gets browsers to warn | No | Automatically |
| Leaves a record | A thread nobody reads | A case with a timeline |
From reading the help pages of 14 Japanese and US companies: every one offered a mailbox, most said they would not reply, most did not ask for the link.
Free does the reporting. Pro does the rest.
Free
One brand- Your brand's report page
- Answers, receipts and a status page for reporters
- Reported where it gets taken down, followed until it is offline
- Cases, evidence screenshots, one notification per report
Pro
Per brand- Hosting and registrar abuse reports sent with one click
- Official reports to JPCERT, the Anti-Phishing Council and Netcraft
- Continuous monitoring for lookalike domains
- Seats, audit log, evidence PDF
Questions
Do I need to change DNS or install anything?
No. You add one link. Your domain is used only to tell your own sites apart from fakes.
What does the reporter see?
Within seconds: whether the site is a fake, what to do if they already typed something, and a status page that updates as the site is reported and goes offline.
What if a report is wrong?
Nothing goes to a hosting provider or registrar without your confirmation. Automatic reports go only to the browser blocklists, and only for sites that are already listed there or that our own review saw collecting credentials.
Under whose name are reports filed?
OpenBait files under its own fixed reporter identity and marks the report as made on your behalf; you receive a copy. Your domain stays out of spam filters, and one reputation builds up with the receiving desks.
Can I change the text the reporter sees?
Yes. The advice shown after an answer is yours to edit in the console. The default tells people to change their password on the real site.