Overview
Phishing Domain Checker uses the Phishing.Database project, which aggregates phishing domains from multiple sources, and The Block List Project's phishing list; sources reports which matched. Entries naming a top-50k site outright are excluded so one listed page cannot flag a whole platform. The API accepts either a domain or full URL and checks against the active phishing domains list, and additionally applies list-free structural heuristics — punycode/IDN homograph detection, raw-IP hosts and other indicators — to produce a composite risk score for domains that may not be listed yet.
Live Test Phishing Check Skill Skill →
The tool
Once your client is connected to the VerveKit server, this appears in its tool list as PhishingCheckSkill. It is read-only and open-world — it fetches and never mutates anything on your side — so most clients call it without asking you to confirm.
{
"name": "PhishingCheckSkill",
"arguments": {
"domain": "centruldepiele.ro"
}
}You do not name the tool yourself; the model picks it. Asking about centruldepiele.ro in the terms this skill covers is enough for it to reach for PhishingCheckSkill on its own — naming it explicitly also works, and is the way to force the call.
Connecting
One server URL covers every skill in the catalog, including this one. Authorization is OAuth: the client opens a browser once, and there is no key to paste into a config file.
{
"mcpServers": {
"vervekit": {
"url": "https://api.vervekit.com/v1/mcp"
}
}
}https://api.vervekit.com/v1/mcpPer-client setup — Claude, Cursor, VS Code, ChatGPT — is on the MCP setup page.
Arguments
These are the properties on the tool's inputSchema, so a well-behaved client validates them before the call is made. Premium arguments are accepted on every plan but only take effect on plans that include them.
| Argument | Type | Description |
|---|---|---|
domainRequired | string | The domain to check (e.g., example.com) domain |
What the model gets back
The result carries a structuredContent object matching the tool's declared outputSchema, so a client reads fields without parsing prose. status is "ok" and error is null on success; a null field means the value was not available for that input, not that the call failed.
{
"status": "ok",
"error": null,
"data": {
"domain": "secure-banking-login.suspicious-domain.com",
"isPhishing": true,
"matchedDomain": "suspicious-domain.com",
"inputType": "url",
"originalInput": "https://secure-banking-login.suspicious-domain.com/auth",
"isPunycode": false,
"isIpAddress": false,
"riskScore": 85,
"riskLevel": "high",
"sources": [
"phishing-database",
"blocklistproject"
]
}
}
Response fields
Paths are relative to data. Premium fields are absent rather than zeroed on plans that do not include them, so check for presence instead of comparing to 0.
| Field | Type | Example | Description |
|---|---|---|---|
domain | string | secure-banking-login.suspicious-domain.com | The domain that was checked for phishing threats |
isPhishing | boolean | true | Whether the domain is a known phishing site |
matchedDomainPremium | string | suspicious-domain.com | The matched phishing domain from threat database |
inputType | string | url | Type of input checked - domain or URL format |
originalInput | string | https://secure-banking-login.suspicious-domain.com/auth | The original input provided by the user |
isPunycodePremium | boolean | false | Whether the domain uses punycode/IDN encoding (xn--), the vector for homograph attacks that impersonate brands with lookalike characters |
isIpAddressPremium | boolean | false | Whether a raw IP address was used in place of a domain, a common trait of malicious links |
riskScorePremium | number | 85 | Composite 0-100 risk score combining the blocklist match with structural phishing indicators — a heuristic supplement to isPhishing, not a verdict (higher is riskier) |
riskLevelPremium | string | high | Risk band derived from the score: low, medium or high |
sourcesPremium | array | ["phishing-database","blocklistproject"] | Blocklists that matched: phishing-database, blocklistproject; empty when not listed |
Failure modes
Errors come back as tool errors carrying a sentence the model can act on, not a bare status code. Error handling covers the full list.
| Status | What it means |
|---|---|
400 / 422 | The arguments did not validate. The message names the offending one. |
401 | The OAuth session is invalid or expired — reconnect the server. |
403 | Blocked by a key restriction or an IP allow-list. Never a bad identity. |
404 | This skill is not part of VerveKit. Check the catalog. |
429 | Out of credits, or a brief rate limit. The message tells them apart. |
A call costs 10 credits each time the tool actually runs; a model that reasons about the tool without calling it costs nothing.
Use cases
- Email Security
- Check links in emails before users click them to prevent phishing attacks
- Browser Extensions
- Build security extensions that warn users about phishing sites in real-time
- URL Shortener Safety
- Verify destination URLs before allowing shortened links to be created
- Chat/Messaging Moderation
- Automatically detect and block phishing links shared in chat platforms
Other ways to use Phishing Check Skill
Set up Phishing Check Skill on VerveKit, or reach the same source a different way. Your VerveKit account and credits work on all of them — one key, one balance.
Related
More in Networking: