A phishing report desk a brand runs under its own name. It replaces the
phishing@ mailbox with one link — openbait.com/report/<brand>. A customer
pastes the site they do not trust, the answer comes back in seconds, and
anything confirmed as phishing is filed with the browser blocklists, the
hosting provider and the registrar, under one fixed reporter identity, on
behalf of the brand. Nothing reaches a host or a registrar without the brand's
confirmation.
→ openbait.com · run by Puson Limited, Hong Kong
| rdap-abuse | Who to send a phishing report to, from RDAP: registrar, IANA ID, abuse address, creation date, nameservers, status. One shell script, no API key. |
Each of these is a case we ran, with dates, including what we got wrong.
- Five clone shops, nine domains — an hour-by-hour UTC record of one takedown case. We reported a site as offline while it was still taking card numbers from US visitors, because every probe we had ran from one country and the site answered some networks and played dead for others.
- How to report a phishing domain to its registrar — a report you can copy, what we measured in two cases, and what to do when the first one is ignored.
- Typosquat detection: five methods and their trade-offs — including the audit of our own pipeline: of 100 candidates it had rated high or critical, none was a live impersonation and 87 no longer existed.
- A
.cnphishing site — reported the same day to Google Safe Browsing and, through Phish.Report, to Tencent. Gone in about a day by one route; no visible reaction from the other in three.
Reports go out from one fixed address, contact@openbait.com, marked as made
on behalf of the brand. Evidence is archived with a third party while the site
is still live. Security researchers: same address for vulnerability reports,
acknowledged within 48 hours — security page.