# Destroy Analyze

Domain threat intelligence from PhishDestroy.

Site: https://analyze.destroy.tools/
Toolkit: https://destroy.tools/
API documentation: https://api.destroy.tools/

## Analyze a domain

Enter one public domain or HTTP(S) URL and select **Analyze domain**. Only the
normalized hostname is sent to the public PhishDestroy endpoint:

`GET https://api.destroy.tools/v1/check?domain=example.com`

URL paths, query strings, and fragments are discarded. URLs containing credentials,
IP addresses, and local hostnames are rejected. This interface does not visit the
submitted page, submit scans, send abuse reports, or initiate takedowns.

The report displays the API's Boolean threat verdict and any available risk score,
severity, named blocklist matches, detection flags, activity, and matched keywords.
It also exposes the complete original response as JSON. Unknown and missing fields
are not treated as zero risk. A domain without a blocklist match is not guaranteed
safe. Request failures produce an error state, never a clean verdict.

The optional `?d=example.com` or `?domain=example.com` parameter prefills the form.
It does not run a lookup automatically. No lookup history is stored by this interface.

## Research services

After submitting a valid domain, external research links point to its DNS records
on NSLookup.io, registration lookup on ICANN Lookup, reputation on VirusTotal,
and existing public scans on urlscan.io. These services open separately and may
require login. Their responses are not fetched or incorporated into this report.
Opening an external research link shares the chosen domain with that service.

## Related tools

- URL checker: https://ban.destroy.tools/
- Domain reports: https://phishdestroy.io/domain/
- API reference: https://api.destroy.tools/
- False-positive appeals: https://phishdestroy.io/appeals/
- Project privacy policy: https://phishdestroy.io/privacy/

JavaScript is required for interactive analysis. API and hosting providers may
process requests under their own policies.
