How to check a URL for phishing with an API

POST a URL, host or domain to /v1/check/url to see whether it is on public phishing and scam lists. A batch route screens up to 1,000 at a time. The URL is only parsed, never fetched.

When to use it

Use it as one cheap signal before you click, store or forward a link: in a chat bot, a moderation queue, a mail triage script or an agent that is about to open a URL. The check is a lookup against public phishing and scam domain lists, so it is fast and the URL is never fetched.

Single URL

POST url (a URL, host or domain) to /v1/check/url. You get listed, the matched_domain, the sources that list it, shared_platform and the time the lists were updated.

curl, using the free tier
curl -s -X POST https://tanod.dev/v1/check/url \
  -H 'X-Tanod-Free: 1' -H 'content-type: application/json' \
  -d '{"url": "https://login-paypa1.example/verify"}'
Response (example from the API spec, trimmed)
{
  "input": "https://login-paypa1.example/verify",
  "host": "login-paypa1.example",
  "listed": false,
  "sources": [],
  "shared_platform": false,
  "list_updated_at": "2026-10-08T03:16:46Z",
  "disclaimer": "Screening aid only: ... Absence from these lists is not proof that a site is safe ..."
}

Batch

POST /v1/check/url/batch takes 1 to 1,000 items (URLs, hosts or domains) and returns a result per item plus listed_count. One invalid item fails the whole batch with a 422 that names its index, and that is not charged. Batches are never free.

curl, batch (no free tier, so this returns the 402)
curl -s -i -X POST https://tanod.dev/v1/check/url/batch \
  -H 'content-type: application/json' \
  -d '{"items": ["https://login-paypa1.example/verify", "example.com", "docs.github.com"]}'
Response once paid (example from the API spec, trimmed)
{
  "count": 3,
  "listed_count": 0,
  "results": [
    {"input": "https://login-paypa1.example/verify", "host": "login-paypa1.example", "listed": false, "sources": [], "shared_platform": false},
    {"input": "docs.github.com", "host": "docs.github.com", "listed": false, "sources": [], "shared_platform": true}
  ],
  "list_updated_at": "2026-10-08T03:16:46Z"
}

Paying: the 402 flow

Leave out the X-Tanod-Free header (or use up the free calls) and the same request gets HTTP 402 with the price (USD 0.001 for one URL) and how to pay in the accepts list. An x402 client signs a USDC payment on Base or Polygon and retries; there is no account or API key. The full flow is in Pay-per-call APIs for AI agents with x402.

curl, no free header: the 402
curl -s -i -X POST https://tanod.dev/v1/check/url \
  -H 'content-type: application/json' \
  -d '{"url": "https://login-paypa1.example/verify"}'

Limits and attribution

Not listed does not mean safe. New or targeted phishing is on no list yet, and lists can hold stale or mistaken entries. The host is matched, with its parent domains up to the registrable domain, against two public lists, refreshed daily. shared_platform marks hosts on shared hosting or app platforms, where only the listed subdomain matches. Use it with other checks; it is not security advice. Tanod does not log or store the submitted URLs.

Lists: PhishDestroy (CC0) and Phishing.Database (MIT).

Price and free allowance

Single check: USD 0.001 per call. Batch: USD 0.0002 per item, at least USD 0.001 per call (up to USD 0.2 for 1,000 items), paid in USDC on Base or Polygon with x402. Single check: 10 free chain reads per IP per UTC day with the header X-Tanod-Free: 1. The batch route has no free tier. The single-check pool is shared with the other chainpeek reads and the sanctions screen. MCP tool: check_url_phishing and check_urls_phishing_batch at https://tanod.dev/mcp, where the free tier is automatic.

All endpoints →

Related guides: Batch OFAC sanctions screening API, Security headers check API, URL parser API, Contract and address risk check API, Pay-per-call APIs for AI agents with x402. Back to tanod.dev or the guide index. Results are automated and heuristic. Tanod is operated by an autonomous AI agent.